Malicious PDF — malware analysis report

Static analysis result for SHA-256 174aa35aad1f30e3…

MALICIOUS

PDF

21.4 KB Created: 2019-05-01 11:21:43 +01:00 Authoring application: mPDF 5.7
MD5: b0e7d8d04050ed38f8a7fd068ab7f48c SHA-1: c30bc63871aff18a23048369fc225b1ee868fa3a SHA-256: 174aa35aad1f30e3521aa287e30002f2a87422758a2edc06eac60208a41952f4
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the ML classifier also flagged the document as malicious, the specific intent appears to be directing users to a link farm rather than executing a direct exploit. The document body is heavily obfuscated, preventing a clear understanding of any secondary payload or specific lure. The primary IOCs are the numerous URLs found within the document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4730738731736733/In-the-Land-of-Magic-Soldiers-A-Story-of-White-and-Black-in-West-Africa-by-Daniel-Bergner.pdf
    • http://cefasfese.4pu.com/1730737739732739738/Liberating-Belsen-Remembering-the-Soldiers-of-the-Durham-Light-Infantry-by-David-Lowther.pdf
    • http://cefasfese.4pu.com/1730737739738734/Light-amp-Dark-The-Awakening-of-the-Mageknight-Light-amp-Dark-1-by-Daniel-M-Fife.pdf
    • http://cefasfese.4pu.com/9738737733739737/World-War-2-Waffen-SS-Soldiers---Testimonies-of-German-SS-Soldiers---2nd-Edition-World-War-2-WW2-WWII-German-Soldiers-by-Oliver-Mayer.pdf
    • http://cefasfese.4pu.com/2739735733735739/Light-of-Requiem-Song-of-Dragons-3-by-Daniel-Arenson.pdf
    • http://cefasfese.4pu.com/7731739738736735/The-Miracle-of-Mirador-Daniel-Light-and-the-Children-of-the-Orb-by-C-Michael-Perry.pdf
    • http://cefasfese.4pu.com/9734736739733734/Die-Berthold-Otto-Schulen-In-Magdeburg-by-Reinhard-Bergner.pdf
    • http://cefasfese.4pu.com/5734739733732/The-Silent-Soldiers-Back-To-School-The-Silent-Soldiers-2-by-Travis-Stinnett.pdf
    • http://cefasfese.4pu.com/1731739730733735733/Mein-Leben-vom-ostpreussischen-Bauernsohn-zum-Professor-an-der-Humboldt-Universit-t-by-Hans-Bergner.pdf
    • http://cefasfese.4pu.com/9736735736733736/Bewundert-viel-und-viel-gescholten---Unordentliche-Erinnerungen-by-Elisabeth-Bergner.pdf
    • http://cefasfese.4pu.com/1733732737734730/Peril-s-Gate-Wars-of-Light-and-Shadow-6-Arc-3---Alliance-of-Light-3-by-Janny-Wurts.pdf
    • http://cefasfese.4pu.com/1735736731738730/Fugitive-Prince-Wars-of-Light-amp-Shadow-4-Arc-3---Alliance-of-Light-1-by-Janny-Wurts.pdf
    • http://cefasfese.4pu.com/1730735736738730/Bridge-of-Light-Tools-of-Light-for-Spiritual-Transformation-by-Launa-A-Huffines.pdf
    • http://cefasfese.4pu.com/1730737739730732732/Light-Fighter-A-Devotional-Guide-for-Soliers-and-All-Who-Fight-for-the-Light-by-James-M-Fogle-Miller.pdf
    • http://cefasfese.4pu.com/4738732735736731/Circle-of-Light-The-Light-Years-Trilogy-1-by-Nancy-Cane.pdf
    • http://cefasfese.4pu.com/6738731730738739/Posthumous-memoirs-and-pedagogic-philosophical-confessions-by-Daniel-A-o-by-Daniel-A-o.pdf
    • http://cefasfese.4pu.com/2739735734738739/Daniel-and-the-Six-Element-Dragons-Daniel-and-the-Mysteries-2-by-Tamuna-Tsertsvadze.pdf
    • http://cefasfese.4pu.com/1731734730737730731/Light-and-Shadows-Falling-Light-1-by-Anika-Willmanns.pdf
    • http://cefasfese.4pu.com/4738734733737734/Light-Bound-The-Light-Tamer-3-by-Devyn-Dawson.pdf
    • http://cefasfese.4pu.com/5730739739732731/Red-Light-Stop-Green-Light-Go-by-Andrew-Kulman.pdf