Malicious PDF — malware analysis report

Static analysis result for SHA-256 174b8ced06573bfb…

MALICIOUS

PDF

21.7 KB Created: 2019-11-07 20:40:01 +00:00 Authoring application: mPDF 5.7
MD5: 493a43ba68c5228bc9ec724b1fb9eb23 SHA-1: 1fbd54e9b040d34ce911981f80126a684a73eddc SHA-256: 174b8ced06573bfb0240b38c0c6d5e252cc818ec16d6f40a8a266d4cd97a8155
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF was flagged by a machine learning classifier and contains a large number of embedded links, many of which appear to be SEO-optimized with numeric slugs. While the document body is heavily obfuscated, the heuristic 'PDF_SEO_LINK_FARM' indicates a deliberate attempt to create a link farm. The presence of embedded URLs suggests an attempt to direct users to external resources, potentially for malicious purposes such as distributing malware or phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9796

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3733739733735734/The-Visual-Dictionary-of-Star-Wars-Episode-I---The-Phantom-Menace-by-David-West-Reynolds.pdf
    • http://cefasfese.4pu.com/3733739737732736/Star-Wars-Episode-II---Attack-of-the-Clones-The-Visual-Dictionary-by-David-West-Reynolds.pdf
    • http://cefasfese.4pu.com/3734730730733737/Star-Wars-Episode-I-The-Phantom-Menace-Volume-1-by-Henry-Gilroy.pdf
    • http://cefasfese.4pu.com/5738735736732734/The-Making-of-Star-Wars-Episode-I---The-Phantom-Menace-by-Laurent-Bouzereau.pdf
    • http://cefasfese.4pu.com/1738730738739734/The-Phantom-Menace-Star-Wars-Novelizations-1-by-Terry-Brooks.pdf
    • http://cefasfese.4pu.com/4737739733731738/William-Shakespeare-s-The-Phantom-of-Menace-Star-Wars-Part-the-First-by-Ian-Doescher.pdf
    • http://cefasfese.4pu.com/8731733730732739/Star-Wars-Episode-1-Journal-Pack--Anakin-Skywalker-and-Queen-Amidala-Star-Wars-Episode-1-Journal-by-Todd-Strasser.pdf
    • http://cefasfese.4pu.com/7734739734734/Star-Wars-The-Ultimate-Visual-Guide-by-Daniel-Wallace.pdf
    • http://cefasfese.4pu.com/3730734732733734/A-New-Hope-Star-Wars-Episode-IV-by-George-Lucas.pdf
    • http://cefasfese.4pu.com/3733739737735736/The-Art-of-Star-Wars-Episode-VI-Return-of-the-Jedi-by-Carol-Titelman.pdf
    • http://cefasfese.4pu.com/3734730731731735/Star-Wars-Episode-II-Attack-of-the-Clones-Volume-1-by-Henry-Gilroy.pdf
    • http://cefasfese.4pu.com/3734730731731734/Star-Wars-Episode-II-Attack-of-the-Clones-Volume-4-by-Henry-Gilroy.pdf
    • http://cefasfese.4pu.com/3733739737734731/The-Art-of-Star-Wars-Episode-V-The-Empire-Strikes-Back-by-Deborah-Call.pdf
    • http://cefasfese.4pu.com/5733735738731735/My-First-Visual-Dictionary-Mi-Primer-Diccionario-Visual-by-Caroline-Fortin.pdf
    • http://cefasfese.4pu.com/1730738737739731735/Star-Wars-Rebels-Hera-s-Phantom-Flight-World-of-Reading-Level-2-by-Elizabeth-Schaefer.pdf
    • http://cefasfese.4pu.com/6736731736738736/Star-Wars-Chevaliers-de-l-ancienne-r-publique-T05-Sans-piti-Star-Wars-Knights-of-the-Old-Republic-6-by-John-Jackson-Miller.pdf
    • http://cefasfese.4pu.com/3733739737733739/Star-Wars-Vol-3-Rebel-Jail-Star-Wars-3-by-Jason-Aaron.pdf
    • http://cefasfese.4pu.com/8736734732732735/Star-Wars-Jedi-Academy-The-Phantom-Bully-Jedi-Academy-3-by-Jeffrey-Brown.pdf
    • http://cefasfese.4pu.com/8739738737732734/Star-Wars-Vor-dem-Erwachen-Die-offizielle-Vorgeschichte-zu-Star-Wars-Das-Erwachen-der-Macht-by-Greg-Rucka.pdf
    • http://cefasfese.4pu.com/6735737739739/Star-by-Star-Star-Wars-The-New-Jedi-Order-9-by-Troy-Denning.pdf