Malicious PDF — malware analysis report

Static analysis result for SHA-256 1886b87e8cce13b2…

MALICIOUS

PDF

18.7 KB Created: 2019-05-03 06:06:58 +01:00 Authoring application: mPDF 5.7
MD5: d92747d83fd9124b2bf9c07213ab60c3 SHA-1: 1dcf316ba934713a22eac1761f5b88137af99158 SHA-256: 1886b87e8cce13b25050fa152599140e4d3ceca35e471ce7c368c0ec388d9fcb
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded external links, identified as a link farm. The primary heuristic indicates this is a critical finding, suggesting the document's purpose is to direct users to numerous external sites. While the specific intent of these external sites is unclear, the pattern suggests a potential SEO manipulation or a distribution mechanism for further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3739730730738739/Prime-Suspect-The-Floods-5-by-Colin-Thompson.pdf
    • http://cefasfese.4pu.com/4736735734731733/The-Prince-the-Showgirl-and-Me-Six-Months-on-the-Set-With-Marilyn-and-Olivier-by-Colin-Clark.pdf
    • http://cefasfese.4pu.com/2739733733732/One-Vast-Winter-Count-The-Native-American-West-before-Lewis-and-Clark-by-Colin-G-Calloway.pdf
    • http://cefasfese.4pu.com/1735735734730730/When-the-Floods-Came-by-Clare-Morrall.pdf
    • http://cefasfese.4pu.com/3734734733731737/Cataclysms-on-the-Columbia-The-Great-Missoula-Floods-by-John-Eliot-Allen.pdf
    • http://cefasfese.4pu.com/4730730731735/------1-Ponniyin-Selvan---The-First-Floods-by-Kalki.pdf
    • http://cefasfese.4pu.com/3738730737735731/Colin-McCool-and-the-Vampire-Dwarf-Colin-McCool-Children-s-Fantasy-Book-Series-by-M-D-Massey.pdf
    • http://cefasfese.4pu.com/4737735739736736/Jim-Clark-at-the-Wheel-The-World-s-Greatest-Motor-Racing-Champion-Tells-His-Own-Supercharged-Success-Story-by-Jim-Clark.pdf
    • http://cefasfese.4pu.com/2732734737737730/Father-Son-and-Constitution-How-Justice-Tom-Clark-and-Attorney-General-Ramsey-Clark-Shaped-American-Democracy-by-Alexander-Wohl.pdf
    • http://cefasfese.4pu.com/5733734737739733/Colin-and-Martin-s-London-Christmas-Colin-and-Martin-2-by-Drew-Hunt.pdf
    • http://cefasfese.4pu.com/3731739733735/We-Can-Be-Heroes-by-Catherine-Bruton.pdf
    • http://cefasfese.4pu.com/6736739735736731/Down-and-Out-in-Bridgwater-by-Dale-Bruton.pdf
    • http://cefasfese.4pu.com/6736739732738738/I-Predict-A-Riot-by-Catherine-Bruton.pdf
    • http://cefasfese.4pu.com/6736739734739739/Somalia-A-New-Approach-by-Bronwyn-E-Bruton.pdf
    • http://cefasfese.4pu.com/6736739734735733/The-Virus-Doctors-by-Noel-Bruton.pdf
    • http://cefasfese.4pu.com/6736739733737738/Bruton-Through-Time-by-Andrew-Pickering.pdf
    • http://cefasfese.4pu.com/6736739735735739/How-to-Manage-the-IT-Help-Desk-by-Noel-Bruton.pdf
    • http://cefasfese.4pu.com/6736739735736732/In-a-Mirror-Dimly-by-Oleta-Bruton.pdf
    • http://cefasfese.4pu.com/6736739735736734/Active-Reading-by-Anthony-Bruton.pdf
    • http://cefasfese.4pu.com/6736739733738736/Of-Silence-and-Slow-Time-by-Catherine-Bruton.pdf