Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e1e0ad9aaf61da3…

MALICIOUS

PDF

19.8 KB Created: 2019-05-26 17:14:04 +01:00 Authoring application: mPDF 5.7
MD5: 35e0771a20245b46ccc1e2507bb3204b SHA-1: 471efd907384a75e5e635ae695c4ac51b10acba7 SHA-256: 1e1e0ad9aaf61da33d8afde0dc19f706139ec5238adefebd5eeeb96c1aed320f
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF_SEO_LINK_FARM heuristic indicates the presence of a large number of external links within the PDF, pointing to various book-related URLs. The ML classifier and ClamAV detection strongly suggest malicious intent, classifying it as a dropper. While the specific payload is not directly evident, the extensive link farm suggests a tactic to distribute malicious content or manipulate search engine results. The embedded URLs are likely part of this distribution or redirection scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9809

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-8721127-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-8721127-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7737731734731738/At-the-Scene-of-the-Crime-Forensic-Mysteries-from-Today-s-Best-Writers-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/3735736730732734/The-Real-CSI-A-Forensic-Handbook-for-Crime-Writers-by-Kate-Bendelow.pdf
    • http://cefasfese.4pu.com/3739738732732732/The-Earth-Cries-Out-Forensic-Chemistry-and-Environmental-Science-Crime-Scene-Club-Factor-and-Fiction-9-by-Kenneth-McIntosh.pdf
    • http://cefasfese.4pu.com/7737731735733731/Dana-Stabenow-Books-Checklist-Reading-Order-Of-Coast-Guard-Series-in-Order-Kate-Shugak-Series-in-Order-Silk-and-Song-Trilogy-Star-Svensdotter-Series-in-Order-and-List-of-All-Dana-Stabenow-Books-by-Kevin-Hanson.pdf
    • http://cefasfese.4pu.com/1736738739735/Scene-of-the-Crime-The-Importance-of-Place-in-Crime-and-Mystery-Fiction-by-David-Geherin.pdf
    • http://cefasfese.4pu.com/7737731734732733/Cheechako-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731734731739/The-Mysterious-North-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/4731733735731738/Wild-Crimes-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731734732736/Gold-Fever-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731735732739/Taint-in-the-Blood-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731734736731/The-Kate-Shugak-Novels-Vol-3-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/2732731738732737/Though-Not-Dead-Kate-Shugak-18-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/8734736730736/Blood-Will-Tell-Kate-Shugak-6-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/8735738738733/A-Taint-In-The-Blood-Kate-Shugak-14-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731732737736/Cherchez-la-Femme-Kate-Shugak-17-5-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731732737730/Any-Taint-of-Vice-Kate-Shugak-19-5-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/1734733733736739/Whisper-To-The-Blood-Kate-Shugak-16-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/8735731735735/Hunter-s-Moon-Kate-Shugak-9-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731734736736/No-Fixed-Line-Kate-Shugak-22-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731734737733/Les-enqu-tes-de-Kate-Shugak---Int-grale-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731735733731/Dana-Stabenow-Books-Checklist-Reading-Order-Of-Coast-Guard-Series-in-Order-Kate-Shugak-Series-in-Order-Silk-and-Song-Trilogy-Star-Svensdotter-Series-in-Order-and-Lis