Malicious PDF — malware analysis report

Static analysis result for SHA-256 24961e4a2ab9d5b8…

MALICIOUS

PDF

23.8 KB Created: 2019-05-04 10:20:39 +01:00 Authoring application: mPDF 5.7
MD5: 0c06ecc23feea744ca9191a6316b6f70 SHA-1: 32af06c8f4ea241949416302b54306dcaa66ae23 SHA-256: 24961e4a2ab9d5b82ca0f2c4f002e0edb111bf898bcdfbae808694c80c89fdb2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The primary heuristic indicates this is a PDF SEO link farm, suggesting a malicious intent to direct users to external content. While the specific URLs appear benign, the sheer volume and structure point to a malicious delivery mechanism. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9711

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5734739737736735/Fenwick-Travers-and-the-Years-of-Empire-An-Entertainment-by-Raymond-Saunders.pdf
    • http://cefasfese.4pu.com/5734739737736738/Fenwick-Travers-and-the-Panama-Canal-An-Entertainment-by-Raymond-Saunders.pdf
    • http://cefasfese.4pu.com/2733730738730737/The-Complete-Empire-Trilogy-Daughter-of-the-Empire-Mistress-of-the-Empire-Servant-of-the-Empire-The-Empire-Trilogy-1-3-by-Raymond-E-Feist.pdf
    • http://cefasfese.4pu.com/5730735735739739/Daughter-of-the-Empire-The-Empire-Trilogy-Book-1-by-Raymond-E-Feist.pdf
    • http://cefasfese.4pu.com/2739738735736735/Daughter-of-the-Empire-The-Empire-Trilogy-1-by-Raymond-E-Feist.pdf
    • http://cefasfese.4pu.com/4734736730731/Mistress-of-the-Empire-The-Empire-Trilogy-3-by-Raymond-E-Feist.pdf
    • http://cefasfese.4pu.com/2733733736731737/Daughter-of-the-Empire-The-Empire-Trilogy-1-by-Raymond-E-Feist.pdf
    • http://cefasfese.4pu.com/6735739736730/Articles-on-Raymond-E-Feist-Including-Midkemia-Novindus-Betrayal-at-Krondor-the-Riftwar-Saga-Kelewan-the-Kingdom-of-the-Isles-the-Empire-of-Great-Kesh-Return-to-Krondor-Empire-Trilogy-Tsurani-Krondor-s-Sons-Triagia-Elvandar-by-Hephaestus-Books.pdf
    • http://cefasfese.4pu.com/3733734733736733/Destruction-Galactic-Empire-Wars-1-by-Raymond-L-Weil.pdf
    • http://cefasfese.4pu.com/8739734733734733/A-Senhora-do-Imp-rio-The-Empire-Trilogy-3-by-Raymond-E-Feist.pdf
    • http://cefasfese.4pu.com/2731731732735732/The-Inland-Empire-Unfolding-Years-1879-1929-by-John-Fahey.pdf
    • http://cefasfese.4pu.com/1731730732731732/The-Great-War-for-the-Empire-The-Victorious-Years-1758-1760-by-Lawrence-Henry-Gipson.pdf
    • http://cefasfese.4pu.com/2730731732736737/Church-And-State-In-Russia-The-Last-Years-Of-The-Empire-1900-1917-by-John-Shelton-Curtiss.pdf
    • http://cefasfese.4pu.com/3738734737737730/Crucible-of-War-The-Seven-Years-War-and-the-Fate-of-Empire-in-British-North-America-1754-1766-by-Fred-Anderson.pdf
    • http://cefasfese.4pu.com/2731736738738/Crucible-of-War-The-Seven-Years-War-and-the-Fate-of-Empire-in-British-North-America-1754-1766-by-Fred-Anderson.pdf
    • http://cefasfese.4pu.com/5732738737730732/-travers-la-nuit-sans-fin-travers-la-nuit-sans-fin-by-Veronica-Rossi.pdf
    • http://cefasfese.4pu.com/1731732736732737733/Oeuvres-Raymond-Radiguet-Le-Diable-au-corps-Le-Bal-du-comte-d-Orgel-by-Raymond-Radiguet.pdf
    • http://cefasfese.4pu.com/4732732739738737/Sanctification-Empire-saga-6-Space-Empire-Trilogy-3-by-Michael-J-Findley.pdf
    • http://cefasfese.4pu.com/4732732739739738/Repentance-Empire-Saga-5-Space-Empire-Trilogy-2-by-Michael-J-Findley.pdf
    • http://cefasfese.4pu.com/1731730732737736/Raymond-and-Graham-Rule-the-School-Raymond-and-Graham-1-by-Mike-Knudson.pdf