Malicious PDF — malware analysis report

Static analysis result for SHA-256 26e1f0f3a4eea8d2…

MALICIOUS

PDF

15.8 KB Created: 2019-06-04 08:43:46 +01:00 Authoring application: mPDF 5.7
MD5: f82c1e66303b313df23ae668aa919466 SHA-1: 5e881098074c967da9d38e933df3070e374b8581 SHA-256: 26e1f0f3a4eea8d2a4b1644d5db4f35e0ae9c935513d22fc2ca7560922b5b78d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, characteristic of a link farm used for SEO manipulation or to distribute further malicious content. While the specific URLs themselves were labeled as benign, the sheer volume and the heuristic firing indicate a malicious intent to redirect users. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9800

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8731739737731734/Murphy-s-Madness-Brac-Pack-15-by-Lynn-Hagen.pdf
    • http://cefasfese.4pu.com/6735733737733730/Making-Corrections-Work-Effective-Offender-Rehabilitation-Francis-Cullen-and-Paul-Gendreau-by-Francis-T-Cullen.pdf
    • http://cefasfese.4pu.com/8732730730732734/Brac-Pack-Volume-8-Murphy-s-Madness-amp-Montana-s-Vamp-by-Lynn-Hagen.pdf
    • http://cefasfese.4pu.com/5730732739734730/Chronicle-of-the-Pharaohs-The-Reign-By-Reign-Record-of-the-Rulers-and-Dynasties-of-Ancient-Egypt-by-Peter-A-Clayton.pdf
    • http://cefasfese.4pu.com/2739736734735730/The-Madness-Project-The-Madness-Method-1-by-J-Leigh-Bralick.pdf
    • http://cefasfese.4pu.com/7732731731/Reign-of-the-Fallen-Reign-of-the-Fallen-1-by-Sarah-Glenn-Marsh.pdf
    • http://cefasfese.4pu.com/4733738739733/Reign-of-Blood-Reign-of-Blood-1-by-Alexia-Purdy.pdf
    • http://cefasfese.4pu.com/9736736732/Columbine-by-Dave-Cullen.pdf
    • http://cefasfese.4pu.com/5731734739739731/Pearl-by-Nancy-Jo-Cullen.pdf
    • http://cefasfese.4pu.com/9730734739738/The-Prince-of-Neither-Here-Nor-There-by-Se-n-Cullen.pdf
    • http://cefasfese.4pu.com/1734731733733735/Columbine-by-Dave-Cullen.pdf
    • http://cefasfese.4pu.com/7734735737738736/The-Last-Caldera-by-Conrad-F-Cullen-Jr-.pdf
    • http://cefasfese.4pu.com/7736737735738732/Merry-Meerkat-Madness-Meerkat-Madness-4-by-Ian-Whybrow.pdf
    • http://cefasfese.4pu.com/2738737739737731/Harrow-County-4-by-Cullen-Bunn.pdf
    • http://cefasfese.4pu.com/9734731731733736/El-tribunal-de-Dios-by-Cullen-Murphy.pdf
    • http://cefasfese.4pu.com/2737739739739735/Creeping-Stones-by-Cullen-Bunn.pdf
    • http://cefasfese.4pu.com/1739733731736736/Fearless-Defenders-1-by-Cullen-Bunn.pdf
    • http://cefasfese.4pu.com/7736736739737733/Rafael-Ferrer-by-Deborah-Cullen.pdf
    • http://cefasfese.4pu.com/4739739736737737/Thanatopsis-and-Other-Poems-by-William-Cullen-Bryant.pdf
    • http://cefasfese.4pu.com/2739739739731730/Love-Before-Dawn-Kindred-1-by-Claire-Cullen.pdf