Malicious PDF — malware analysis report

Static analysis result for SHA-256 2b9aef412bb2a7c1…

MALICIOUS

PDF

17.3 KB Created: 2019-05-02 05:39:33 +01:00 Authoring application: mPDF 5.7
MD5: 28caff90d455bbe8c6ed2bac833a3b82 SHA-1: 5d9fa1ad83f06b8046145ebc155c43a04a9598e9 SHA-256: 2b9aef412bb2a7c1e70544876312974312b111f705f748b8c4d2c3d9604feeff
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, forming a link farm. The primary heuristic indicates this is a PDF SEO link farm, suggesting the document's purpose is to direct users to a multitude of external PDF files. While the document body is heavily corrupted, the presence of numerous links points towards a social engineering tactic to drive traffic to potentially malicious or unwanted content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6732736731738/The-World-According-to-Clarkson-World-According-to-Clarkson-1-by-Jeremy-Clarkson.pdf
    • http://cefasfese.4pu.com/4733731733731736/If-I-Break-Complete-Series-If-I-Break-1-3-by-Portia-Moore.pdf
    • http://cefasfese.4pu.com/3734736733732739/Break-My-Heart-and-I-ll-Break-Your-Car-by-VampireLover269.pdf
    • http://cefasfese.4pu.com/4730732735736738/Long-Way-Down-by-Ewan-McGregor.pdf
    • http://cefasfese.4pu.com/5731736735733738/Brondings-Honour-by-Ann-Ewan.pdf
    • http://cefasfese.4pu.com/3739736732734731/Safe-House-by-Chris-Ewan.pdf
    • http://cefasfese.4pu.com/3734733738737739/Safe-House-by-Chris-Ewan.pdf
    • http://cefasfese.4pu.com/1730731732731738731/Payback-Time-to-die-again-by-Douglas-Ewan-Cameron.pdf
    • http://cefasfese.4pu.com/1730731732730732735/Payback-is-a-Bitch-by-Douglas-Ewan-Cameron.pdf
    • http://cefasfese.4pu.com/5730739739734731/A-Little-Taste-of-Freedom-The-Black-Freedom-Struggle-in-Claiborne-County-Mississippi-by-Emilye-Crosby.pdf
    • http://cefasfese.4pu.com/3730737734730/Freedom-Freedom-In-The-Making-Of-Western-Culture-by-Orlando-Patterson.pdf
    • http://cefasfese.4pu.com/2732730739737730/Faith-Honor-amp-Freedom-Fighting-for-Freedom-2-by-Shannon-Callahan.pdf
    • http://cefasfese.4pu.com/3733732734737/Freedom-Is-Freedom-Ain-t-Jazz-and-the-Making-of-the-Sixties-by-Scott-Saul.pdf
    • http://cefasfese.4pu.com/1730739731730738739/The-Numbers---Welche-Zahl-bringt-dir-den-Tod-by-Ewan-Scott.pdf
    • http://cefasfese.4pu.com/8739739730736732/Schwarze-Schafe-in-Venedig-Krimi-by-Chris-Ewan.pdf
    • http://cefasfese.4pu.com/1730736732736738/Down-the-Stairs-A-Ewan-Johns-Adventure-Byways-Book-8-by-C-J-Milbrandt.pdf
    • http://cefasfese.4pu.com/1730736732737731/Inside-the-Tree-A-Ewan-Johns-Adventure-Byways-5-by-C-J-Milbrandt.pdf
    • http://cefasfese.4pu.com/9739732735733/The-Picts-A-History-by-Tim-Clarkson.pdf
    • http://cefasfese.4pu.com/1731737739731731734/Freedom-s-Call-Dive-Into-Freedom---Gently-Tread-the-Stepping-Stones-of-Your-Inner-World-and-Experience-Your-Dreams-Effortlessly-Unfolding-by-Themis-Thomas.pdf
    • http://cefasfese.4pu.com/4733735732736733/Round-the-Bend-by-Jeremy-Clarkson.pdf
    • http://cefasfese.4pu.com/5730739739734731/A-Little-Taste-of-Freedom-The-Black-Freedom-Struggle-in-Claibor