Malicious PDF — malware analysis report

Static analysis result for SHA-256 2ba0a3f653f24a59…

MALICIOUS

PDF

29.1 KB Created: 2019-11-08 00:32:46 +00:00 Authoring application: mPDF 5.7
MD5: 9e96961b6c109322521cf1723da3980c SHA-1: 87413257d1cea0e54e81e05efe2539b66d404f31 SHA-256: 2ba0a3f653f24a59b0a709086f080c6fb9e44e0ff650bccb7fa05f59f92f6bcb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. While the document body is heavily obfuscated, the presence of numerous external links suggests a malicious intent, possibly for SEO manipulation or to direct users to malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8735734735732736/The-Art-of-Animal-Drawing-Construction-Action-Analysis-Caricature-by-Ken-Hultgren.pdf
    • http://cefasfese.4pu.com/7735733738733739/Drawing-Figures-in-Action-by-Andrew-Loomis.pdf
    • http://cefasfese.4pu.com/8735734736733736/The-Cambrian-Explosion-The-Construction-of-Animal-Biodiversity-by-Douglas-H-Erwin.pdf
    • http://cefasfese.4pu.com/8735734733739731/The-Artist-s-Complete-Guide-to-Figure-Drawing-A-Contemporary-Master-Reveals-the-Secrets-of-Drawing-the-Human-Form-by-Anthony-Ryder.pdf
    • http://cefasfese.4pu.com/5735732739739734/Handbook-of-Building-Construction-Data-for-Architects-Designing-and-Construction-Engineers-and-Contractors-V-1-by-George-a-Hool.pdf
    • http://cefasfese.4pu.com/5735732739731739/Handbook-of-Building-Construction-Data-for-Architects-Designing-and-Construction-Engineers-and-Contractors-by-George-a-Hool.pdf
    • http://cefasfese.4pu.com/5732738733733739/Psychology-Art-and-Antifascism-Ernst-Kris-E-H-Gombrich-and-the-Politics-of-Caricature-by-Louis-Rose.pdf
    • http://cefasfese.4pu.com/8733736738734732/Analysis-2-Part-Set-Integration-Distributions-Holomorphic-Functions-Tensor-and-Harmonic-Analysis-by-Krzysztof-Maurin.pdf
    • http://cefasfese.4pu.com/8732732733731739/Functional-Analysis-Introduction-to-Further-Topics-in-Analysis-by-Elias-M-Stein.pdf
    • http://cefasfese.4pu.com/3731738732731738/Leopard-at-the-Lodge-Animal-Ark-Series-44-Animal-Ark-in-South-Africa-by-Lucy-Daniels.pdf
    • http://cefasfese.4pu.com/1730734735734738739/The-Animal-Alphabet-An-Animal-ABC-Book-for-Children-by-Julie-Sonnen.pdf
    • http://cefasfese.4pu.com/9732732739/The-End-of-Animal-Farming-How-Scientists-Entrepreneurs-and-Activists-Are-Building-an-Animal-Free-Food-System-by-Jacy-Reese.pdf
    • http://cefasfese.4pu.com/6733737730736733/The-Elegance-of-the-Hedgehog-by-Muriel-Barbery-Book-Analysis-Detailed-Summary-Analysis-and-Reading-Guide-BrightSummaries-com-by-Bright-Summaries.pdf
    • http://cefasfese.4pu.com/6730735735736739/What-the-Day-Owes-the-Night-by-Yasmina-Khadra-Book-Analysis-Detailed-Summary-Analysis-and-Reading-Guide-BrightSummaries-com-by-Bright-Summaries.pdf
    • http://cefasfese.4pu.com/5733730734734738/Hunting-and-Gathering-by-Anna-Gavalda-Book-Analysis-Detailed-Summary-Analysis-and-Reading-Guide-BrightSummaries-com-by-Bright-Summaries.pdf
    • http://cefasfese.4pu.com/5732734730735736/Fear-and-Trembling-by-Am-lie-Nothomb-Book-Analysis-Detailed-Summary-Analysis-and-Reading-Guide-BrightSummaries-com-by-Bright-Summaries.pdf
    • http://cefasfese.4pu.com/2735736738737/Animal-Attraction-Animal-Magnetism-2-by-Jill-Shalvis.pdf
    • http://cefasfese.4pu.com/7733738733731730/Perfume-The-Story-of-a-Murderer-by-Patrick-S-skind-Book-Analysis-Detailed-Summary-Analysis-and-Reading-Guide-BrightSummaries-com-by-Bright-Summaries.pdf
    • http://cefasfese.4pu.com/5738731738735735/The-Truth-About-the-Harry-Quebert-Affair-by-Jo-l-Dicker-Book-Analysis-Detailed-Summary-Analysis-and-Reading-Guide-BrightSummaries-com-by-Bright-Summaries.pdf
    • http://cefasfese.4pu.com/3730734733739737/Animal-Man-Volume-2-Animal-vs-Man-by-Jeff-Lemire.pdf
    • http://cefasfese.4pu.com/5735732739739734/Handbook-of-Building-Construction-Data-for-Architects-Designing-and-Construction-Engineers-and-Contractors-