Malicious PDF — malware analysis report

Static analysis result for SHA-256 2d7451022816b583…

MALICIOUS

PDF

17.3 KB Created: 2019-11-07 12:38:45 +00:00 Authoring application: mPDF 5.7
MD5: f74ea2231ba6b00faedcffed8aa93ec2 SHA-1: d7000fe67dd2183b5ec53811db401c646f753692 SHA-256: 2d7451022816b583303e08b4f0e69b5c60538e34ceab500939b3351412417f6e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these specific URLs were marked as benign, the sheer volume and structure suggest a link farm intended to distribute malicious content or lead users to phishing pages. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8731739734738731/King-Lear-As-Broadcast-in-the-Columbia-Shakespearean-Cycle-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/8734731737734735/King-Lear-The-Global-Shakespeare-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/6739736731730735/King-Lear-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/1730737735733733732/King-Lear-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/6731734735733733/King-Lear-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/3732733731738/King-Lear-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/7732735735736736/King-Lear-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/8736733735736736/King-Lear-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/5738735735730/King-Lear-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/4733733737733737/King-Lear-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/9730733736737738/King-Lear-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/1731732732737737730/The-Tragedy-of-King-Lear-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/9731732739735735/King-Lear-a-tragedy-in-five-acts-Altered-as-performed-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/6731737737739736/The-Cambridge-King-Lear-CD-ROM-Text-and-Performance-Archive-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/5739738733735730/King-Lear-SmartPass-Teacher-Audio-Education-Resource-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/6734738739733739/King-Lear-No-1-of-the-Edvin-Forrest-Edition-of-Shakespearian-and-Other-Plans-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/7737734730734739/King-Lear---The-Annotated-Edition-including-the-classic-A-C-Bradley-lectures-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/5737737738736732/King-Lear-With-Introductions-Notes-Glossary-Critical-Comments-and-Method-of-Study-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/6732735730735736/Edward-Bond-s-Lear-And-Shakespeare-s-King-Lear-by-Horst-Oppel.pdf
    • http://cefasfese.4pu.com/1731737731733738732/Manga-Shakespeare-King-Lear-by-Richard-Appignanesi.pdf
    • http://cefasfese.4pu.com/6731737737739736/