Malicious PDF — malware analysis report

Static analysis result for SHA-256 2f7ee5f088f8b3c8…

MALICIOUS

PDF

16.2 KB Created: 2019-05-03 06:05:29 +01:00 Authoring application: mPDF 5.7
MD5: fdbc3d838bacd1aa98457921e298d8e0 SHA-1: 7749b6fc4624b1cf30f23fc2c14411bba94b23fa SHA-256: 2f7ee5f088f8b3c899a3e2b4ad32022d75bd489d1ba403831a2302786f8da99f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs extracted were classified as benign, the sheer volume and structure suggest a malicious intent, likely to manipulate search engine results or redirect users to malicious sites. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1735736736737737/The-Bow-of-Destiny-by-P-H-Solomon.pdf
    • http://cefasfese.4pu.com/8731731731731734/Bikfala-Faet-olketa-Solomon-Aelanda-rimembarem-Wol-Wo-Tu-The-Big-Death-Solomon-Islanders-remember-World-War-II-by-Geoffrey-M-White.pdf
    • http://cefasfese.4pu.com/2735734730739739/The-Solomon-Key-The-Solomon-Key-2-by-Shawn-Hopkins.pdf
    • http://cefasfese.4pu.com/9739739732734730/Solomon-Kane-The-Hills-of-the-Dead-Solomon-Kane-2-by-Robert-E-Howard.pdf
    • http://cefasfese.4pu.com/1738739730734732/Finding-Destiny-Sons-of-Destiny-8-5-by-Jean-Johnson.pdf
    • http://cefasfese.4pu.com/2734739739731730/Destiny-Divided-Shadows-of-Destiny-1-by-Leia-Shaw.pdf
    • http://cefasfese.4pu.com/3738736733737732/The-Destiny-of-a-Galaxy-Destiny-Trilogy-3-by-Sarah-Holman.pdf
    • http://cefasfese.4pu.com/2734733737735732/Destiny-Divided-Shadows-of-Destiny-1-by-Leia-Shaw.pdf
    • http://cefasfese.4pu.com/3731735732734731/When-Destiny-Knocks-Destiny-Saga-1-by-Heather-M-White.pdf
    • http://cefasfese.4pu.com/1739736739731730/Solomon-vs-Lord-Solomon-vs-Lord-1-by-Paul-Levine.pdf
    • http://cefasfese.4pu.com/4736735734737/Solomon-vs-Lord-Solomon-vs-Lord-1-by-Paul-Levine.pdf
    • http://cefasfese.4pu.com/4734735737738733/When-Destiny-Calls-Destiny-1-by-Suzanne-Elizabeth.pdf
    • http://cefasfese.4pu.com/3739738733733732/Destiny-s-Way-Destiny-s-Series-3-by-Victoria-Saccenti.pdf
    • http://cefasfese.4pu.com/1731735731734733738/Destiny-s-Wrath-Destiny-3-by-Nancy-Straight.pdf
    • http://cefasfese.4pu.com/3738736733737730/The-Destiny-of-a-Few-Destiny-Trilogy-2-by-Sarah-Holman.pdf
    • http://cefasfese.4pu.com/2738738739737735/Destiny-and-Faith-Go-to-Twincentric-Academy-Destiny-And-Faith-1-by-Teddy-O-39-Malley.pdf
    • http://cefasfese.4pu.com/4733730732735/Limits-of-Destiny-Limits-of-Destiny-2-by-Sharlyn-G-Branson.pdf
    • http://cefasfese.4pu.com/4732731732739/Flame-of-Destiny-Flame-of-Destiny-1-by-Colleen-Helme.pdf
    • http://cefasfese.4pu.com/4732736738732/Limits-of-Destiny-Limits-of-Destiny-1-by-Sharlyn-G-Branson.pdf
    • http://cefasfese.4pu.com/1735737730732730/What-Is-Needed-by-P-H-Solomon.pdf
    • http://cefasfese.4pu.com/1739736739731730/Solomon-vs-Lord-Solomon-vs-Lord-1-by-