Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c690ad90a2ba87f…

MALICIOUS

PDF

17.5 KB Created: 2019-11-07 13:38:09 +00:00 Authoring application: mPDF 5.7
MD5: 13c2b0b49b7f1e0ece605bfe10cfea15 SHA-1: 569fd320c73140f7cb61f6c1e9069775f925a9a2 SHA-256: 3c690ad90a2ba87fc5734c0bc5d39c1e602134038b2d69acaa71f12faf447b46
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign content, the sheer volume and the ML_NYX_PDF_MALICIOUS classification suggest a malicious intent, likely to direct users to harmful sites or for SEO abuse. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3739739737736/Zig-Zag-by-Jos-Carlos-Somoza.pdf
    • http://cefasfese.4pu.com/7735739738735/The-Art-of-Murder-by-Jos-Carlos-Somoza.pdf
    • http://cefasfese.4pu.com/7731736735733/The-Athenian-Murders-by-Jos-Carlos-Somoza.pdf
    • http://cefasfese.4pu.com/1731737735730737730/People-from-Santa-Fe-Argentina-Carlos-Monzon-Carlos-Reutemann-Andres-Nocioni-Sebastian-Spreng-Luciano-Figueroa-Carlos-Delfino-by-Source-Wikipedia.pdf
    • http://cefasfese.4pu.com/7736733732737735/Nicaraguan-Revolution-Anastasio-Somoza-Debayle-Sandinista-National-Liberation-Front-Daniel-Ortega-National-Guard-Anastasio-Somoza-Garc-a-by-Books-LLC.pdf
    • http://cefasfese.4pu.com/7736733732733736/Cityzen-by-Joseph-Somoza.pdf
    • http://cefasfese.4pu.com/7736733732736735/Out-of-This-World-Poems-by-Joseph-Somoza.pdf
    • http://cefasfese.4pu.com/7736733731730733/Somoza-Falling-by-Anthony-Lake.pdf
    • http://cefasfese.4pu.com/7736733731731735/Dawn-of-the-Living-Dead-by-Melissa-Somoza.pdf
    • http://cefasfese.4pu.com/7736733732738731/Somoza-s-Last-Stand-Testimonies-from-Nicaragua-by-Larry-Towell.pdf
    • http://cefasfese.4pu.com/7736733733735738/Orden-de-la-Cruz-Cruzados-de-las-estrellas-n-3-by-Alan-Somoza.pdf
    • http://cefasfese.4pu.com/7736733731731738/Regime-of-Anastasio-Somoza-1936-1956-by-Knut-Walter.pdf
    • http://cefasfese.4pu.com/7736733732738732/Anastasio-Somoza-Garcia-Un-dictador-made-in-USA-by-Ternot-Macrenato.pdf
    • http://cefasfese.4pu.com/6731735730736735/Carlos-Ruiz-Zafon-Books-2017-Checklist-Reading-Order-of-Cemetery-Of-Forgotten-Series-Niebla-Series-and-List-of-All-Carlos-Ruiz-Zafon-Books-by-Platinum-List.pdf
    • http://cefasfese.4pu.com/7736733733735730/Orden-de-las-Estrellas-Cruzados-de-las-estrellas-n-1-by-Alan-Somoza.pdf
    • http://cefasfese.4pu.com/6739738739734732/Very-Best-of-Carlos-Gardel-by-Carlos-Gardel.pdf
    • http://cefasfese.4pu.com/5730738736739736/O-sol-do-ver-n-by-Carlos-Casares.pdf
    • http://cefasfese.4pu.com/1733733731738731/The-Big-Hoax-by-Carlos-Trillo.pdf
    • http://cefasfese.4pu.com/1730736735737734732/The-Campaign-by-Carlos-Fuentes.pdf
    • http://cefasfese.4pu.com/5737732730731/Aura-by-Carlos-Fuentes.pdf