Malicious PDF — malware analysis report

Static analysis result for SHA-256 3e76a7416969502c…

MALICIOUS

PDF

16.2 KB Created: 2019-05-03 06:05:35 +01:00 Authoring application: mPDF 5.7
MD5: 2b14b8d02c7227519c7156463e20269b SHA-1: 52ffabe0f90b0e2a0093df37f627be0a04c94641 SHA-256: 3e76a7416969502c55282a988ec74e95c6b5f63a59e40aef26581fc2830f1044
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, many of which point to PDF files with numeric slugs, indicative of a link farm or SEO manipulation tactic. While the specific intent of these links is unclear due to their 'confirmed_benign' reputation, the sheer volume and the critical heuristic firing suggest a malicious intent, possibly to distribute further malware or engage in phishing. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1735736736737737/The-Bow-of-Destiny-by-P-H-Solomon.pdf
    • http://cefasfese.4pu.com/8731731731731734/Bikfala-Faet-olketa-Solomon-Aelanda-rimembarem-Wol-Wo-Tu-The-Big-Death-Solomon-Islanders-remember-World-War-II-by-Geoffrey-M-White.pdf
    • http://cefasfese.4pu.com/2735734730739739/The-Solomon-Key-The-Solomon-Key-2-by-Shawn-Hopkins.pdf
    • http://cefasfese.4pu.com/9739739732734730/Solomon-Kane-The-Hills-of-the-Dead-Solomon-Kane-2-by-Robert-E-Howard.pdf
    • http://cefasfese.4pu.com/1738739730734732/Finding-Destiny-Sons-of-Destiny-8-5-by-Jean-Johnson.pdf
    • http://cefasfese.4pu.com/2734739739731730/Destiny-Divided-Shadows-of-Destiny-1-by-Leia-Shaw.pdf
    • http://cefasfese.4pu.com/3738736733737732/The-Destiny-of-a-Galaxy-Destiny-Trilogy-3-by-Sarah-Holman.pdf
    • http://cefasfese.4pu.com/2734733737735732/Destiny-Divided-Shadows-of-Destiny-1-by-Leia-Shaw.pdf
    • http://cefasfese.4pu.com/3731735732734731/When-Destiny-Knocks-Destiny-Saga-1-by-Heather-M-White.pdf
    • http://cefasfese.4pu.com/1739736739731730/Solomon-vs-Lord-Solomon-vs-Lord-1-by-Paul-Levine.pdf
    • http://cefasfese.4pu.com/4736735734737/Solomon-vs-Lord-Solomon-vs-Lord-1-by-Paul-Levine.pdf
    • http://cefasfese.4pu.com/4734735737738733/When-Destiny-Calls-Destiny-1-by-Suzanne-Elizabeth.pdf
    • http://cefasfese.4pu.com/3739738733733732/Destiny-s-Way-Destiny-s-Series-3-by-Victoria-Saccenti.pdf
    • http://cefasfese.4pu.com/1731735731734733738/Destiny-s-Wrath-Destiny-3-by-Nancy-Straight.pdf
    • http://cefasfese.4pu.com/3738736733737730/The-Destiny-of-a-Few-Destiny-Trilogy-2-by-Sarah-Holman.pdf
    • http://cefasfese.4pu.com/2738738739737735/Destiny-and-Faith-Go-to-Twincentric-Academy-Destiny-And-Faith-1-by-Teddy-O-39-Malley.pdf
    • http://cefasfese.4pu.com/4733730732735/Limits-of-Destiny-Limits-of-Destiny-2-by-Sharlyn-G-Branson.pdf
    • http://cefasfese.4pu.com/4732731732739/Flame-of-Destiny-Flame-of-Destiny-1-by-Colleen-Helme.pdf
    • http://cefasfese.4pu.com/4732736738732/Limits-of-Destiny-Limits-of-Destiny-1-by-Sharlyn-G-Branson.pdf
    • http://cefasfese.4pu.com/1735737730732730/What-Is-Needed-by-P-H-Solomon.pdf
    • http://cefasfese.4pu.com/1739736739731730/Solomon-vs-Lord-Solomon-vs-Lord-1-by-