Malicious PDF — malware analysis report

Static analysis result for SHA-256 43950d04893db4eb…

MALICIOUS

PDF

22.0 KB Created: 2019-05-02 06:02:50 +01:00 Authoring application: mPDF 5.7
MD5: a35002b242fb01af6d50f2be1ea68c34 SHA-1: 6c086e587908f9b682f2e979f2b06307d686c09e SHA-256: 43950d04893db4eb035097fd14049cc8597ba50390565d1d5b25073fdd5b4cb3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the sheer volume of links suggests a malicious intent to redirect users to potentially harmful content or phishing sites. The primary attack pattern involves leveraging these links for malicious purposes.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9796

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3731730730731738/The-Thousand-Scars-Counterbalance-Volume-One-by-Michael-R-Baker.pdf
    • http://cefasfese.4pu.com/4738734731736730/Where-Souls-Spoil-Bayonet-Scars-Series-Volume-I-Bayonet-Scars-1-4-5-by-J-C-Emery.pdf
    • http://cefasfese.4pu.com/1739739733731738/Sapphire-Scars-Volume-1-The-Sapphire-Scars-Trilogy-1-by-A-P-Moraez.pdf
    • http://cefasfese.4pu.com/7735734732730730/The-Brothers-of-Baker-Street-Baker-Street-Letters-2-by-Michael-Robertson.pdf
    • http://cefasfese.4pu.com/5738732733739734/The-Thousand-Coffins-Affair-The-Man-from-U-N-C-L-E-1-by-Michael-Avallone.pdf
    • http://cefasfese.4pu.com/1730735736737739731/Lon-Chaney-The-Man-Behind-The-Thousand-Faces-by-Michael-F-Blake.pdf
    • http://cefasfese.4pu.com/1739731733737733/Blade-of-the-Immortal-Volume-1-Blood-of-a-Thousand-by-Hiroaki-Samura.pdf
    • http://cefasfese.4pu.com/1733732733732731/Ten-Thousand-Joys-amp-Ten-Thousand-Sorrows-A-Couple-s-Journey-Through-Alzheimer-s-by-Olivia-Ames-Hoblitzelle.pdf
    • http://cefasfese.4pu.com/1730739731736730/Thousand-Sinful-Kisses-Thousand-Trilogy-1-by-Liam-Levi.pdf
    • http://cefasfese.4pu.com/2736738733735730/Baker-Street-Irregulars-Thirteen-Authors-with-New-Takes-on-Sherlock-Holmes-by-Michael-A-Ventrella.pdf
    • http://cefasfese.4pu.com/5737733739731730/TARDIS-Eruditorum---An-Unofficial-Critical-History-of-Doctor-Who-Volume-5-Tom-Baker-and-the-Williams-Years-by-Philip-Sandifer.pdf
    • http://cefasfese.4pu.com/8738731733736736/Harlequin-E-Contemporary-Romance-Box-Set-Volume-1-Coming-in-from-the-Cold-Maid-to-Fit-Calling-His-Bluff-Baker-s-Law-by-Sarina-Bowen.pdf
    • http://cefasfese.4pu.com/5737733738739739/TARDIS-Eruditorum---An-Unofficial-Critical-History-of-Doctor-Who-Volume-4-Tom-Baker-and-the-Hinchcliffe-Years-by-Philip-Sandifer.pdf
    • http://cefasfese.4pu.com/2738734738739733/Hidden-Scars-Hidden-Scars-1-by-Amanda-K-Byrne.pdf
    • http://cefasfese.4pu.com/2739733735734731/Baker-s-Bad-Boys-by-Dean-J-Baker.pdf
    • http://cefasfese.4pu.com/3730734738733731/Ultimate-Comics-Spider-Man-by-Brian-Michael-Bendis-Volume-2-by-Brian-Michael-Bendis.pdf
    • http://cefasfese.4pu.com/3730735733730736/Ultimate-Comics-Spider-Man-by-Brian-Michael-Bendis-Volume-4-by-Brian-Michael-Bendis.pdf
    • http://cefasfese.4pu.com/2736735736730734/BAD-INTENT-Volume-1-by-Michael-Tabman.pdf
    • http://cefasfese.4pu.com/4734734733737733/The-Best-of-Spider-Man-Volume-1-by-J-Michael-Straczynski.pdf
    • http://cefasfese.4pu.com/5734735739739/Superman-Earth-One-Volume-1-by-J-Michael-Straczynski.pdf
    • http://cefasfese.4pu.com/1730739731736730/Thousand-Sinful-Kisses-Thousand-Trilogy-1-b