Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b505c168b7f2122…

MALICIOUS

PDF

18.5 KB Created: 2019-06-10 06:05:14 +01:00 Authoring application: mPDF 5.7
MD5: b027857c00443d7ba38f390ab83ffe07 SHA-1: 208023db3cccbe8376c149c9b3a0d44b7162a337 SHA-256: 4b505c168b7f2122e1a161123a2ae29de68d058f11caf2631c382005abedf64c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or SEO spamming operation. While the document body is unreadable, the presence of 24 external links points to a malicious intent to redirect users. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification with a high confidence score.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9739736739739739/Blackout-by-Joey-Jameson.pdf
    • http://cefasfese.4pu.com/3731739738734733/Strangers-Have-the-Best-Candy-by-Margaret-Meps-Schulte.pdf
    • http://cefasfese.4pu.com/4738733730739731/Never-Take-Candy-from-Strangers-What-Lies-Between-2-by-Tamra-Flournoy.pdf
    • http://cefasfese.4pu.com/7732739735735/The-Candy-Men-The-Rollicking-Life-amp-Times-of-the-Notorious-Novel-Candy-by-Nile-Southern.pdf
    • http://cefasfese.4pu.com/1730736735739734736/The-Sweet-Book-of-Candy-Making-From-the-Simple-to-the-Spectacular-How-to-Make-Caramels-Fudge-Hard-Candy-Fondant-Toffee-and-More-by-Elizabeth-LaBau.pdf
    • http://cefasfese.4pu.com/1732735/Never-Smile-at-Strangers-Strangers-1-by-Jennifer-Jaynes.pdf
    • http://cefasfese.4pu.com/4732730731735738/Eye-Candy-Candy-3-by-Amanda-Young.pdf
    • http://cefasfese.4pu.com/2732733739733730/Candy-Man-Candy-Man-1-by-Amy-Lane.pdf
    • http://cefasfese.4pu.com/8730739735733737/Manga-Publicado-En-Nakayoshi-Sailor-Moon-Cardcaptor-Sakura-Tokyo-Mew-Mew-Candy-Candy-Shugo-Chara-Jigoku-Sh-Jo-Ashita-No-Nadja-Ghost-Hunt-Magic-Knight-Rayearth-Mermaid-Melody-Pichi-Pichi-Pitch-DOS-Fuera-de-Serie-by-Source-Wikipedia.pdf
    • http://cefasfese.4pu.com/4734730739734737/A-Day-Off-by-Storm-Jameson.pdf
    • http://cefasfese.4pu.com/3733731738732730/Mr-Wright-by-Liza-Jameson.pdf
    • http://cefasfese.4pu.com/1733730732738732/Blood-Wish-by-Fionn-Jameson.pdf
    • http://cefasfese.4pu.com/4732730737737739/The-Killers-by-Mike-Jameson.pdf
    • http://cefasfese.4pu.com/1734735734738739/Come-The-Fight-Club-1-by-Becca-Jameson.pdf
    • http://cefasfese.4pu.com/3738733736730736/Blind-With-Love-by-Becca-Jameson.pdf
    • http://cefasfese.4pu.com/7735733738736733/Vengence-in-Her-Bones-by-Malcolm-Jameson.pdf
    • http://cefasfese.4pu.com/5731733739734738/The-Antinomies-of-Realism-by-Fredric-Jameson.pdf
    • http://cefasfese.4pu.com/6736730733732738/American-Riff-by-Jameson-Parker.pdf
    • http://cefasfese.4pu.com/1736735738739732/Shards-of-Summer-by-Kelly-Jameson.pdf
    • http://cefasfese.4pu.com/6732733730736739/The-Most-Formidable-Thing-by-William-Jameson.pdf
    • http://cefasfese.4pu.com/1730736735739734736/The-Sweet-Book-of-Candy-Making-From-the-Simple-to-the-Spectacular-How-to-Ma