Malicious PDF — malware analysis report

Static analysis result for SHA-256 4cd69d4dc00ce930…

MALICIOUS

PDF

16.3 KB Created: 2019-05-02 07:54:42 +01:00 Authoring application: mPDF 5.7
MD5: d9517afce3952b00ca376d0a902520df SHA-1: 28ead9386f2c7ce73959eba687be0a4fb358f3d6 SHA-256: 4cd69d4dc00ce9307c58a9c8e4e8dfd8eeab0e5908589cbd2d4a219d46134e63
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded URLs, identified as a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to a multitude of external PDF documents, likely for SEO manipulation or to serve malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8731730738735734/And-the-Mountains-Echoed-Free-Preview-by-Khaled-Hosseini.pdf
    • http://cefasfese.4pu.com/8731731730738735/And-the-Mountains-Echoed-by-Khaled-Hosseini---Review-and-Summary-by-Easytodigest-Summaries.pdf
    • http://cefasfese.4pu.com/9732730736738734/And-the-Mountains-Echoed-By-Khaled-Hosseini-Trivia-On-Books-by-Trivion-Books.pdf
    • http://cefasfese.4pu.com/8731731730735737/And-the-Mountains-Echoed-by-Khaled-Hosseini---Expert-Book-Review-amp-Analysis-by-Expert-Book-Reviews.pdf
    • http://cefasfese.4pu.com/4738733738736736/Sea-Prayer-by-Khaled-Hosseini.pdf
    • http://cefasfese.4pu.com/8736735732/Sea-Prayer-by-Khaled-Hosseini.pdf
    • http://cefasfese.4pu.com/3730733730733731/The-Kite-Runner-by-Khaled-Hosseini.pdf
    • http://cefasfese.4pu.com/7731736733733734/The-Kite-Runner-by-Khaled-Hosseini.pdf
    • http://cefasfese.4pu.com/3734730733739730/A-Thousand-Splendid-Suns-by-Khaled-Hosseini.pdf
    • http://cefasfese.4pu.com/1730730730733730/A-Thousand-Splendid-Suns-by-Khaled-Hosseini.pdf
    • http://cefasfese.4pu.com/8731731730732734/Reading-Khaled-Hosseini-by-Rebecca-Stuhr.pdf
    • http://cefasfese.4pu.com/5739738739732731/Cidade-do-Sol---Edicao-de-2013-by-Khaled-Hosseini.pdf
    • http://cefasfese.4pu.com/4738735732732733/A-Thousand-Splendid-Suns-by-Khaled-Hosseini.pdf
    • http://cefasfese.4pu.com/5733731734731/A-Thousand-Splendid-Suns-by-Khaled-Hosseini.pdf
    • http://cefasfese.4pu.com/8731730738731736/The-Kite-Runner-Khaled-Hosseini-by-Calum-Kerr.pdf
    • http://cefasfese.4pu.com/8731731730733737/The-Kite-Runner-By-Khaled-Hosseini-Student-Packet-by-Pat-Watson.pdf
    • http://cefasfese.4pu.com/6734736739734733/The-Kite-Runner-York-Notes-Advanced-by-Khaled-Hosseini.pdf
    • http://cefasfese.4pu.com/8731731730733731/Bookclub-in-a-Box-Discusses-A-Thousand-Splendid-Suns-by-Khaled-Hosseini-by-Marilyn-Herbert.pdf
    • http://cefasfese.4pu.com/8731730738731737/Khaled-Hosseini-quot-A-Thousand-Splendid-Suns-quot-by-Ayse-G-kce.pdf
    • http://cefasfese.4pu.com/1737739735734735/Mountains-Wanted-Mountains-1-by-Phoebe-Alexander.pdf
    • http://cefasfese.4pu.com/87317317307327