Malicious PDF — malware analysis report

Static analysis result for SHA-256 4dde95290c15906f…

MALICIOUS

PDF

21.2 KB Created: 2019-11-08 00:09:50 +00:00 Authoring application: mPDF 5.7
MD5: 0dfbb6aaaead818201989ae13371a4bf SHA-1: 9c269272c4e119da78dc2860c3af8da2cba12b47 SHA-256: 4dde95290c15906f92d857b72fd108cc27100b85cd479ee08472bbf70d9cd0d5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which point to external PDF documents. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to a link farm, likely for SEO poisoning or to host further malicious content, rather than direct exploitation within the PDF itself.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9796

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4730739733730730/Religion-for-Atheists-A-Non-Believer-s-Guide-to-the-Uses-of-Religion-by-Alain-de-Botton.pdf
    • http://cefasfese.4pu.com/1731739732739738737/Religion-and-Culture-An-Introduction-to-Anthropology-of-Religion-by-Annemarie-de-Waal-Malefijt.pdf
    • http://cefasfese.4pu.com/2732731738730734/Natural-Religion-amp-Christian-Theology-Vol-1-Science-amp-Religion-Gifford-Lectures-1951-by-Charles-E-Raven.pdf
    • http://cefasfese.4pu.com/1739736739735738/Making-Religion-Making-the-State-The-Politics-of-Religion-in-Modern-China-by-Yoshiko-Ashiwa.pdf
    • http://cefasfese.4pu.com/6733733735731/Dialogues-Concerning-Natural-Religion-and-The-Natural-History-of-Religion-by-David-Hume.pdf
    • http://cefasfese.4pu.com/1731737738739733736/Epilegomena-to-the-Study-of-Greek-Religion-Themis-A-Study-of-the-Social-Origins-of-Greek-Religion-by-Jane-Ellen-Harrison.pdf
    • http://cefasfese.4pu.com/1730731736739737/On-Love-by-Alain-de-Botton.pdf
    • http://cefasfese.4pu.com/3730731734/The-Course-of-Love-by-Alain-de-Botton.pdf
    • http://cefasfese.4pu.com/4732739736738738/Everything-You-Know-About-God-is-Wrong-The-Disinformation-Guide-to-Religion-by-Russ-Kick.pdf
    • http://cefasfese.4pu.com/8731734739734737/O-s-pt-m-n-n-aeroport-by-Alain-de-Botton.pdf
    • http://cefasfese.4pu.com/1733737730736739/The-Consolations-of-Philosophy-by-Alain-de-Botton.pdf
    • http://cefasfese.4pu.com/8737730735738734/Airport-Eine-Woche-In-Heathrow-by-Alain-de-Botton.pdf
    • http://cefasfese.4pu.com/7734731739737737/Shinto-Shrines-A-Guide-to-the-Sacred-Sites-of-Japan-s-Ancient-Religion-by-Joseph-Cali.pdf
    • http://cefasfese.4pu.com/9730733738737738/the-course-of-love-audible-narrator-Julian-rhind-tutt-by-Alain-de-Botton.pdf
    • http://cefasfese.4pu.com/5739732737736735/The-Savvy-Convert-s-Guide-to-Choosing-a-Religion-Compare-and-Contrast-Before-You-Commit-by-Knock-Knock.pdf
    • http://cefasfese.4pu.com/5730731737735734/There-s-Probably-No-God-the-Atheists-Guide-to-Christmas-by-Ariane-Sherine.pdf
    • http://cefasfese.4pu.com/5739739732731732/The-Religion-of-Man-by-Rabindranath-Tagore.pdf
    • http://cefasfese.4pu.com/9735738736731/The-Idea-of-One-Religion-by-J-S-Thakur.pdf
    • http://cefasfese.4pu.com/7730732737732/The-Sociology-of-Religion-by-Max-Weber.pdf
    • http://cefasfese.4pu.com/1733738730730730/The-Religion-of-Man-by-Rabindranath-Tagore.pdf