Malicious PDF — malware analysis report

Static analysis result for SHA-256 4ed0e641df09d55e…

MALICIOUS

PDF

20.8 KB Created: 2019-05-03 16:10:36 +01:00 Authoring application: mPDF 5.7
MD5: bc49f64afce547c6e9efd7fd4d11f712 SHA-1: 7df54acee80d0e58366735c08516379b5f9ac9b1 SHA-256: 4ed0e641df09d55e2fbd8cfb45b482d7ea0f726951f7fd9489c36e50d194dc1f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these URLs were classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO poisoning or to distribute further malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2731737730738738/Single-Sashimi-Sushi-3-by-Camy-Tang.pdf
    • http://cefasfese.4pu.com/1731738730738739735/Weddings-and-Wasabi-Sushi-4-by-Camy-Tang.pdf
    • http://cefasfese.4pu.com/1739736736738735/The-Sword-Dancer-Lovers-and-Rebels-1-Tang-Dynasty-4-by-Jeannie-Lin.pdf
    • http://cefasfese.4pu.com/4731733732732734/Unlocking-the-Kingdom-The-Battle-for-Walt-Disney-s-Magic-Kingdom-by-Jeff-Dixon.pdf
    • http://cefasfese.4pu.com/1739736736736735/The-Key-to-the-Kingdom-Unlocking-Walt-Disney-s-Magic-Kingdom-by-Jeff-Dixon.pdf
    • http://cefasfese.4pu.com/4734735731731734/Of-Such-Is-The-Kingdom-Parts-I-amp-II-A-Novel-of-The-Christ-and-the-Roman-Empire-Kingdom-1-by-James-M-Becher.pdf
    • http://cefasfese.4pu.com/1735730732739736/Of-Such-Is-the-Kingdom-Parts-I-amp-II-A-Novel-of-the-Christ-and-the-Roman-Empire-Kingdom-1-by-James-M-Becher.pdf
    • http://cefasfese.4pu.com/7737733736730739/Kingdom-Principles-Preparing-for-Kingdom-Experience-and-Expansion-by-Myles-Munroe.pdf
    • http://cefasfese.4pu.com/1733736731736733/Kingdom-Series-Collection-Books-1-3-Kingdom-1-3-by-Marie-Hall.pdf
    • http://cefasfese.4pu.com/3731735730736736/Kingdom-Series-Collection-Books-1-3-Kingdom-1-3-by-Marie-Hall.pdf
    • http://cefasfese.4pu.com/1730736732730739739/Yin-Yu-Tang-The-Architecture-and-Daily-Life-of-a-Chinese-House-by-Nancy-Berliner.pdf
    • http://cefasfese.4pu.com/4731735739732731/Disrobed-How-Clothing-Predicts-Economic-Cycles-Saves-Lives-and-Determines-the-Future-by-Syl-Tang.pdf
    • http://cefasfese.4pu.com/1735737738738732/Kingdom-s-Edge-Kingdom-3-by-Chuck-Black.pdf
    • http://cefasfese.4pu.com/1730736737737731/The-Kingdom-Within-The-Kingdom-Within-1-by-Samantha-Gillespie.pdf
    • http://cefasfese.4pu.com/4734732738732734/Kingdom-Hearts-The-Complete-Series-Kingdom-Hearts-1-4-by-Shiro-Amano.pdf
    • http://cefasfese.4pu.com/1731738730738739731/The-Sushi-Toss-Sushi-1-1-by-Camy-Tang.pdf
    • http://cefasfese.4pu.com/3731737730736730/The-Canticle-Kingdom-The-Canticle-Kingdom-1-by-Michael-D-Young.pdf
    • http://cefasfese.4pu.com/8735737737730/Kingdom-Hearts-Vol-1-Kingdom-Hearts-1-by-Shiro-Amano.pdf
    • http://cefasfese.4pu.com/7732735737737733/Solutions-manual-to-accompany-General-chemistry-third-edition-and-General-chemistry-with-qualitative-analysis-third-edition-by-Whitten-Gailey-Davis-Saunders-golden-sunburst-series-by-Yi-Noo-Tang.pdf
    • http://cefasfese.4pu.com/1733732737730730/Magic-Kingdom-for-Sale-1-5-Magic-Kingdom-for-Sale-1-5-by-Terry-Brooks.pdf