Malicious PDF — malware analysis report

Static analysis result for SHA-256 56a0752a7ffbea3d…

MALICIOUS

PDF

17.0 KB Created: 2019-08-02 07:36:10 +01:00 Authoring application: mPDF 5.7
MD5: 9fb5371cc44ebc98d15bdf85b3b5f493 SHA-1: 0e37c67fbaf2d9eff69fbc3817cb168c1fd357c3 SHA-256: 56a0752a7ffbea3d4ee0884d970296c241b09110887d73b14396b2de025bd5fe
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS classifier also flagged the document with high confidence. While no scripts were extracted, the structure suggests a link farm designed to redirect users to potentially malicious content or for SEO manipulation. The primary IOCs are the numerous URLs embedded within the document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9732731738733736/The-Metamorphosis-1000-Copy-Limited-Edition-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/9732732730730739/The-Portrait-of-a-Lady-1000-Copy-Limited-Edition-by-Henry-James.pdf
    • http://cefasfese.4pu.com/9732732730730736/The-Island-of-Doctor-Moreau-1000-Copy-Limited-Edition-by-H-G-Wells.pdf
    • http://cefasfese.4pu.com/9732732730735733/The-Lost-World-1000-Copy-Limited-Edition-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/9732731739734730/The-Tale-of-Peter-Rabbit-1000-Copy-Limited-Edition-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/9732731738733732/The-Picture-of-Dorian-Gray-1000-Copy-Limited-Edition-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/9732731738733734/The-Count-of-Monte-Cristo-1000-Copy-Limited-Edition-by-Alexandre-Dumas.pdf
    • http://cefasfese.4pu.com/9732731739732739/The-Adventures-of-Sherlock-Holmes-Illustrated-1000-Copy-Limited-Edition-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/9732731739739737/Journey-to-the-Center-of-the-Earth-1000-Copy-Limited-Illustrated-Edition-SF-Classic-by-Jules-Verne.pdf
    • http://cefasfese.4pu.com/9732732730735738/The-Legend-of-Sleepy-Hollow-and-Other-Stories-1000-Copy-Limited-Edition-Or-the-Sketch-Book-of-Geoffrey-Crayon-Gent-by-Washington-Irving.pdf
    • http://cefasfese.4pu.com/7736732733735734/The-Trial-by-Franz-Kafka-Classic-Annotated-and-Translated-Edition-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/1733739731739737/The-Metamorphosis-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/6730737738738736/metamorphosis-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/6731738739735732/The-Metamorphosis-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/1730739738738736736/The-Metamorphosis-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/7730732737736735/The-Metamorphosis-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/4731738734738735/The-Metamorphosis-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/5733731730739730/Metamorphosis-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/3738737732734/The-Metamorphosis-and-Other-Stories-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/1730738732730733733/The-Metamorphosis-Die-Verwandlung-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/973273173973