Malicious PDF — malware analysis report

Static analysis result for SHA-256 5828d0a2e236909c…

MALICIOUS

PDF

24.4 KB Created: 2019-06-04 19:49:07 +01:00 Authoring application: mPDF 5.7
MD5: 14b2ac2cb859e97261fd0de9a658636d SHA-1: 80a05b344f01bec27fd4e61eb43be3abaa13db93 SHA-256: 5828d0a2e236909c53eeb444bf44b1a0f76a5ff24615fd99f6f13aed9da2951a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified as a PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged the document as malicious. While no scripts were extracted, the sheer volume of links suggests a malicious intent, possibly to distribute malware or conduct phishing by directing users to external sites. The document body was unreadable, preventing further analysis of its specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4735734738739739/212-Ellie-Hatcher-3-by-Alafair-Burke.pdf
    • http://cefasfese.4pu.com/2734733733738739/Never-Tell-Ellie-Hatcher-4-by-Alafair-Burke.pdf
    • http://cefasfese.4pu.com/6731734735730738/All-Day-and-a-Night-Ellie-Hatcher-5-by-Alafair-Burke.pdf
    • http://cefasfese.4pu.com/2733731732737730/Angel-s-Tip-Ellie-Hatcher-2-by-Alafair-Burke.pdf
    • http://cefasfese.4pu.com/1739737734737735/Dead-Connection-An-Ellie-Hatcher-Novel-by-Alafair-Burke.pdf
    • http://cefasfese.4pu.com/3736730734738739/Close-Case-Samantha-Kincaid-3-by-Alafair-Burke.pdf
    • http://cefasfese.4pu.com/4737738734733733/Judgment-Calls-Samantha-Kincaid-1-by-Alafair-Burke.pdf
    • http://cefasfese.4pu.com/7735735732737734/James-Lee-Burke-A-Dave-Robicheaux-Audio-Collection-A-Stained-White-Radiance-In-The-Electric-Mist-With-Confederate-Dead-Dixie-City-Jam-Burning-Angel-and-Cadillac-Jukebox-by-James-Lee-Burke.pdf
    • http://cefasfese.4pu.com/1738739739738/My-Awesome-Place-Autobiography-of-Cheryl-Burke-by-Cheryl-Burke.pdf
    • http://cefasfese.4pu.com/3730731731737733/Wrong-Hill-to-Die-On-Alafair-Tucker-6-by-Donis-Casey.pdf
    • http://cefasfese.4pu.com/7735735732735738/JAMES-LEE-BURKE---THE-ROBICHEAUX-COLLECTION-by-James-Lee-Burke.pdf
    • http://cefasfese.4pu.com/7735735733738731/JAMES-LEE-BURKE-BOOKS-AND-ALL-SHORT-STORIES-CHECKLIST-AND-SUMMARIES---INCLUDES-LATEST-DAVE-ROBICHEAUX---JAMES-LEE-BURKE-SHORT-STORIES-AND-STANDALONE-NOVELS-AND-CHECKLIST-BEST-READING-ORDER-Book-56-by-Avid-Reader.pdf
    • http://cefasfese.4pu.com/7735735733738734/James-Lee-Burke-Books-Checklist-Reading-Order-of-Billy-Bob-Holland-Series-Dave-Robicheaux-Series-Hackberry-Holland-Series-and-List-of-All-James-Lee-Burke-Books-Over-35-Books-by-Kevin-Hanson.pdf
    • http://cefasfese.4pu.com/7735735733738732/James-Lee-Burke-Books-2017-Checklist-Reading-Order-of-Billy-Bob-Holland-Series-Dave-Robicheaux-Series-Hackberry-Holland-Series-and-List-of-All-James-Lee-Burke-Books-Over-35-Books-by-Primary-List.pdf
    • http://cefasfese.4pu.com/7734738739/Semiosis-by-Sue-Burke.pdf
    • http://cefasfese.4pu.com/3730733734733/46-by-Melissa-Burke.pdf
    • http://cefasfese.4pu.com/5730732731733735/Passion-s-Prize-by-E-E-Burke.pdf
    • http://cefasfese.4pu.com/2736739730739738/Connections-by-James-Burke.pdf
    • http://cefasfese.4pu.com/2735731732738730/Connections-by-James-Burke.pdf
    • http://cefasfese.4pu.com/1732737739734739/Kin-by-Kealan-Patrick-Burke.pdf
    • http://cefasfese.4pu.com/7735735732737734/James-Lee-Burke-A-Dave-Robicheaux-Audio-Collection-A-Stained-White-Radiance-In-The-Electric-Mist-With-Confederate-Dead-Dixie-City-Jam-Bu