Malicious PDF — malware analysis report

Static analysis result for SHA-256 5adf91207eacf687…

MALICIOUS

PDF

18.9 KB Created: 2019-06-13 13:10:00 +01:00 Authoring application: mPDF 5.7
MD5: 613f027564ae0742e273da0f8fe9b9ff SHA-1: 5222b7d96913cd6f45c097743f1ee32cdd06d0e6 SHA-256: 5adf91207eacf6877143b128da865d7bb26ff1d29c8359c1966941a2aac5d5e2
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. While the extracted document body text is heavily corrupted, the heuristic 'PDF_SEO_LINK_FARM' indicates the likely intent is to manipulate search engine results or redirect users to potentially malicious content. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6737734738735739/Boucher-s-World-Emergent-by-Bea-Cannon.pdf
    • http://cefasfese.4pu.com/7737738739739733/The-Internet-of-Elsewhere-The-Emergent-Effects-of-a-Wired-World-by-Cyrus-Farivar.pdf
    • http://cefasfese.4pu.com/8730735735735734/The-Appalling-Political-Career-of-Luce-Cannon-The-Sad-Tale-of-of-how-Luce-Cannon-Overreaches-and-is-hoist-with-his-own-Petard-by-J-D-Stewart.pdf
    • http://cefasfese.4pu.com/2737731736739734/Why-We-re-Not-Emergent-by-Kevin-DeYoung.pdf
    • http://cefasfese.4pu.com/1733734737736732/Emergent-Annex-2-by-Rachel-Cohn.pdf
    • http://cefasfese.4pu.com/3730735735736/EMMA-Emergent-Movement-of-Militant-Anarchists-by-Michael-Segedy.pdf
    • http://cefasfese.4pu.com/2737736731737731/Becoming-Beauty-by-Sarah-E-Boucher.pdf
    • http://cefasfese.4pu.com/2731734731737730/Novel-Hearts-by-Rebecca-Boucher.pdf
    • http://cefasfese.4pu.com/6737734738736735/Doctor-Who-Last-Man-Running-by-Chris-Boucher.pdf
    • http://cefasfese.4pu.com/6735732731734734/Scales-Hierarchies-And-Emergent-Properties-In-Ecological-Models-by-Gustavo-A-Anzola-Jurgenson.pdf
    • http://cefasfese.4pu.com/9733735735734736/The-Emergent-Christ-Exploring-the-Meaning-of-Catholic-in-an-Evolutionary-Universe-by-Ilia-Delio.pdf
    • http://cefasfese.4pu.com/1731733735735734739/No-Fuss-Diabetes-Recipes-for-1-or-2-by-Jackie-L-Boucher.pdf
    • http://cefasfese.4pu.com/2736738733739/Anthony-Boucher-A-Biobibliography-by-Jeffrey-Marks.pdf
    • http://cefasfese.4pu.com/6737734738735735/Lost-in-Flight-Complicated-Love-2-by-Neeny-Boucher.pdf
    • http://cefasfese.4pu.com/6737734737738730/20-000-Years-of-Fashion-The-History-of-Costume-and-Personal-Adornment-by-Fran-ois-Boucher.pdf
    • http://cefasfese.4pu.com/5731738736738732/Cannibal-Encounters-Europeans-and-Island-Caribs-1492-1763-by-Philip-P-Boucher.pdf
    • http://cefasfese.4pu.com/6735733737733734/A-Historical-Genealogy-for-Roy-Desjardins-Dit-Lauzier-Dionne-Gendreau-Boucher-by-Betty-A-Lausier-Lindsay.pdf
    • http://cefasfese.4pu.com/2731739736734739/And-Then-We-Ran-by-Katy-Cannon.pdf
    • http://cefasfese.4pu.com/7733731738732738/Necessary-Sacrifices-by-Zoe-Cannon.pdf
    • http://cefasfese.4pu.com/3735731734732738/On-the-Air-by-Geonn-Cannon.pdf