Malicious PDF — malware analysis report

Static analysis result for SHA-256 5e0765ee5399c1f6…

MALICIOUS

PDF

16.0 KB Created: 2019-11-07 14:07:50 +00:00 Authoring application: mPDF 5.7
MD5: 860d536eaa8a46bc4c93f15120f53f1b SHA-1: 2c70dd260612a6ae9ec0c5f917cf2915f8a50869 SHA-256: 5e0765ee5399c1f631572f8a5dbaf991e557ff65c3a5cb3114965daa56f4c140
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links are presented as book titles, likely to trick users into clicking them. The ML_NYX_PDF_MALICIOUS classifier also flagged this document with high confidence. The primary attack pattern involves directing users to external resources, potentially for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731731732734734734/Quiet-Power-The-Secret-Strengths-of-Introverts-by-Susan-Cain.pdf
    • http://cefasfese.4pu.com/3732739735/Quiet-Power-The-Secret-Strengths-of-Introverts-by-Susan-Cain.pdf
    • http://cefasfese.4pu.com/5730733737739734/Quiet-The-Power-of-Introverts-in-a-World-That-Can-t-Stop-Talking-by-Susan-Cain.pdf
    • http://cefasfese.4pu.com/4730731731738739/Quiet-The-Power-of-Introverts-in-a-World-That-Can-t-Stop-Talking-by-Susan-Cain.pdf
    • http://cefasfese.4pu.com/5732736732736/Quiet-The-Power-of-Introverts-in-a-World-That-Can-t-Stop-Talking-by-Susan-Cain.pdf
    • http://cefasfese.4pu.com/9736739734739/Introverts-Leverage-Your-Strengths-for-an-Effective-Job-Search-by-Gabriela-Casineanu.pdf
    • http://cefasfese.4pu.com/5737731734739738/La-force-des-discrets-by-Susan-Cain.pdf
    • http://cefasfese.4pu.com/4732734733731739/Too-Quiet-In-Brooklyn-Fina-Fitzgibbons-1-by-Susan-Russo-Anderson.pdf
    • http://cefasfese.4pu.com/4739731736733736/Silence-The-Power-of-Quiet-in-a-World-Full-of-Noise-by-Thich-Nhat-Hanh.pdf
    • http://cefasfese.4pu.com/3739731733738732/Silence-The-Power-of-Quiet-in-a-World-Full-of-Noise-by-Thich-Nhat-Hanh.pdf
    • http://cefasfese.4pu.com/1738739739736731/A-Quiet-Heart---Discovering-Peace-and-Power-At-Jesus-Feet-by-Carla-Jividen-Peer.pdf
    • http://cefasfese.4pu.com/1730731733738731731/The-Irresistible-Introvert-Harness-the-Power-of-Quiet-Charisma-in-a-Loud-World-by-Michaela-Chung.pdf
    • http://cefasfese.4pu.com/8734737736730732/Three-by-Cain-Serenade-Love-s-Lovely-Counterfeit-The-Butterfly-by-James-M-Cain.pdf
    • http://cefasfese.4pu.com/9737731732737736/Diablo-III-Book-of-Cain-by-Deckard-Cain.pdf
    • http://cefasfese.4pu.com/3735738738731739/The-Grass-Dancer-by-Susan-Power.pdf
    • http://cefasfese.4pu.com/4730730734734738/The-Higher-Power-of-Lucky-by-Susan-Patron.pdf
    • http://cefasfese.4pu.com/3736734738731/The-Power-The-Secret-2-by-Rhonda-Byrne.pdf
    • http://cefasfese.4pu.com/6734732736731731/The-Grand-Adventures-of-Madeline-Cain-Madeline-Cain-1-by-Emily-Craven.pdf
    • http://cefasfese.4pu.com/1733733739733/The-Higher-Power-of-Lucky-The-Hard-Pan-Trilogy-1-by-Susan-Patron.pdf
    • http://cefasfese.4pu.com/3738737736730731/Secret-Desire-by-Susan-D-Taylor.pdf