Malicious PDF — malware analysis report

Static analysis result for SHA-256 5fbde77283bf5109…

MALICIOUS

PDF

26.5 KB Created: 2019-05-02 05:06:31 +01:00 Authoring application: mPDF 5.7
MD5: 6ec4be2f241fbc0720b9335a714c0650 SHA-1: 0bc790d3c1657640a40966c6f0198a9d6aab38e4 SHA-256: 5fbde77283bf5109065b20c59ab146b6540dacb11be77fc68dfe9bdcd6e51ac1
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the use of numeric slugs in the URLs suggest a potential attempt to manipulate search engine rankings or to host malicious content disguised as legitimate files. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2733738735731733/The-Box-How-the-Shipping-Container-Made-the-World-Smaller-and-the-World-Economy-Bigger-by-Marc-Levinson.pdf
    • http://cefasfese.4pu.com/1730733731732731/The-Box-How-the-Shipping-Container-Made-the-World-Smaller-and-the-World-Economy-Bigger-by-Marc-Levinson.pdf
    • http://cefasfese.4pu.com/6734730736738730/The-Modern-World-System-III-The-Second-Era-of-Great-Expansion-of-the-Capitalist-World-Economy-1730s-1840s-by-Immanuel-Wallerstein.pdf
    • http://cefasfese.4pu.com/1737739733732739/Greater-Dream-Bigger-Start-Smaller-Ignite-God-s-Vision-for-Your-Life-by-Steven-Furtick.pdf
    • http://cefasfese.4pu.com/7731738737738730/The-World-s-Key-Industry-History-and-Economics-of-International-Shipping-by-Gelina-Harlaftis.pdf
    • http://cefasfese.4pu.com/7735731731738737/Romances-Tales-and-Smaller-Pieces-of-M-de-Voltaire-Vol-1-of-2-Zadig-The-World-as-It-Goes-Micromegas-The-White-Bull-Travels-of-Scaramentado-How-Far-We-Ought-to-Impose-Upon-the-People-by-Voltaire.pdf
    • http://cefasfese.4pu.com/8737739734736731/Understanding-the-World-Economy-by-Tony-Cleaver.pdf
    • http://cefasfese.4pu.com/2735733734734736/Into-The-Open-Economy-How-Everything-You-Know-About-The-World-Is-About-To-Change-by-Colin-R-Turner.pdf
    • http://cefasfese.4pu.com/5731738739731737/National-Purpose-in-the-World-Economy-by-Rawi-Abdelal.pdf
    • http://cefasfese.4pu.com/7739732736732735/Philosophy-of-Economy-The-World-as-Household-by-Sergius-Bulgakov.pdf
    • http://cefasfese.4pu.com/1731734732737733735/Surgical-Efficiency-and-Economy-See-Proceedings-of-the-3rd-World-Conference-by-P-Dohrmann.pdf
    • http://cefasfese.4pu.com/4730731731736737/The-Commanding-Heights-The-Battle-for-the-World-Economy-by-Daniel-Yergin.pdf
    • http://cefasfese.4pu.com/7737730731736735/Global-Shift-Mapping-the-Changing-Contours-of-the-World-Economy-by-Peter-Dicken.pdf
    • http://cefasfese.4pu.com/1738737732734731/The-New-World-Order---Whether-It-Is-Attainable-How-It-Can-Be-Attained-and-What-Sort-of-World-a-World-at-Peace-Will-Have-to-Be-by-H-G-Wells.pdf
    • http://cefasfese.4pu.com/5731739738735730/America-and-the-World-Political-Economy-Atlantic-Dreams-and-National-Realities-by-David-Calleo.pdf
    • http://cefasfese.4pu.com/3731737731739737/A-World-Made-of-Fire-by-Mark-Childress.pdf
    • http://cefasfese.4pu.com/1733739733735730/The-World-Jones-Made-by-Philip-K-Dick.pdf
    • http://cefasfese.4pu.com/4730738737730733/Why-Were-They-Built-Six-Man-Made-Wonders-of-the-World-by-Scott-Hayden.pdf
    • http://cefasfese.4pu.com/2736738731736735/Domesticated-Evolution-in-a-Man-Made-World-by-Richard-C-Francis.pdf
    • http://cefasfese.4pu.com/2732738730739734/Bailout-Nation-How-Greed-and-Easy-Money-Corrupted-Wall-Street-and-Shook-the-World-Economy-by-Barry-Ritholtz.pdf