Malicious PDF — malware analysis report

Static analysis result for SHA-256 62fd184221784b4a…

MALICIOUS

PDF

16.4 KB Created: 2019-05-02 07:39:19 +01:00 Authoring application: mPDF 5.7
MD5: fbfea23fb7f20bbcbff75caf25796ea9 SHA-1: eab5b9a07f0971929560e783429dd67b4d2cb689 SHA-256: 62fd184221784b4af19a987724dc48405b4c3c5d109a7a2879d2ef1c24e9e694
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which suggests a link farm or a method to distribute malicious content. The ML classifier also flagged the document as malicious. While the document body is heavily obfuscated, the presence of numerous external links points towards a potential phishing or content distribution attack. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1733730734738/Face-to-Face-Harlequin-Temptation-258-by-Julie-Meyers.pdf
    • http://cefasfese.4pu.com/9732737736737737/Face-To-Face-Encounters-Between-Jews-amp-Blacks-Photographs-And-Text-by-Laurence-Salzmann.pdf
    • http://cefasfese.4pu.com/9732735734730730/Godfathers-of-Crime-Face-to-Face-with-India-s-Most-Wanted-by-Sheela-Raval.pdf
    • http://cefasfese.4pu.com/1734739732733736/A-Crime-So-Monstrous-Face-to-Face-with-Modern-Day-Slavery-by-E-Benjamin-Skinner.pdf
    • http://cefasfese.4pu.com/7736736733739739/Un-d-sir-indomptable---Troublant-face---face-by-Julia-James.pdf
    • http://cefasfese.4pu.com/2737731730737739/This-Was-Your-Life-Preparing-to-Meet-God-Face-to-Face-by-Rick-Howard.pdf
    • http://cefasfese.4pu.com/7735735735738/Now-Face-to-Face-Tamworth-Saga-3-by-Karleen-Koen.pdf
    • http://cefasfese.4pu.com/2737738737731/Face-to-Face-by-Marion-Dane-Bauer.pdf
    • http://cefasfese.4pu.com/2735739735734736/Batman-Face-the-Face-by-James-Robinson.pdf
    • http://cefasfese.4pu.com/4731730730738737/Skull-Face-and-Others-Skull-Face-Omnibus-Volume-1-by-Robert-E-Howard.pdf
    • http://cefasfese.4pu.com/9730738732734737/You-Can-Do-It-Stinky-Face-A-Stinky-Face-Book-by-Lisa-McCourt.pdf
    • http://cefasfese.4pu.com/5731731733732/Guitar-Face-Guitar-Face-1-by-Sasha-Marshall.pdf
    • http://cefasfese.4pu.com/7734735734730/Guitar-Face-Guitar-Face-1-by-Sasha-Marshall.pdf
    • http://cefasfese.4pu.com/2731737733737739/Open-Invitation-Harlequin-Temptation-74-by-Tiffany-White.pdf
    • http://cefasfese.4pu.com/2737731738736732/Face-to-Face-Praying-the-Scriptures-for-Intimate-Worship-Praying-the-Scriptures-for-Intimate-Worship-v-1-by-Kenneth-D-Boa.pdf
    • http://cefasfese.4pu.com/1731733739734730/A-Face-in-Every-Window-by-Han-Nolan.pdf
    • http://cefasfese.4pu.com/4731738739734730/Face-Value-Sanctuary-3-by-R-J-Scott.pdf
    • http://cefasfese.4pu.com/3736737739734735/In-My-Face-by-Chamera-Sampson.pdf
    • http://cefasfese.4pu.com/4733736739739735/I-Can-Face-Tomorrow-by-H-C-Robins.pdf
    • http://cefasfese.4pu.com/4738736737734739/The-Face-of-War-by-Martha-Gellhorn.pdf