Malicious PDF — malware analysis report

Static analysis result for SHA-256 6323a1638ccc50ad…

MALICIOUS

PDF

19.3 KB Created: 2019-05-03 07:24:33 +01:00 Authoring application: mPDF 5.7
MD5: e83fd327fefb99e0a9bb3fd31c34d79b SHA-1: c7be8f888dc0e9c90157810008798faa4ea4ecec SHA-256: 6323a1638ccc50ad7df5de9980bead190c0bdbd1722528fdcfc41387054795e8
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links were classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4739733731737736/My-Depression-A-Picture-Book-by-Elizabeth-Swados.pdf
    • http://cefasfese.4pu.com/9733737737733730/This-REALLY-is-a-Picture-Book-Picture-Books-from-KPMedia-Artistic-Collective-by-Kathleen-Odenthal.pdf
    • http://cefasfese.4pu.com/1730734731731739735/From-Picture-to-Picture-Book-by-Ali-Mitgutsch.pdf
    • http://cefasfese.4pu.com/4730733734739732/Go-Away-Dog-An-I-Can-Read-Book-Picture-Book-Series-by-Joan-L-Nodset.pdf
    • http://cefasfese.4pu.com/1730734731732736730/The-Busy-Book-A-Picture-Book-by-Ali-Mitgutsch.pdf
    • http://cefasfese.4pu.com/2739731738730737/Depression-Strategies-Practical-Tools-for-Professionals-Treating-Depression-by-Claudia-Black.pdf
    • http://cefasfese.4pu.com/3738735736733736/Your-Depression-Map-Find-the-Source-of-Your-Depression-and-Chart-Your-Own-Recovery-by-Randy-J-Paterson.pdf
    • http://cefasfese.4pu.com/8732735730730733/Depression-Self-Help-Blueprint-The-Physiological-Way-Through-Depression-And-Out-Of-All-That-Pain-by-Witek-Kozlowski.pdf
    • http://cefasfese.4pu.com/3735732734737739/Sunbathing-In-The-Rain-A-Cheerful-Book-About-Depression-by-Gwyneth-Lewis.pdf
    • http://cefasfese.4pu.com/3733737730738733/This-Is-Not-a-Picture-Book-by-Sergio-Ruzzier.pdf
    • http://cefasfese.4pu.com/4731736733731730/Once-Upon-a-Twice-Picture-Book-by-Denise-Doyen.pdf
    • http://cefasfese.4pu.com/6735735735732737/My-Flower-pot-Child-s-Picture-Book-by-N-H-Concord.pdf
    • http://cefasfese.4pu.com/6732730737735/Storm-Boy-Picture-Book-by-Colin-Thiele.pdf
    • http://cefasfese.4pu.com/1730730735735731733/Pizza-Day-A-Picture-Book-by-Melissa-Iwai.pdf
    • http://cefasfese.4pu.com/6732732732739737/One-Survivor-s-Guide-for-Beating-Depression-and-Thriving-Thereafter-Simple-Practical-Step-by-Step-Remedies-for-the-Illness-of-Depression-by-Nima-Fard.pdf
    • http://cefasfese.4pu.com/4736736737736731/The-Young-Rider-s-Picture-Book-by-Golden-Gorse.pdf
    • http://cefasfese.4pu.com/8731736732734738/Jim-s-Grandiose-Big-Bible-Picture-Book-by-James-Paterson.pdf
    • http://cefasfese.4pu.com/4730734732734739/A-Picture-Book-of-Cesar-Chavez-by-David-A-Adler.pdf
    • http://cefasfese.4pu.com/7732731738730732/My-First-Chamorro-200-Picture-Word-Book-by-Gerard-Aflague.pdf
    • http://cefasfese.4pu.com/7730730738739/Animals-of-the-Bible-A-Picture-Book-by-Dorothy-P-Lathrop.pdf