Malicious PDF — malware analysis report

Static analysis result for SHA-256 63b5853d0752ba8d…

MALICIOUS

PDF

19.5 KB Created: 2019-11-07 09:28:31 +00:00 Authoring application: mPDF 5.7
MD5: eb185d4e2b18b2a0e31a747cba5b577a SHA-1: d4f2d035e5cea2b6cd0e3158a1df791076751eee SHA-256: 63b5853d0752ba8db078d925a1e03f4cd200b5f8dc128cea1d807cda7a15b99b
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3736739730735735/Girl-with-the-Dragon-Tattoo-Trilogy-Bundle-The-Girl-with-the-Dragon-Tattoo-The-Girl-Who-Played-with-Fire-The-Girl-Who-Kicked-the-Hornet-s-Nest-by-Stieg-Larsson.pdf
    • http://cefasfese.4pu.com/2738735739739735/Tattoo-Girl-by-Brooke-Stevens.pdf
    • http://cefasfese.4pu.com/8735734730736/The-Girl-with-the-Dragon-Tattoo-Millennium-1-by-Stieg-Larsson.pdf
    • http://cefasfese.4pu.com/3730731735732739/The-Girl-with-the-Dragon-Tattoo-Millennium-1-by-Stieg-Larsson.pdf
    • http://cefasfese.4pu.com/1730732736730738731/The-Girl-with-the-Dragon-Tattoo-Millennium-1-by-Stieg-Larsson.pdf
    • http://cefasfese.4pu.com/3733734731738735/The-Girl-with-the-Dragon-Tattoo-Millennium-1-by-Stieg-Larsson.pdf
    • http://cefasfese.4pu.com/1731737737737731739/The-Girl-with-the-Dragon-Tattoo-in-Vietnamese-by-Stieg-Larsson.pdf
    • http://cefasfese.4pu.com/2730737730731730/The-Girl-with-the-Cat-Tattoo-Cool-Cats-1-by-Theresa-Weir.pdf
    • http://cefasfese.4pu.com/1731735738735731734/The-Girl-With-the-Dragon-Tattoo-Wiki-content-for-your-Kindle-by-AMencher19.pdf
    • http://cefasfese.4pu.com/1730735738731738735/Ratgeber-Tattoo-Dein-Weg-zum-perfekten-Tattoo-by-Gregor-Ulitsch.pdf
    • http://cefasfese.4pu.com/4738733737737738/Tattoo-Tattoo-1-by-Jennifer-Lynn-Barnes.pdf
    • http://cefasfese.4pu.com/7739735739735734/Patriote-Movement-Lower-Canada-Rebellion-Bibliography-of-the-1837-1838-Insurrections-in-Lower-Canada-Ceinture-Flechee-by-Source-Wikipedia.pdf
    • http://cefasfese.4pu.com/4735734733735733/The-Dragon-with-the-Girl-Tattoo-Paranormal-Dating-Agency-Dragon-Guard-16-by-Julia-Mills.pdf
    • http://cefasfese.4pu.com/6735734736/The-Girl-Who-Came-Back-by-Kerry-Wilkinson.pdf
    • http://cefasfese.4pu.com/7733731736738/The-Come-back-Girl-by-Katie-Price.pdf
    • http://cefasfese.4pu.com/4735734737738734/The-Girl-Who-Came-Back-to-Life-by-Craig-Staufenberg.pdf
    • http://cefasfese.4pu.com/3736731739732739/I-Have-to-Go-Back-to-1994-and-Kill-a-Girl-Poems-by-Karyna-McGlynn.pdf
    • http://cefasfese.4pu.com/2737730739730734/Tattoo-Thief-Tattoo-Thief-1-by-Heidi-Joy-Tretheway.pdf
    • http://cefasfese.4pu.com/2739736731739736/Gluten-Free-Girl-How-I-Found-the-Food-That-Loves-Me-Back-amp-How-You-Can-Too-by-Shauna-James-Ahern.pdf
    • http://cefasfese.4pu.com/8734733738730737/Back-RX-A-15-Minute-a-Day-Yoga--and-Pilates-Based-Program-to-End-Low-Back-Pain-by-Vijay-Vad.pdf