Malicious PDF — malware analysis report

Static analysis result for SHA-256 6be81d06ec35469c…

MALICIOUS

PDF

27.3 KB Created: 2019-05-01 05:15:45 +01:00 Authoring application: mPDF 5.7
MD5: be10d5645032dfedbc53e0afc4eecaf3 SHA-1: 0a91e61e8beda338ceb153c137cd7c6f716ae9f9 SHA-256: 6be81d06ec35469cf4b86c96193eb81b5d2dfb4c10a2fd97704207f554e859cf
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign content, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2738737734733737/Our-Southern-Highlanders-A-Narrative-of-Adventure-in-the-Southern-Appalachians-and-a-Study-of-Life-Among-the-Mountaineers-by-Horace-Kephart.pdf
    • http://cefasfese.4pu.com/2738738731737731/Mountain-Nature-A-Seasonal-Natural-History-of-the-Southern-Appalachians-by-Jennifer-Frick-Ruppert.pdf
    • http://cefasfese.4pu.com/1739737734735732/Appalachia-on-Our-Mind-The-Southern-Mountains-and-Mountaineers-in-the-American-Consciousness-1870-1920-by-Henry-D-Shapiro.pdf
    • http://cefasfese.4pu.com/2733739734737732/The-United-States-of-Appalachia-How-Southern-Mountaineers-Brought-Independence-Culture-and-Enlightenment-to-America-by-Jeff-Biggers.pdf
    • http://cefasfese.4pu.com/1730735735734732730/A-Mess-of-Greens-Southern-Gender-and-Southern-Food-by-Elizabeth-S-D-Engelhardt.pdf
    • http://cefasfese.4pu.com/1732737732734733/My-Big-Fat-Southern-Gay-Wedding-A-Southern-Thing-3-by-Sara-York.pdf
    • http://cefasfese.4pu.com/8735732733737730/Southern-Attraction-Southern-Heart-3-by-Kaylee-Ryan.pdf
    • http://cefasfese.4pu.com/1734732732734733/The-New-South-Creed-A-Study-in-Southern-Mythmaking-by-Paul-M-Gaston.pdf
    • http://cefasfese.4pu.com/4738735738737737/Southern-Living-Fix-It-and-Freeze-It-Heat-It-and-Eat-It-A-quick-cook-guide-to-over-200-make-ahead-dishes-by-Southern-Living-Inc-.pdf
    • http://cefasfese.4pu.com/9739732735730738/The-Cherokees-of-the-Smoky-Mountains-by-Horace-Kephart.pdf
    • http://cefasfese.4pu.com/9739732732737739/Smoky-Mountain-Magic-by-Horace-Kephart.pdf
    • http://cefasfese.4pu.com/5736736733735735/Exercises-in-Dedication-of-George-Finley-Bovard-Administration-Auditorium-Hoose-Hall-of-Philosophy-and-Stowell-Hall-of-Education-University-of-Southern-California-1921-by-University-of-Southern-California.pdf
    • http://cefasfese.4pu.com/4738736734731739/Road-Belong-Cargo-A-Study-Of-The-Cargo-Movement-In-The-Southern-Madang-District-New-Guinea-by-Peter-Lawrence.pdf
    • http://cefasfese.4pu.com/2738730738734731/Murder-Gets-a-Life-Southern-Sisters-5-by-Anne-George.pdf
    • http://cefasfese.4pu.com/2736737738732739/Women-s-Life-and-Work-in-the-Southern-Colonies-by-Julia-Cherry-Spruill.pdf
    • http://cefasfese.4pu.com/1736731738730735/The-Little-Way-of-Ruthie-Leming-A-Southern-Girl-a-Small-Town-and-the-Secret-of-a-Good-Life-by-Rod-Dreher.pdf
    • http://cefasfese.4pu.com/4734737738733737/The-Story-of-Earth-amp-Life-A-Southern-African-Perspective-on-a-4-6-Billion-Year-Journey-by-Terence-McCarthy.pdf
    • http://cefasfese.4pu.com/3731735732739737/Southern-Bloodlines-Southern-Bloodlines-1-by-R-Malone.pdf
    • http://cefasfese.4pu.com/7732739735735/The-Candy-Men-The-Rollicking-Life-amp-Times-of-the-Notorious-Novel-Candy-by-Nile-Southern.pdf
    • http://cefasfese.4pu.com/1739737734734733/Coal-Towns-Life-Work-and-Culture-in-Company-Towns-of-Southern-Appalachia-1880-1960-by-Crandall-A-Shifflett.pdf