Malicious PDF — malware analysis report

Static analysis result for SHA-256 72457796f8d6dd30…

MALICIOUS

PDF

16.1 KB Created: 2019-11-07 13:35:24 +00:00 Authoring application: mPDF 5.7
MD5: 0caa0df68192d569bdbf65f0e4afeabb SHA-1: 67fb17b3cf436e2bfd6f5a7da14634dfccb181d5 SHA-256: 72457796f8d6dd3090c09898699482dfd20357132f9643d8a69bfcf9c30a296a
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to a single domain, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are labeled as confirmed benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a landing page for further malicious activity. The ML_NYX_PDF_MALICIOUS classifier also flagged this document with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3739738735734737/A-Voyage-to-Arcturus-by-David-Lindsay.pdf
    • http://cefasfese.4pu.com/5732733734731738/The-Voyage-by-David-Drake.pdf
    • http://cefasfese.4pu.com/9732739734736736/Australia-Boom-to-Bust-by-Lindsay-David.pdf
    • http://cefasfese.4pu.com/7738737731734732/VOYAGE-A-AUSCHWITZ-LE-DEMON-DE-LA-CERTITUDE-by-David-Haziot.pdf
    • http://cefasfese.4pu.com/8738733733737735/The-Chronicles-of-Narnia-The-Voyage-of-the-Dawn-Treader-by-David-Arnold.pdf
    • http://cefasfese.4pu.com/1735734735738737/Voyage-of-the-Dead-Sovereign-Spirit-Saga-1-by-David-P-Forsyth.pdf
    • http://cefasfese.4pu.com/3730739732733731/Rabbit-Hole---Acting-Edition-by-David-Lindsay-Abaire.pdf
    • http://cefasfese.4pu.com/7736736731736739/Bumper-Book-of-Criss-Cross-by-Arcturus.pdf
    • http://cefasfese.4pu.com/3739738735737732/Voyage-of-Purpose-Spiritual-Wisdom-from-Near-Death-back-to-Life-by-David-Bennett.pdf
    • http://cefasfese.4pu.com/7736734731739732/Channelled-Communications-from-Sirius-Arcturus-Pleiades-amp-Betelgeuse-Books-1---4-by-Mrs-Beryl-Charnley.pdf
    • http://cefasfese.4pu.com/7731736733734732/Gaspar-And-The-Fantastical-Hats-Gaspar-the-Thief-0-5-by-David-A-Lindsay.pdf
    • http://cefasfese.4pu.com/2735736735739732/Norman-Lindsay-Artful-Cats-by-Norman-Lindsay.pdf
    • http://cefasfese.4pu.com/4733735734732731/The-Voyage-of-the-Star-Wolf-Star-Wolf-2-by-David-Gerrold.pdf
    • http://cefasfese.4pu.com/2735734739734737/Voyage-to-the-Bunny-Planet-Voyage-to-the-Bunny-Planet-1-3-Plus-Intro-by-Rosemary-Wells.pdf
    • http://cefasfese.4pu.com/4735739737737737/The-Poetical-Works-of-Adam-Lindsay-Gordon-by-Adam-Lindsay-Gordon.pdf
    • http://cefasfese.4pu.com/1735737732737730/The-Little-Bastards-by-Jim-Lindsay.pdf
    • http://cefasfese.4pu.com/5732733734732733/Voyage-by-Sterling-Hayden.pdf
    • http://cefasfese.4pu.com/7731737731731735/Voyage-of-the-Mistral-by-Madeleine-Ker.pdf
    • http://cefasfese.4pu.com/7737733735731737/Vinland-Voyage-by-J-R-L-Anderson.pdf
    • http://cefasfese.4pu.com/6734736737737/Voyage-of-the-Sea-Wolf-by-Eve-Bunting.pdf