Malicious PDF — malware analysis report

Static analysis result for SHA-256 76746e1617ec0747…

MALICIOUS

PDF

24.3 KB Created: 2019-11-09 22:39:03 +00:00 Authoring application: mPDF 5.7
MD5: de96a6407cc91d141b93b60295ea3260 SHA-1: 84fc41464f925e2635ea260b327711f4986e5b22 SHA-256: 76746e1617ec0747afc6db5ac83f460d7a4ffe4ae816f493e9a74b404b2dc2e8
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded external links, forming a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern observed is the distribution of a link farm, likely intended to direct users to malicious or deceptive content, potentially as a form of phishing or SEO poisoning. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9716

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4732733736731739/Typewriting-Behavior-Psychology-Applied-to-Teaching-and-Learning-Typewriting-by-August-Dvorak.pdf
    • http://cefasfese.4pu.com/8734737730734733/Educational-Psychology-for-Learning-and-Teaching-by-Sue-Duchesne-.pdf
    • http://cefasfese.4pu.com/8732732732732736/Criminal-Psychology-Topics-in-Applied-Psychology-by-David-Canter.pdf
    • http://cefasfese.4pu.com/1731734736735730738/Psychology-in-Organizations-Issues-from-an-Applied-Area-by-Kathrin-Heinitz.pdf
    • http://cefasfese.4pu.com/1731730733737735731/Teaching-Assistant-s-Handbook-for-Level-2-Supporting-Teaching-and-Learning-in-Schools-Teena-Kamen-by-Kamen.pdf
    • http://cefasfese.4pu.com/6739730739736731/Place-Advantage-Applied-Psychology-for-Interior-Architecture-by-Sally-Augustin.pdf
    • http://cefasfese.4pu.com/7737737737735732/Learning-and-Behavior-A-Contemporary-Synthesis-by-Mark-E-Bouton.pdf
    • http://cefasfese.4pu.com/3735733739737738/The-Writer-s-Guide-to-Psychology-How-to-Write-Accurately-about-Psychological-Disorders-Clinical-Treatment-and-Human-Behavior-by-Carolyn-Kaufman.pdf
    • http://cefasfese.4pu.com/5732731735730733/Task-Based-Language-Learning-and-Teaching-by-Rod-Ellis.pdf
    • http://cefasfese.4pu.com/6731730739730738/So-What-Do-They-Really-Know-Assessment-That-Informs-Teaching-and-Learning-by-Cris-Tovani.pdf
    • http://cefasfese.4pu.com/8735731738735/Learning-How-to-Learn-Psychology-and-Spirituality-in-the-Sufi-Way-by-Idries-Shah.pdf
    • http://cefasfese.4pu.com/5730733739733731/Teaching-amp-Researching-Language-Learning-Strategies-by-Rebecca-L-Oxford.pdf
    • http://cefasfese.4pu.com/5730733739733739/Culturally-and-Linguistically-Responsive-Teaching-and-Learning-by-Sharroky-Hollie.pdf
    • http://cefasfese.4pu.com/5731731733738730/Vocabulary-Matrix-Understanding-Learning-Teaching-by-Michael-McCarthy.pdf
    • http://cefasfese.4pu.com/6732739739739733/Radical-Reflections-Passionate-Opinions-on-Teaching-Learning-and-Living-by-Mem-Fox.pdf
    • http://cefasfese.4pu.com/1731737734738731733/The-Marvelous-Learning-Animal-What-Makes-Human-Behavior-Unique-by-Arthur-W-Staats.pdf
    • http://cefasfese.4pu.com/1730731737731730735/Teaching-the-FE-Curriculum-Encouraging-active-learning-in-the-classroom-by-Mark-Weyers.pdf
    • http://cefasfese.4pu.com/1731733737730732735/Big-Truths-for-Young-Hearts-Teaching-and-Learning-the-Greatness-of-God-by-Bruce-A-Ware.pdf
    • http://cefasfese.4pu.com/1737734732737732/Unfinished-Revolution-Learning-Human-Behavior-Community-and-Political-Paradox-by-John-Abbott.pdf
    • http://cefasfese.4pu.com/8736739734736731/Supporting-Positive-Behavior-Responding-to-Behavior-Guiding-Challenging-Behavior-Assorted-Pack-Winning-Ways-for-Early-Childhood-Professionals-by-Gigi-Schweikert.pdf