Malicious PDF — malware analysis report

Static analysis result for SHA-256 772d66c3cc001dc8…

MALICIOUS

PDF

16.6 KB Created: 2019-06-04 12:05:32 +01:00 Authoring application: mPDF 5.7
MD5: cb851bac596e8333259d4f6f6b66405e SHA-1: 9b9ae4e5aa570cee54248c17ebdda20de8ad9b2f SHA-256: 772d66c3cc001dc851f536633ed6234433149ebef3fd00ca5d4f88bc9cd2b076
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to external PDF files. While the specific URLs extracted were labeled as confirmed_benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to distribute further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5738734730739737/Complete-Poems-Muriel-Spark-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/5738733739737738/The-Collected-Stories-of-Muriel-Spark-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/1730735730736732/All-the-Stories-of-Muriel-Spark-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/4731731738731737/The-Comforters-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/4735735732738735/The-Finishing-School-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/5738734730739735/Reality-and-Dreams-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/4734739733739738/Memento-Mori-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/3736737736732/Loitering-with-Intent-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/1737733736733736/The-Ballad-of-Peckham-Rye-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/6730735735732737/Albania-s-rights-and-claims-to-independance-and-territorial-integrity-by-Christo-Anastas.pdf
    • http://cefasfese.4pu.com/2736735739738734/The-Girls-of-Slender-Means-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/6730735735732736/Albania-s-Rights-and-Claims-to-Independance-and-Territorial-Integrity-by-Christo-Anastas-Dako.pdf
    • http://cefasfese.4pu.com/8730739737735730/The-Prime-of-Miss-Jean-Brodie-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/4731731736733732/The-Prime-of-Miss-Jean-Brodie-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/4734739733735736/The-Prime-of-Miss-Jean-Brodie-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/4732738737733735/The-Prime-of-Miss-Jean-Brodie-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/3732739737739/The-Prime-of-Miss-Jean-Brodie-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/6730735735738733/Albania-s-Rights-and-Claims-to-Independance-and-Territorial-Integrity---Scholar-s-Choice-Edition-by-Christo-Anastas-1878--From-Old-Dako.pdf
    • http://cefasfese.4pu.com/4734739735733/The-Prime-of-Miss-Jean-Brodie-The-Girls-of-Slender-Means-The-Driver-s-Seat-The-Only-Problem-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/1737734735733733/The-Spark-Series-The-Complete-Box-Set-Spark-1-3-by-Brooke-Cumberland.pdf
    • http://cefasfese.4pu.com/6730735735732