Malicious PDF — malware analysis report

Static analysis result for SHA-256 77bdc575bb0f7742…

MALICIOUS

PDF

16.5 KB Created: 2019-04-30 08:47:38 +01:00 Authoring application: mPDF 5.7
MD5: 17a7b2a43421e14198de272868163346 SHA-1: 581e24cdf5e2a4490cdf64b770179b454751c019 SHA-256: 77bdc575bb0f7742bb5bf3d643dfeab4d6818e46d85571a90a915900e3f6217a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to external sites. While the URLs themselves are currently classified as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content. The ML_NYX_PDF_MALICIOUS classifier also flagged this file with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2738734734730730/Raised-by-Wolves-Raised-by-Wolves-1-by-Jennifer-Lynn-Barnes.pdf
    • http://cefasfese.4pu.com/2735737731738/Raised-by-Wolves-Raised-by-Wolves-1-by-Jennifer-Lynn-Barnes.pdf
    • http://cefasfese.4pu.com/1734731739731731/Matelots-Raised-By-Wolves-2-by-W-A-Hoffman.pdf
    • http://cefasfese.4pu.com/4738739739736733/St-Lucy-s-Home-For-Girls-Raised-By-Wolves-by-Karen-Russell.pdf
    • http://cefasfese.4pu.com/4736732731739739/The-Wolves-of-Willoughby-Chase-The-Wolves-Chronicles-1-by-Joan-Aiken.pdf
    • http://cefasfese.4pu.com/4738730735738738/A-Cougar-Among-Wolves-Black-Hills-Wolves-45-by-Kali-Willows.pdf
    • http://cefasfese.4pu.com/2733736734738736/The-Wolves-of-Willoughby-Chase-The-Wolves-Chronicles-1-by-Joan-Aiken.pdf
    • http://cefasfese.4pu.com/2737737737739736/Dances-with-Wolves-Highland-Wolves-1-by-Mandy-Monroe.pdf
    • http://cefasfese.4pu.com/3734734738737734/Among-Wolves-Wolves-of-Llis-1-by-Nancy-K-Wallace.pdf
    • http://cefasfese.4pu.com/2732732730733731/Every-Other-Day-by-Jennifer-Lynn-Barnes.pdf
    • http://cefasfese.4pu.com/2735731730733737/Platinum-Golden-2-by-Jennifer-Lynn-Barnes.pdf
    • http://cefasfese.4pu.com/1737738733732732/Fate-Tattoo-2-by-Jennifer-Lynn-Barnes.pdf
    • http://cefasfese.4pu.com/4737730736731738/Fate-Tattoo-2-by-Jennifer-Lynn-Barnes.pdf
    • http://cefasfese.4pu.com/5736731739738735/The-Lovely-and-the-Lost-by-Jennifer-Lynn-Barnes.pdf
    • http://cefasfese.4pu.com/1732732731739734/The-Long-Game-The-Fixer-2-by-Jennifer-Lynn-Barnes.pdf
    • http://cefasfese.4pu.com/2737738734735730/The-Riveauxs-Wolves-of-the-Rising-Sun-Vol-1-Box-Set-Wolves-of-the-Rising-Sun-1-3-Mating-Season-by-Kenzie-Cox.pdf
    • http://cefasfese.4pu.com/4738739734733736/Raised-from-the-Ground-by-Jos-Saramago.pdf
    • http://cefasfese.4pu.com/4737730733738735/Raised-in-Captivity-Why-Does-America-Fail-It-s-Children-by-Lucia-Hodgson.pdf
    • http://cefasfese.4pu.com/8730737731739/Founding-Mothers-The-Women-Who-Raised-Our-Nation-by-Cokie-Roberts.pdf
    • http://cefasfese.4pu.com/1730738731735738739/Raised-from-the-Dead-The-Essence-of-Christian-Knowing-Being-amp-Doing-A-Devotional-for-Thinkers-by-Don-Forss.pdf