Malicious PDF — malware analysis report

Static analysis result for SHA-256 788922bd721d3e34…

MALICIOUS

PDF

16.7 KB Created: 2019-04-30 19:28:44 +01:00 Authoring application: mPDF 5.7
MD5: d2bdd0b0a3e3e8b8f2f4769b5fc2ed22 SHA-1: 0dc57195373b2822dbd51573717aadd47c86fd91 SHA-256: 788922bd721d3e34b315fbab6275859628f7720efef140889621f73674b0e766
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified as a link farm, which is a common technique for SEO manipulation or directing users to malicious sites. While the document body is unreadable, the heuristic firings and the presence of numerous URLs strongly suggest a malicious intent to redirect the user. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9731736737734/Childtimes-A-Three-Generation-Memoir-by-Eloise-Greenfield.pdf
    • http://cefasfese.4pu.com/9731736736737/Grandmama-s-Joy-by-Eloise-Greenfield.pdf
    • http://cefasfese.4pu.com/4730733738738737/Honey-I-Love-and-Other-Love-Poems-by-Eloise-Greenfield.pdf
    • http://cefasfese.4pu.com/1738735732733734/Eloise-Wilkin-Stories-by-Eloise-Wilkin.pdf
    • http://cefasfese.4pu.com/4734739736738738/From-Generation-to-Generation-The-Longs-of-Wilkes-Barre-by-Bettijane-Long-Eisenpreis.pdf
    • http://cefasfese.4pu.com/9731733736733736/Jackpot-by-Jeff-Greenfield.pdf
    • http://cefasfese.4pu.com/1735735736730732/2121-A-Tale-From-the-Next-Century-by-Susan-A-Greenfield.pdf
    • http://cefasfese.4pu.com/9731736730732732/43-When-Gore-Beat-Bush-by-Jeff-Greenfield.pdf
    • http://cefasfese.4pu.com/1730731735738736/The-Second-Generation-Dragonlance-The-Second-Generation-1-by-Margaret-Weis.pdf
    • http://cefasfese.4pu.com/3736731735732737/Generation-Z-Generation-Z-1-by-Peter-Meredith.pdf
    • http://cefasfese.4pu.com/4737733731739/Out-Of-The-Flame-by-Eloise-Lownsbery.pdf
    • http://cefasfese.4pu.com/6733738739739733/Birds-of-the-Carolinas-by-Eloise-F-Potter.pdf
    • http://cefasfese.4pu.com/8738732731733735/Eloise-The-Absolutely-Essential-by-Kay-Thompson.pdf
    • http://cefasfese.4pu.com/9731739739732/Letters-to-Eloise-by-Emily-Williams.pdf
    • http://cefasfese.4pu.com/9731732738731/The-Golden-Goblet-by-Eloise-Jarvis-McGraw.pdf
    • http://cefasfese.4pu.com/1738734732734731/Hansel-and-Gretel-Little-Golden-Books-by-Eloise-Wilkin.pdf
    • http://cefasfese.4pu.com/1730738739735733/Generation-Generation-1-by-Sam-Reid.pdf
    • http://cefasfese.4pu.com/5738733739732735/Brissot-de-Warville-A-Study-in-the-History-of-the-French-Revolution-by-Eloise-1874--Ellery.pdf
    • http://cefasfese.4pu.com/4735738738735/The-Wild-Gardener-The-Life-and-Selected-Writings-of-Eloise-Butler-by-Martha-E-Hellander.pdf
    • http://cefasfese.4pu.com/8736732736738739/Star-Trek-Die-n-chste-Generation---berlebende-Star-Trek-The-Next-Generation-4-by-Jean-Lorrah.pdf