Malicious PDF — malware analysis report

Static analysis result for SHA-256 7b9a9dad186fb3dd…

MALICIOUS

PDF

20.1 KB Created: 2019-06-04 10:31:40 +01:00 Authoring application: mPDF 5.7
MD5: 3959c928272869feb200bfc52e65657a SHA-1: 034f948b2a807be3be628a307a50b7e91e4c4b23 SHA-256: 7b9a9dad186fb3dd6acb75d40cc289f6b1eb24f94490863fa2305a01262d520e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged the document as malicious. While the extracted URLs themselves are confirmed benign, the sheer volume and structure suggest a malicious intent, likely SEO poisoning or a link farm for distributing further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9809

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730739733739736734/Truly-Wilde-The-Unsettling-Story-Of-Dolly-Wilde-Oscar-s-Unusual-Niece-by-Joan-Schenkar.pdf
    • http://cefasfese.4pu.com/7733733731730736/An-Ideal-Husband-1895-by-Oscar-Wilde-An-Ideal-Husband-Is-an-1895-Comedic-Stage-Play-by-Oscar-Wilde-Which-Revolves-Around-Blackmail-and-Political-Corruption-and-Touches-on-the-Themes-of-Public-and-Private-Honour-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/9737731738732736/The-Picture-of-Dorian-Gray-De-Profundis-The-Happy-Prince-and-other-tales-by-Oscar-Wilde---With-a-clickable-Table-of-Contents-Illustrated-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/2735730738730734/The-Importance-of-Being-Earnest-Oscar-Wilde-Notes-by-Ruth-Robbins-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/6732734731738739/Oeuvres-de-Oscar-Wilde-Avec-Original-Version-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/5738738730736736/The-Importance-of-Being-Earnest-By-Oscar-Wilde---Illustrated-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/9738735730736733/Salome-Drama-in-Einem-Aufzuge-Nach-Oskar-Wilde-s-Gleichnamiger-Dichtung-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/4732734739731738/Oscar-Wilde-Short-Stories-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/1731737733733737733/De-profundis-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/4739738738734732/Intentions-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/4737734737738731/The-Soul-of-a-Man-under-Socialism-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/3735732738731736/A-Woman-of-No-Importance-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/4731730739731732/The-Happy-Prince-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/7732731735730733/The-Importance-of-Being-Earnest-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/7739731732736736/The-Importance-of-Being-Earnest-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/3737731738736/The-Nightingale-and-the-Rose-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/3731734736738739/The-Selfish-Giant-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/2731733732735/Oscar-Wilde-by-Richard-Ellmann.pdf
    • http://cefasfese.4pu.com/1739733739730731/The-Canterville-Ghost-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/3735733738734739/An-Ideal-Husband-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/2735730738730734/The-Importanc