Malicious PDF — malware analysis report

Static analysis result for SHA-256 7cefa0e0e0749224…

MALICIOUS

PDF

16.9 KB Created: 2019-05-02 07:05:01 +01:00 Authoring application: mPDF 5.7
MD5: d7d6e962b1afff212e9b95b6b5c71e6c SHA-1: f5ea43b9759d545cd7ed4e2c6af4324eeba1676e SHA-256: 7cefa0e0e074922493a35b7720e31d04b1c57b3ee932c8e1fe53b96fe1653a5b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links pointing to external resources, identified as a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be SEO spam or a lure to distribute further malicious content via the numerous URLs. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3730732730737739/As-Husbands-Go-by-Susan-Isaacs.pdf
    • http://cefasfese.4pu.com/3737732739737731/As-Husbands-Go-by-Susan-Isaacs.pdf
    • http://cefasfese.4pu.com/1737733734735734/After-All-These-Years-by-Susan-Isaacs.pdf
    • http://cefasfese.4pu.com/1734733736736731/Any-Place-I-Hang-My-Hat-by-Susan-Isaacs.pdf
    • http://cefasfese.4pu.com/1735738735731730/Long-Time-No-See-by-Susan-Isaacs.pdf
    • http://cefasfese.4pu.com/9737738734737731/Wie-ein-Licht-in-dunkler-Nacht-by-Susan-Isaacs.pdf
    • http://cefasfese.4pu.com/2733739734731735/Angry-Conversations-with-God-A-Snarky-But-Authentic-Spiritual-Memoir-by-Susan-E-Isaacs.pdf
    • http://cefasfese.4pu.com/1731730738734731733/The-Shining-Mountains-by-Susan-Silvi.pdf
    • http://cefasfese.4pu.com/1731731734733735737/The-Shining-The-Shining-1-by-Stephen-King.pdf
    • http://cefasfese.4pu.com/4731736738738734/The-Greatest-Blessings-by-Mark-Isaacs.pdf
    • http://cefasfese.4pu.com/1730734738735735734/Dialogue-The-Art-of-Thinking-Together-by-William-Isaacs.pdf
    • http://cefasfese.4pu.com/1736733735738733/The-Light-of-Asteria-Kailmeyra-1-by-Elizabeth-Isaacs.pdf
    • http://cefasfese.4pu.com/2738733735735734/Dragons-or-Dinosaurs-Creation-or-Evolution-by-Darek-Isaacs.pdf
    • http://cefasfese.4pu.com/6738735737732730/Mazeppa-the-Lives-Loves-and-Legends-of-Adah-Isaacs-Menken-A-Biographical-Quest-by-Wolf-Mankowitz.pdf
    • http://cefasfese.4pu.com/9734730738732739/Konigskinder-Royal-Children-or-the-Prince-and-the-Goosegirl-a-Guide-to-Engelburt-Humperdinck-s-and-Ernst-Rosmer-s-Opera-Facsimile-of-1912-Edition-by-Lewis-Isaacs.pdf
    • http://cefasfese.4pu.com/6731732734736730/The-Shining-by-Stephen-King.pdf
    • http://cefasfese.4pu.com/6738733732732738/Dad-Shining-by-Noreen-Lace.pdf
    • http://cefasfese.4pu.com/5733733734730733/The-Shining-by-Stephen-King.pdf
    • http://cefasfese.4pu.com/3732738731737735/The-Heart-of-the-Ancients-Kailmeyra-s-Redemption-Kailmeyra-3-by-Elizabeth-Isaacs.pdf
    • http://cefasfese.4pu.com/1730735738734737/The-Light-of-Asteria-Kailmeyra-s-Last-Hope-Kailmeyra-1-by-Elizabeth-Isaacs.pdf
    • http://cefasfese.4pu.com/4731736738738734/The-Greatest-Blessings-by-Mark-Isaac