Malicious PDF — malware analysis report

Static analysis result for SHA-256 7edfd9e9e3b66e77…

MALICIOUS

PDF

16.6 KB Created: 2019-04-30 08:01:03 +01:00 Authoring application: mPDF 5.7
MD5: c0816e59cd262d162885086429d04e0c SHA-1: 87e3842633eb99ccb2dad1ba58fa5d5b2cc9e4b6 SHA-256: 7edfd9e9e3b66e77d4854a655d05f8f151a643370cfe8600c4f15edc503ce5f5
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, forming a link farm. The primary heuristic indicates this is a technique to potentially distribute malicious content or engage in SEO abuse. While the specific URLs extracted were classified as benign, the sheer volume and structure suggest a malicious intent to drive traffic or host malicious files. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9810

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731736730736733738/Edinburgh-Mapping-the-City-by-Christopher-Fleet.pdf
    • http://cefasfese.4pu.com/1739734733730734/The-Town-Below-the-Ground-Edinburgh-s-Legendary-Underground-City-by-Jan-Andrew-Henderson.pdf
    • http://cefasfese.4pu.com/1731736730736733733/Reading-Round-Edinburgh-A-Guide-to-Children-s-Books-of-the-City-by-Lindsey-Fraser.pdf
    • http://cefasfese.4pu.com/1731736730735739735/The-Edinburgh-Fate-The-Edinburgh-Seer-3-by-Alisha-Klapheke.pdf
    • http://cefasfese.4pu.com/1735737731731735/To-Train-the-Fleet-for-War-The-U-S-Navy-Fleet-Problems-1923-1940-by-Albert-A-Nofi.pdf
    • http://cefasfese.4pu.com/3739734730732/The-Mortal-Instruments-the-Complete-Collection-City-of-Bones-City-of-Ashes-City-of-Glass-City-of-Fallen-Angels-City-of-Lost-Souls-City-of-Heavenly-Fire-by-Cassandra-Clare.pdf
    • http://cefasfese.4pu.com/5735730730737733/Rome-The-Biography-of-a-City-by-Christopher-Hibbert.pdf
    • http://cefasfese.4pu.com/3732732731738734/London-The-Biography-of-a-City-by-Christopher-Hibbert.pdf
    • http://cefasfese.4pu.com/2737735737731735/The-City-of-Gold-and-Lead-by-John-Christopher.pdf
    • http://cefasfese.4pu.com/2731739737733739/Fleet-of-Worlds-Fleet-of-Worlds-1-by-Larry-Niven.pdf
    • http://cefasfese.4pu.com/3732736732733731/Rebel-Fleet-Rebel-Fleet-1-by-B-V-Larson.pdf
    • http://cefasfese.4pu.com/2735734731735730/Edinburgh-by-Terry-Deary.pdf
    • http://cefasfese.4pu.com/3732738739735731/The-Edinburgh-Dead-by-Brian-Ruckley.pdf
    • http://cefasfese.4pu.com/1731736730736730731/On-Glasgow-and-Edinburgh-by-Robert-Crawford.pdf
    • http://cefasfese.4pu.com/1731736730736736738/The-Edinburgh-Bride-by-Anne-Douglas.pdf
    • http://cefasfese.4pu.com/1731736730736732734/Lost-Edinburgh-by-hamish-coghill.pdf
    • http://cefasfese.4pu.com/1731736730735738739/Supernatural-The-Dogs-of-Edinburgh-by-Brian-Wood.pdf
    • http://cefasfese.4pu.com/1731736730736736736/A-Visitor-s-Guide-to-Edinburgh-by-Irvine-Welsh.pdf
    • http://cefasfese.4pu.com/7737734732737735/The-Edinburgh-Lectures-on-Mental-Science-by-Thomas-Troward.pdf
    • http://cefasfese.4pu.com/6734733731/Edinburgh-Twilight-Ian-Hamilton-Mysteries-1-by-Carole-Lawrence.pdf