Malicious PDF — malware analysis report

Static analysis result for SHA-256 81707835eb637225…

MALICIOUS

PDF

14.5 KB Created: 2019-06-05 06:19:46 +01:00 Authoring application: mPDF 5.7
MD5: b7aa98e94c07755ab20d89d2fa8af24b SHA-1: 0bb1c07fc358e61f39d117c4b584aee0a1a99a2e SHA-256: 81707835eb63722507e6b64e36a97ea8260b2f0b4d89db8a67cba4f5ecefe4be
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary attack pattern observed is the creation of a link farm designed to direct users to potentially harmful content hosted on the dominant domain cefasfese.4pu.com.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6732730736737732/Gang-of-Four-by-Liz-Byrski.pdf
    • http://cefasfese.4pu.com/3734733734731739/A-Month-of-Sundays-by-Liz-Byrski.pdf
    • http://cefasfese.4pu.com/2732738737737734/Trip-of-a-Lifetime-by-Liz-Byrski.pdf
    • http://cefasfese.4pu.com/4734739734734734/Belly-Dancing-for-Beginners-by-Liz-Byrski.pdf
    • http://cefasfese.4pu.com/1730734735731735732/Bad-Behaviour-by-Sheila-O-39-Flanagan.pdf
    • http://cefasfese.4pu.com/3736737736733/Good-Behaviour-by-Molly-Keane.pdf
    • http://cefasfese.4pu.com/4734733739731734/Flight-Behaviour-by-Barbara-Kingsolver.pdf
    • http://cefasfese.4pu.com/2738735737731736/Ungentlemanly-Behaviour-by-Margaret-Mayo.pdf
    • http://cefasfese.4pu.com/8733735732734733/The-Sociology-of-Behaviour-and-Psychology-by-John-Dollard.pdf
    • http://cefasfese.4pu.com/4738732736734734/Drugs-and-Human-Behaviour-by-Gordon-Claridge.pdf
    • http://cefasfese.4pu.com/8735735730738/Management-and-Organisational-Behaviour-by-Karen-Meudell.pdf
    • http://cefasfese.4pu.com/9736735738736736/The-Problem-Behaviour-Pocketbook-by-Angelena-Boden.pdf
    • http://cefasfese.4pu.com/7731734732737732/Good-Manners-and-Bad-Behaviour-by-Candida-Slater.pdf
    • http://cefasfese.4pu.com/7738739737736738/Consumer-Behaviour-A-European-Outlook-by-Havard-Hansen.pdf
    • http://cefasfese.4pu.com/1730734733736732738/Construction-Management-and-Organisational-Behaviour-by-Maureen-Rhoden.pdf
    • http://cefasfese.4pu.com/8734739733738/Hospitality-Management-and-Organisational-Behaviour-by-Laurie-J-Mullins.pdf
    • http://cefasfese.4pu.com/1731739738737736736/Bumblebees-Behaviour-Ecology-and-Conservation-by-Goulson-Dave.pdf
    • http://cefasfese.4pu.com/8739739734736733/Conduct-Unbecoming-The-Regulation-of-Parliamentary-Behaviour-by-Oonagh-Gay.pdf
    • http://cefasfese.4pu.com/6737732730738735/Hypnosis-and-Behaviour-Modification-Imagery-Conditioning-by-William-S-Kroger.pdf
    • http://cefasfese.4pu.com/3739736737730737/Wandering-Significance-An-Essay-on-Conceptual-Behaviour-by-Mark-Wilson.pdf
    • http://cefasfese.4pu.com/7738739737736738/Consumer-Behaviour-A-European-Outlook-by-Ha