Malicious PDF — malware analysis report

Static analysis result for SHA-256 8720a9ffc154944a…

MALICIOUS

PDF

24.7 KB Created: 2020-01-03 01:54:22 +00:00 Authoring application: mPDF 5.7
MD5: e02ad3b5d13e6ee4adc512889cdb9021 SHA-1: aea5d5a564821cf67cc2ff77fe236c6107821d5c SHA-256: 8720a9ffc154944a214a621ccd47c5d75f50858b74780335e8d54c6c8f9da08a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the heuristic 'PDF_SEO_LINK_FARM' and the sheer volume of links to a single, suspicious domain suggest a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9727

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1735733735732732/Terminal-Rage-by-A-M-Khalifa.pdf
    • http://cefasfese.4pu.com/9736736733736738/Richtiges-Messen-in-Dampf--Und-Feuerungsbetrieben-by-Gesellschaft-Fur-Warmewirtschaft-Wien.pdf
    • http://cefasfese.4pu.com/4732739730739730/The-Labyrinth-of-Osiris-Yusuf-Khalifa-3-by-Paul-Sussman.pdf
    • http://cefasfese.4pu.com/4739730737730734/The-Many-Selves-of-Katherine-North-by-Emma-Geen.pdf
    • http://cefasfese.4pu.com/5737736736739734/The-Many-Selves-of-Katherine-North-by-Emma-Geen.pdf
    • http://cefasfese.4pu.com/1730731730731731731/In-Geen-Velden-Of-Wegen-by-Peter-Stamm.pdf
    • http://cefasfese.4pu.com/2737739738738737/Stad-in-de-storm-by-Thea-Beckman.pdf
    • http://cefasfese.4pu.com/8736734732737736/Waarom-ik-geen-christen-ben-En-andere-essays-over-religie-en-aanverwante-onderwerpen-by-Bertrand-Russell.pdf
    • http://cefasfese.4pu.com/6734731733730730/Building-in-the-stubborn-city-Bouwen-aan-een-weerbarstige-stad-by-P-Meurs.pdf
    • http://cefasfese.4pu.com/9732738731737735/Wie-we-zijn-wanneer-we-denken-dat-er-niemand-kijkt-by-Christian-Rudder.pdf
    • http://cefasfese.4pu.com/9734732733731734/de-Joodse-Gemeenschap-in-de-Stad-Groningen-1689-1796-by-E-Schut.pdf
    • http://cefasfese.4pu.com/8736734732730739/Wat-baal-ik-van-mijn-hals-en-andere-gedachten-over-vrouw-zijn-by-Nora-Ephron.pdf
    • http://cefasfese.4pu.com/1730732735737738732/Waarom-vrouwen-betere-lezers-zijn-over-boeken-lezen-en-schrijven-by-Herman-Franke.pdf
    • http://cefasfese.4pu.com/6736738730732734/La-Bd-Dans-La-Ville-De-Strip-In-De-Stad-The-Comics-In-The-City-Bruxelles-Brussel-Brussels-by-Thibaut-Vandorselaer.pdf
    • http://cefasfese.4pu.com/1731736735734733739/Humanitat-Im-Arbeitsleben-Der-Mensch-Ist-Wichtiger-ALS-Die-Sache-Referate-Und-Ergebnisse-Des-Kongresses-Humanitat-Im-Arbeitsleben-Am-6-7-Deze-by-Kurt-H-Biedenkopf.pdf
    • http://cefasfese.4pu.com/1731739735739735733/Verleidelijke-List-amp-Mysterieuze-erfgename-amp-Onverbloemde-passie-amp-Nachten-op-zijn-ranch-amp-Met-open-ogen-amp-Echt-gekust-Dynasties-The-Lassiters-1--6-by-Maureen-Child.pdf
    • http://cefasfese.4pu.com/9733730737738736/Stad-in-Zweden-Lijst-Van-Grote-Zweedse-Steden-Helsingborg-Linkoping-Visby-Karlskoga-Kalmar-Lund-Lulea-Halmstad-Kiruna-Sodertalje-by-Wikipedia.pdf
    • http://cefasfese.4pu.com/2731734737736737/Een-bescheiden-voorstel-om-te-voorkomen-dat-kinderen-van-arme-mensen-in-Ierland-hun-ouders-of-vaderland-tot-last-zijn-en-om-hen-in-een-maatschappelijke-behoefte-te-laten-voorzien-satirische-geschriften-by-Jonathan-Swift.pdf
    • http://cefasfese.4pu.com/7738739738733733/Taxi-by-Khaled-Al-Khamissi.pdf
    • http://cefasfese.4pu.com/3733735737730732/Smokescreen-by-Khaled-Talib.pdf
    • http://cefasfese.4pu.com/8736734732737736/Waarom-ik-geen-christen-ben-En-andere-essays-over-religie-en-aanverwante-onderwerpen-by-Ber