Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b836a8df8b736b5…

MALICIOUS

PDF

20.1 KB Created: 2019-05-02 05:21:38 +01:00 Authoring application: mPDF 5.7
MD5: d966bccb70effb117864f19922a8187a SHA-1: 975898a116aba2d9c566cd93ace76106d4f30389 SHA-256: 8b836a8df8b736b578d84a2d0c72731ef22acd30dd9955522e0e8495a3ae3888
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF documents, suggesting a link farm or a method to distribute potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9472

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2736730732735733/And-on-that-Bombshell-Inside-the-Madness-and-Genius-of-Top-Gear-by-Richard-Porter.pdf
    • http://cefasfese.4pu.com/1731734731738735736/Hetty-The-Genius-and-Madness-of-America-s-First-Female-Tycoon-by-Charles-Slack.pdf
    • http://cefasfese.4pu.com/7731731736/Idiot-Genius-Willa-Snap-and-the-Clockwerk-Boy-Idiot-Genius-1-by-Richard-Due.pdf
    • http://cefasfese.4pu.com/4734730732733739/Inside-Bet-Vegas-Top-Guns-2-by-Katie-Porter.pdf
    • http://cefasfese.4pu.com/6732734733739735/The-Measure-of-Madness-Inside-the-Disturbed-and-Disturbing-Criminal-Mind-by-Cheryl-Paradis.pdf
    • http://cefasfese.4pu.com/4730737730733731/He-Wanted-the-Moon-The-Madness-and-Medical-Genius-of-Dr-Perry-Baird-and-His-Daughter-s-Quest-to-Know-Him-by-Mimi-Baird.pdf
    • http://cefasfese.4pu.com/1735731731738/Genius-The-Life-and-Science-of-Richard-Feynman-by-James-Gleick.pdf
    • http://cefasfese.4pu.com/1734733731733738/Madness-Explained-Psychosis-and-Human-Nature-by-Richard-P-Bentall.pdf
    • http://cefasfese.4pu.com/7736739732736738/SR-71-Revealed-The-Inside-Story-by-Richard-H-Graham.pdf
    • http://cefasfese.4pu.com/3733732734731/Against-All-Enemies-Inside-America-s-War-on-Terror-What-Really-Happened-by-Richard-A-Clark.pdf
    • http://cefasfese.4pu.com/2739735730733734/Evil-Genius-Family-Genius-Mysteries-1-by-Patricia-Rice.pdf
    • http://cefasfese.4pu.com/2739735730732733/Cyber-Genius-Family-Genius-Mysteries-3-by-Patricia-Rice.pdf
    • http://cefasfese.4pu.com/8734736731734736/Metal-Gear-Solid-Omnibus-Metal-Gear-Solid-1-4-by-Kris-Oprisko.pdf
    • http://cefasfese.4pu.com/2739736734735730/The-Madness-Project-The-Madness-Method-1-by-J-Leigh-Bralick.pdf
    • http://cefasfese.4pu.com/3737736730737/Evil-Genius-Genius-1-by-Catherine-Jinks.pdf
    • http://cefasfese.4pu.com/2736732736738734/In-the-Shadow-of-Porter-s-Hollow-The-Porter-s-Hollow-Series-Book-1-by-Yvonne-Schuchart.pdf
    • http://cefasfese.4pu.com/5734735735739/101-Things-to-Do-to-Become-a-Superhero---Or-Evil-Genius-Written-by-Helen-Szirtes-and-Richard-Horne-by-Helen-Szirtes.pdf
    • http://cefasfese.4pu.com/1730732730733734736/The-Billionaire-Baby-Bombshell-by-Paula-Roe.pdf
    • http://cefasfese.4pu.com/1735737737734735/Bombshell-FBI-Thriller-17-by-Catherine-Coulter.pdf
    • http://cefasfese.4pu.com/1736736739737731/Bombshell-Bohemia-poetry-from-the-underground-by-Taylor-Roberts.pdf
    • http://cefasfese.4pu.com/4730737730733731/He-Wanted-the-Moon-The-Madness-and-Medical-Genius-of-Dr-Perry-Baird-and-His-Daughte