Malicious PDF — malware analysis report

Static analysis result for SHA-256 9146be09e96f0d27…

MALICIOUS

PDF

19.8 KB Created: 2019-06-10 06:09:23 +01:00 Authoring application: mPDF 5.7
MD5: af729ae1ab9d7553ba976b38f1b93582 SHA-1: 52cdb077e6ec3335b226e26f2ce4c8b0cb37fc74 SHA-256: 9146be09e96f0d27a64593e11d87e59a787fb06e8ba4734bc1982c8109192a2e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also strongly flagged this PDF as malicious. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing suggest a malicious intent, possibly for SEO manipulation or as a distribution vector for other threats. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3738732731734735/Pop-Up-Monster-Party-by-Benrei-Huang.pdf
    • http://cefasfese.4pu.com/1737730734736/Party-Monster-A-Fabulous-But-True-Tale-of-Murder-in-Clubland-by-James-St-James.pdf
    • http://cefasfese.4pu.com/1736739733733735/Rule-and-Ruin-The-Downfall-of-Moderation-and-the-Destruction-of-the-Republican-Party-from-Eisenhower-to-the-Tea-Party-by-Geoffrey-Kabaservice.pdf
    • http://cefasfese.4pu.com/2732736737730734/The-Shadow-Party-How-George-Soros-Hillary-Clinton-and-Sixties-Radicals-Seized-Control-of-the-Democratic-Party-by-David-Horowitz.pdf
    • http://cefasfese.4pu.com/1731730733734733738/Clarence-Monster-s-Monster-Christmas-Story-by-John-E-Dorey.pdf
    • http://cefasfese.4pu.com/6738737731738735/Monster-Graphic-Novels-Monster-Mess-by-Lewis-Trondheim.pdf
    • http://cefasfese.4pu.com/1731736734735732738/Monster-for-a-Day-Or-the-Monster-in-Gregory-s-Pajamas-by-Frank-Kaff.pdf
    • http://cefasfese.4pu.com/2734730731739737/Monster-High-My-Monster-Life-by-Parragon-Publishing.pdf
    • http://cefasfese.4pu.com/1737730733732732/After-the-Party-Ralph-s-Party-2-by-Lisa-Jewell.pdf
    • http://cefasfese.4pu.com/1731737739730735/Monster-Makers-Monster-Chronicles-1-by-C-V-Cook.pdf
    • http://cefasfese.4pu.com/6738731734735730/Mighty-Monster-Machines-Blaze-and-the-Monster-Machines-Little-Golden-Book-by-Nickelodeon-Publishing.pdf
    • http://cefasfese.4pu.com/6739737734739730/Dinosaur-and-Monster-and-The-Magic-Carpet-Dinosaur-and-Monster-stories-Book-1-by-Suzanne-Pollen.pdf
    • http://cefasfese.4pu.com/1732734735731734/Monster-Seeker-2-Rise-of-the-Phoenix-King-Monster-Seeker-Academy-2-by-Ian-Michael-Terry.pdf
    • http://cefasfese.4pu.com/3737737733736739/Monster-High-The-Freaky-Fabulous-Collector-s-Set-Monster-High-1-4-by-Lisi-Harrison.pdf
    • http://cefasfese.4pu.com/1732738730732733/All-I-ve-Never-Wanted-by-Ana-Huang.pdf
    • http://cefasfese.4pu.com/4739735735732736/Zero-Sum-Game-by-S-L-Huang.pdf
    • http://cefasfese.4pu.com/2730739731/For-the-Record-by-Charlotte-Huang.pdf
    • http://cefasfese.4pu.com/3734737739733736/For-the-Record-by-Charlotte-Huang.pdf
    • http://cefasfese.4pu.com/4737731735731733/Best-Of-Sri-Lankan-Party-Foods-Party-Foods-by-Shrinika-Perera.pdf
    • http://cefasfese.4pu.com/4731739736735732/Swimming-with-Sharks-by-George-Huang.pdf
    • http://cefasfese.4pu.com/2734730731739737/Monster-High-