Malicious PDF — malware analysis report

Static analysis result for SHA-256 95cd3a08d25e3567…

MALICIOUS

PDF

20.2 KB Created: 2019-06-04 09:18:46 +01:00 Authoring application: mPDF 5.7
MD5: 0ae17c36d22b2b96aced40ec2fcf134b SHA-1: f1b42ac3a39d9581d097c33584b9889bdb3c95a2 SHA-256: 95cd3a08d25e35676c40bab92e5e41c49523d44447158b665e65cd06819e6a87
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, all pointing to the same domain. This suggests a link farm or redirection tactic to a malicious site. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8734732733734731/Personal-Property-of-Marilyn-Monroe-by-Christie-39-s.pdf
    • http://cefasfese.4pu.com/5739734735736739/Marilyn-Monroe-in-Hollywood-A-Guide-by-Marsha-Bellavance-Johnson.pdf
    • http://cefasfese.4pu.com/5737735738739734/The-Secret-Letters-of-Marilyn-Monroe-and-Jacqueline-Kennedy-by-Wendy-Leigh.pdf
    • http://cefasfese.4pu.com/3734734734735735/Marilyn-Monroe-Confidential-An-Intimate-Personal-Account-by-Lena-Pepitone.pdf
    • http://cefasfese.4pu.com/4732738733730733/Marilyn-Monroe-A-Beautiful-Child-Schirmer-Art-Books-by-Truman-Capote.pdf
    • http://cefasfese.4pu.com/8734732735733735/Casting-Norma-Jeane-A-Starlet-is-Transformed-Into-Marilyn-Monroe-by-James-Glaeg.pdf
    • http://cefasfese.4pu.com/3739731733733739/Dr-Feelgood-The-Story-of-the-Doctor-Who-Influenced-History-by-Treating-and-Drugging-Prominent-Figures-Including-President-Kennedy-Marilyn-Monroe-and-Elvis-Presley-by-Richard-A-Lertzman.pdf
    • http://cefasfese.4pu.com/5738738732735732/Ask-Marilyn-The-Best-of-quot-Ask-Marilyn-quot-Letters-Published-in-Parade-Magazine-from-1986-to-1992-and-Many-More-Never-Before-Published-by-Marilyn-Vos-Savant.pdf
    • http://cefasfese.4pu.com/3730734739736739/Arnold-The-Education-of-a-Bodybuilder-by-Arnold-Schwarzenegger.pdf
    • http://cefasfese.4pu.com/1731730737730737735/Ich-h-re-was-die-Seelen-sprechen-Selbst-Skeptiker-verlassen-Vicki-Monroe-in-voller-Gewissheit-Auch-wenn-nicht-erkl-rbar-ist-wie-sie-wissen-kann-was-sie-wei-by-Vicki-Monroe.pdf
    • http://cefasfese.4pu.com/1731738731737730735/Runt-and-Arnold-Slay-Monster-Hognose-The-Adventures-of-Runt-and-Arnold-by-Gean-Penny.pdf
    • http://cefasfese.4pu.com/8738737733734732/Marilyn-Manson-The-Long-Hard-Road-Out-of-Hell-by-Marilyn-Manson.pdf
    • http://cefasfese.4pu.com/4732736736733731/The-Mating-by-Mandy-Monroe.pdf
    • http://cefasfese.4pu.com/3733735732737733/I-Won-t-Give-Up-by-Sophie-Monroe.pdf
    • http://cefasfese.4pu.com/8739739735730736/Santas-Wunsch-by-Kay-Monroe.pdf
    • http://cefasfese.4pu.com/4732737737737733/The-Wolf-Within-by-Mandy-Monroe.pdf
    • http://cefasfese.4pu.com/1734737732731732/Rugged-by-Lila-Monroe.pdf
    • http://cefasfese.4pu.com/2730735737739732/A-Taste-of-Cyn-by-Marla-Monroe.pdf
    • http://cefasfese.4pu.com/2737730730739734/Conflicted-Battlescars-3-by-Sophie-Monroe.pdf
    • http://cefasfese.4pu.com/1737730735730736/Bittersweet-Revenge-by-Monroe-Scott.pdf