Malicious PDF — malware analysis report

Static analysis result for SHA-256 9b24b1abef85c7a3…

MALICIOUS

PDF

18.6 KB Created: 2019-05-24 17:46:57 +01:00 Authoring application: mPDF 5.7
MD5: 25b7e3087238e44a61e14929013f70d9 SHA-1: 5af477517dd0b70d9060284c2c3099fc285b1221 SHA-256: 9b24b1abef85c7a31db232b41e89f31209986aa3ac919fe15376aae5a2a0f6f6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm. No scripts were extracted from this sample, and the document body was heavily obfuscated, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4731730735738738/A-Quiet-Belief-in-Angels-by-R-J-Ellory.pdf
    • http://cefasfese.4pu.com/4733730735730/A-Quiet-Vendetta-by-R-J-Ellory.pdf
    • http://cefasfese.4pu.com/2737731737734730/Angels-are-Real-Angels-Exist-Proof-that-Angels-are-to-help-us-Real-stories-of-Angels-encounters-Ordinary-people-saved-by-Angels-Guardian-Angels-and-Archangels-Angels-are-Real-Angels-Exist-2-by-Tessy-Rawlins.pdf
    • http://cefasfese.4pu.com/9738731734732734/The-Cop-Three-Days-in-Chicagoland-2-by-R-J-Ellory.pdf
    • http://cefasfese.4pu.com/5732736736737/A-Simple-Act-Of-Violence-by-R-J-Ellory.pdf
    • http://cefasfese.4pu.com/8738730732734736/Angels-101-An-Introduction-to-Connecting-Working-and-Healing-with-the-Angels-by-Doreen-Virtue.pdf
    • http://cefasfese.4pu.com/1739738732735730/When-Angels-Fall-Fallen-Angels-1-by-Jo-Cattell.pdf
    • http://cefasfese.4pu.com/1739738732735731/After-Angels-Fall-Fallen-Angels-2-by-Jo-Cattell.pdf
    • http://cefasfese.4pu.com/2736738730731739/Few-Are-Angels-Few-Are-Angels-1-by-Inger-Iversen.pdf
    • http://cefasfese.4pu.com/2730730733730733/Where-Angels-Go-Angels-Everywhere-6-by-Debbie-Macomber.pdf
    • http://cefasfese.4pu.com/1731736734733731/Angels-Angels-Everywhere-by-Michelle-Beber.pdf
    • http://cefasfese.4pu.com/7733731736735738/Objections-to-Christian-Belief-by-A-R-Vidler.pdf
    • http://cefasfese.4pu.com/6731735732734735/Belief-and-the-Nation-by-John-Scriven.pdf
    • http://cefasfese.4pu.com/3734730735739731/Belief-Change---The-Book-by-Janet-Ingersoll.pdf
    • http://cefasfese.4pu.com/3737739739735735/The-Religious-Case-Against-Belief-by-James-P-Carse.pdf
    • http://cefasfese.4pu.com/2735736732730739/Maps-of-Meaning-The-Architecture-of-Belief-by-Jordan-B-Peterson.pdf
    • http://cefasfese.4pu.com/6733738734736/To-Believe-or-Not-to-Believe-The-Social-and-Neurological-Consequences-of-Belief-Systems-by-Rahasya-Poe.pdf
    • http://cefasfese.4pu.com/1733739733734735/Faith-and-Rationality-Reason-and-Belief-in-God-by-Alvin-Plantinga.pdf
    • http://cefasfese.4pu.com/3739738737731736/Given-Up-for-You-A-Memoir-of-Love-Belonging-and-Belief-by-Erin-White.pdf
    • http://cefasfese.4pu.com/6730730735736/Belief-Readings-on-the-Reason-for-Faith-by-Francis-S-Collins.pdf
    • http://cefasfese.4pu.com/1739738732735731/After-Angels-Fal