Malicious PDF — malware analysis report

Static analysis result for SHA-256 9e536f90c03b0578…

MALICIOUS

PDF

18.6 KB Created: 2019-05-02 06:11:48 +01:00 Authoring application: mPDF 5.7
MD5: c5a0122d3ea6bdcfaaa77dfd6660e964 SHA-1: 50aa48c282d114a960e7e5b813a33776c9fc83b8 SHA-256: 9e536f90c03b0578ae8bf20c60e13c768b3eaf1e762b03e54a5069cb6cb7b7d2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. A critical heuristic identified a link farm containing numerous external PDF links, with the primary URL being http://cefasfese.4pu.com/4735735733736730/More-Mad-For-Miley-An-Unauthorized-Biography-by-Lauren-Alexander.pdf. This suggests the document's purpose is to redirect users to a large number of potentially malicious or compromised sites, likely for SEO poisoning or traffic generation. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4735735733736730/More-Mad-For-Miley-An-Unauthorized-Biography-by-Lauren-Alexander.pdf
    • http://cefasfese.4pu.com/1732732736732737/Tom-Cruise-An-Unauthorized-Biography-by-Andrew-Morton.pdf
    • http://cefasfese.4pu.com/4735735736731736/Angelina-An-Unauthorized-Biography-by-Andrew-Morton.pdf
    • http://cefasfese.4pu.com/9735737738730735/Superman-The-Unauthorized-Biography-by-Glen-Weldon.pdf
    • http://cefasfese.4pu.com/4732738735734731/W-A-R-The-Unauthorized-Biography-of-William-Axl-Rose-by-Mick-Wall.pdf
    • http://cefasfese.4pu.com/4733738731730730/David-Boreanaz-An-Unauthorized-Biography-by-Chris-Nickson.pdf
    • http://cefasfese.4pu.com/6737737737730739/Senator-for-Sale-An-Unauthorized-Biography-of-Senator-Bob-Dole-by-Stanley-G-Hilton.pdf
    • http://cefasfese.4pu.com/8732738730738737/Ol-Strom-An-Unauthorized-Biography-of-Strom-Thurmond-by-Jack-Bass.pdf
    • http://cefasfese.4pu.com/4732737730730736/Rogers-Hornsby-A-Biography-by-Charles-C-Alexander.pdf
    • http://cefasfese.4pu.com/7736731732739739/William-Plomer-A-Biography-by-Peter-F-Alexander.pdf
    • http://cefasfese.4pu.com/1731732731733736735/Yasiel-Puig-The-Inspirational-Story-of-Baseball-Superstar-Yasiel-Puig-Yasiel-Puig-Unauthorized-Biography-Los-Angeles-Dodgers-Cuba-MLB-Books-by-Bill-Redban.pdf
    • http://cefasfese.4pu.com/1735730735731737/The-Competition-by-Caroline-Miley.pdf
    • http://cefasfese.4pu.com/6733736739735/Miles-to-Go-by-Miley-Cyrus.pdf
    • http://cefasfese.4pu.com/7737739731730734/Miley-Ray-Cyrus-by-Heather-E-Schwartz.pdf
    • http://cefasfese.4pu.com/3739733733734732/Miley-Cyrus-by-Sarah-Tieck.pdf
    • http://cefasfese.4pu.com/7737738738735739/Miley-Cyrus-by-Jennifer-Howse.pdf
    • http://cefasfese.4pu.com/1731738731737735738/Gutenachtgeschichten-fur-Kinder-Wasser-Kinderbucher-im-Alter-von-3---8-by-Miley-Smiley.pdf
    • http://cefasfese.4pu.com/8733730734731730/Zayn-Malik-The-Biography-Vs-Liam-Payne-The-Biography-by-Sarah-Oliver.pdf
    • http://cefasfese.4pu.com/1731738731737736739/Gutenachtgeschichten-fur-Kinder-Die-W-scheklammer-Kinderbucher-im-Alter-von-3---7-German-children-s-books-by-Miley-Smiley.pdf
    • http://cefasfese.4pu.com/1731737732735737730/Malala-Yousafzai-The-Girl-Who-Stood-Up-Against-the-Taliban---Biography-for-Kids-9-12-Children-s-Biography-Books-by-Baby-Professor.pdf