Malicious PDF — malware analysis report

Static analysis result for SHA-256 a017b210a01c8024…

MALICIOUS

PDF

22.6 KB Created: 2019-11-09 21:37:08 +00:00 Authoring application: mPDF 5.7
MD5: 202815aaf2d0beb0be43cb75304e83a5 SHA-1: c5c8b84cd996bd385f427081532a6da10ce08bfb SHA-256: a017b210a01c802418ff3056cac9a0fc26da8722b856443cd95075d3aeae5b9d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links, forming a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be SEO poisoning, directing users to a large collection of external PDF documents hosted on the domain 'cefasfese.4pu.com'. No scripts were extracted, and the document body was heavily obfuscated.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9784

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4731735739737734/Death-of-a-King-The-Real-Story-of-Dr-Martin-Luther-King-Jr-s-Final-Year-by-Tavis-Smiley.pdf
    • http://cefasfese.4pu.com/1731732733738732/Chasing-King-s-Killer-The-Hunt-for-Martin-Luther-King-Jr-s-Assassin-The-Hunt-for-Martin-Luther-King-Jr-s-Assassin-by-James-L-Swanson.pdf
    • http://cefasfese.4pu.com/5731735730732/Marching-to-the-Mountaintop-How-Poverty-Labor-Fights-and-Civil-Rights-Set-the-Stage-for-Martin-Luther-King-Jr-s-Final-Hours-by-Ann-Bausum.pdf
    • http://cefasfese.4pu.com/4732736735738735/Martin-Luther-King-and-The-Montgomery-Story-by-Fellowship-of-Reconciliation.pdf
    • http://cefasfese.4pu.com/4731733731732735/April-4-1968-Martin-Luther-King-Jr-s-Death-and-How-It-Changed-America-by-Michael-Eric-Dyson.pdf
    • http://cefasfese.4pu.com/3736739736735736/Why-We-Can-t-Wait-by-Martin-Luther-King-Jr-.pdf
    • http://cefasfese.4pu.com/6734735735734/Strength-to-Love-by-Martin-Luther-King-Jr-.pdf
    • http://cefasfese.4pu.com/7733736733734738/Conscience-for-Change-by-Martin-Luther-King-Jr-.pdf
    • http://cefasfese.4pu.com/1731737737738737732/Martin-Luther-King-Jr-by-David-Colbert.pdf
    • http://cefasfese.4pu.com/5737736733734730/Martin-Luther-King-Jr-A-Biography-by-Roger-A-Bruns.pdf
    • http://cefasfese.4pu.com/1738739731735731/I-Have-a-Dream-Letter-from-Birmingham-Jail-by-Martin-Luther-King-Jr-.pdf
    • http://cefasfese.4pu.com/1731737737738733738/Happy-Birthday-Martin-Luther-King-Jr-by-Jean-Marzollo.pdf
    • http://cefasfese.4pu.com/7739733732737/I-Have-a-Dream-Writings-and-Speeches-That-Changed-the-World-by-Martin-Luther-King-Jr-.pdf
    • http://cefasfese.4pu.com/2730736737734735/Going-Down-Jericho-Road-The-Memphis-Strike-Martin-Luther-King-s-Last-Campaign-by-Michael-K-Honey.pdf
    • http://cefasfese.4pu.com/4731735736739734/Gospel-of-Freedom-Martin-Luther-King-Jr-s-Letter-from-Birmingham-Jail-and-the-Struggle-That-Changed-a-Nation-by-Jonathan-Rieder.pdf
    • http://cefasfese.4pu.com/5730739739733736/From-Civil-Rights-to-Human-Rights-Martin-Luther-King-Jr-and-the-Struggle-for-Economic-Justice-by-Thomas-F-Jackson.pdf
    • http://cefasfese.4pu.com/6731735732732735/On-Air-the-Best-of-Tavis-Smiley-by-Tavis-Smiley.pdf
    • http://cefasfese.4pu.com/8734734733735738/Martin-Luther-s-Ninety-Five-Theses-and-Selected-Sermons-by-Martin-Luther.pdf
    • http://cefasfese.4pu.com/9736738734735736/Once-a-King-Always-a-King-The-Unmaking-of-a-Latin-King-by-Reymundo-S-nchez.pdf
    • http://cefasfese.4pu.com/1730731733734731/Martin-Luther-s-Ninety-Five-Theses-by-Martin-Luther.pdf
    • http://cefasfese.4pu.com/4731733731732735/April-4-1968-Martin-Luther-King-Jr-s-Death-and-How-It-Changed-America-by-Michael-Eric-Dy