Malicious PDF — malware analysis report

Static analysis result for SHA-256 a1556d2a4d738f0c…

MALICIOUS

PDF

18.0 KB Created: 2019-05-02 08:33:04 +01:00 Authoring application: mPDF 5.7
MD5: e526555ad028cdcb01f060ca1afc6d01 SHA-1: ad9ae56f0da3c7ee80c48d96f86690c0f91ef50d SHA-256: a1556d2a4d738f0c6132328f86fa25a761447e0fa0730f22eb1dea324b046da3
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified as a link farm. This technique is often used to manipulate search engine results or to host malicious content. ClamAV detected this file as Pdf.Dropper.Agent-7369496-0, and an ML classifier also flagged it as malicious. The embedded URLs are likely intended to redirect users to malicious sites or download further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7369496-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7369496-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730735737731734733/Rewiring-the-Real-In-Conversation-with-William-Gaddis-Richard-Powers-Mark-Danielewski-and-Don-Delillo-by-Mark-C-Taylor.pdf
    • http://cefasfese.4pu.com/1730738739731730/The-Intermediaries-Beat-amp-Case-by-Taylor-Dye.pdf
    • http://cefasfese.4pu.com/4733739734734732/The-Purloined-Letter-by-Edgar-Allan-Poe.pdf
    • http://cefasfese.4pu.com/2739738737731/Beauty-Was-the-Case-That-They-Gave-Me-by-Mark-Leidner.pdf
    • http://cefasfese.4pu.com/4738731731731738/The-Shyest-Kid-in-the-Patch-by-Mark-Taylor.pdf
    • http://cefasfese.4pu.com/4734733735732737/No-Good-Deed-Mark-Taylor-1-by-M-P-McDonald.pdf
    • http://cefasfese.4pu.com/3733739735737735/Cold-Case-Reopened-The-Princes-in-the-Tower-by-Mark-Garber.pdf
    • http://cefasfese.4pu.com/2732731736732737/The-Curious-Case-of-the-Clockwork-Man-Burton-amp-Swinburne-2-by-Mark-Hodder.pdf
    • http://cefasfese.4pu.com/4734737738738733/Speed-Limits-Where-Time-Went-and-Why-We-Have-So-Little-Left-by-Mark-C-Taylor.pdf
    • http://cefasfese.4pu.com/1736738735738/The-Case-of-the-Case-of-Mistaken-Identity-Brixton-Brothers-1-by-Mac-Barnett.pdf
    • http://cefasfese.4pu.com/1731738736738735733/The-Resolving-of-Conscience-Upon-This-Question-Whether-Upon-Such-a-Supposition-or-Case-as-Is-Now-Usually-Made-Subjects-May-Take-Arms-and-Resist-and-Whether-That-Be-the-Case-Now-By-H-Fern-1642-by-Ferne.pdf
    • http://cefasfese.4pu.com/7738735735738739/Case-by-Case-Basis-by-Patricia-Willers.pdf
    • http://cefasfese.4pu.com/3736735736730734/Spiritual-Secret-of-Hudson-Taylor-by-Howard-Taylor.pdf
    • http://cefasfese.4pu.com/8733730731732/The-Compass-by-Tammy-Kling.pdf
    • http://cefasfese.4pu.com/6734732739738734/The-Points-Of-My-Compass-by-E-B-White.pdf
    • http://cefasfese.4pu.com/9735738735736739/The-Compass-of-His-Bones-by-Jeff-VanderMeer.pdf
    • http://cefasfese.4pu.com/3733731736730736/By-Heart-and-Compass-by-Danielle-Thorne.pdf
    • http://cefasfese.4pu.com/8730735730730737/The-Compass-Stone-by-Fernando-Arrabal.pdf
    • http://cefasfese.4pu.com/4731732739738733/Career-Compass-by-Mohamed-Ibrahim.pdf
    • http://cefasfese.4pu.com/7733730739733736/Compass-of-Dreams-by-Pierdomenico-Baccalario.pdf
    • http://cefasfese.4pu.com/2732731736732737/The-Curious-Case-of-the-Clockwork-Man-Burton-amp-Swinburne-