Malicious PDF — malware analysis report

Static analysis result for SHA-256 a2e0dd29fbd3331e…

MALICIOUS

PDF

26.0 KB Created: 2019-05-02 05:07:10 +01:00 Authoring application: mPDF 5.7
MD5: d35cb30ced77d9a078e711968b7b55d0 SHA-1: 4e489afe66811fd5e1c7d1db00c483cd5d1d636f SHA-256: a2e0dd29fbd3331edb2341471958b68ed618460b553325c493c07ba703950f6e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links, identified as a link farm. The primary heuristic indicates a mass of external PDF links, many with numeric slugs, suggesting a SEO-based lure. While the document body is heavily obfuscated, the presence of numerous URLs points to a redirection or download attempt. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9742

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9738734735733735/Smart-People-Should-Build-Things-How-to-Restore-Our-Culture-of-Achievement-Build-a-Path-for-Entrepreneurs-and-Create-New-Jobs-in-America-by-Andrew-Yang.pdf
    • http://cefasfese.4pu.com/9739732735734/2-Second-Lean-How-to-Grow-People-and-Build-a-Fun-Lean-Culture-by-Paul-A-Akers.pdf
    • http://cefasfese.4pu.com/7733730732/Crushing-It-How-Great-Entrepreneurs-Build-Their-Business-and-Influence-and-How-You-Can-Too-by-Gary-Vaynerchuk.pdf
    • http://cefasfese.4pu.com/1730732737735732730/Build-Dogs-Build-A-Tall-Tail-by-James-Horvath.pdf
    • http://cefasfese.4pu.com/1732732738735732/Build-Web-Applications-with-Java-Learn-every-aspect-to-build-web-applications-from-scratch-by-Mirza-Yousuf-Ahmed-Baig.pdf
    • http://cefasfese.4pu.com/8730736738739731/The-Creativity-Challenge-Design-Experiment-Test-Innovate-Build-Create-Inspire-and-Unleash-Your-Genius-by-Tanner-Christensen.pdf
    • http://cefasfese.4pu.com/1731730732737735733/Small-Business-Marketing-Made-Easy-8-Proven-Strategies-to-Grow-Your-Revenue-Build-Your-Reputation-and-Create-Ongoing-Wealth-by-Jennifer-Thom-.pdf
    • http://cefasfese.4pu.com/1730730738734733731/Successful-Guest-Posting-How-to-Create-Guest-Posts-that-Drive-Traffic-and-Build-Authority-by-Tom-Ewer.pdf
    • http://cefasfese.4pu.com/6736735736731731/How-to-Build-a-Better-Pie-Sweet-and-Savory-Recipes-for-Flaky-Crusts-Toppers-and-the-Things-in-Between-by-Millicent-Souris.pdf
    • http://cefasfese.4pu.com/7732737731737/Rival-Rails-The-Race-to-Build-America-s-Greatest-Transcontinental-Railroad-by-Walter-R-Borneman.pdf
    • http://cefasfese.4pu.com/1732734733731736/How-to-Build-a-Museum-Smithsonian-s-National-Museum-of-African-American-History-and-Culture-by-Tonya-Bolden.pdf
    • http://cefasfese.4pu.com/1730739732735739731/Everyday-Survival-Why-Smart-People-Do-Stupid-Things-by-Laurence-Gonzales.pdf
    • http://cefasfese.4pu.com/2737734735735734/Washington-Rules-America-s-Path-to-Permanent-War-by-Andrew-J-Bacevich.pdf
    • http://cefasfese.4pu.com/3734730732736731/Culture-Smart-India-The-Essential-Guide-to-Customs-amp-Culture-by-Becky-Stephen.pdf
    • http://cefasfese.4pu.com/1731730734733739732/Master-Your-Money-Mindset-How-To-Make-Your-Business-Go-Ka-Ching-A-smart-guide-for-action-taking-entrepreneurs-by-Karen-Strunks.pdf
    • http://cefasfese.4pu.com/3737731730738737/The-House-They-Couldn-t-Build-by-B-Mamatha.pdf
    • http://cefasfese.4pu.com/1730737730734734730/A-Time-to-Build-by-Debra-W-Haffner.pdf
    • http://cefasfese.4pu.com/6734738738738/How-to-Build-a-Girl-by-Caitlin-Moran.pdf
    • http://cefasfese.4pu.com/4734731738739737/How-to-Build-a-Girl-by-Caitlin-Moran.pdf
    • http://cefasfese.4pu.com/9732736734737733/The-80-20-Individual-How-to-Build-on-the-20-of-What-You-Do-Best-by-Richard-Koch.pdf
    • http://cefasfese.4pu.com/1732732738735732/Build-Web-Ap