Malicious PDF — malware analysis report

Static analysis result for SHA-256 a3c4e184d1bad82e…

MALICIOUS

PDF

20.4 KB Created: 2019-11-09 23:31:41 +00:00 Authoring application: mPDF 5.7
MD5: da0e8a187745a5042c32f6b21e1c2ab0 SHA-1: 282f0342de7a8a142f7e7f6a0711dc000098334e SHA-256: a3c4e184d1bad82e60e69a8460a02cbc14187012aa183e17cb01b458329e6eb6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded links, identified as a PDF SEO link farm. While no scripts were extracted, the heuristic suggests the document's primary purpose is to host a link farm, likely for SEO manipulation or to distribute further malicious content. The URLs provided are part of this link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5730732739736730/We-re-Sailing-Down-the-Nile-A-Journey-Through-Egypt-by-Laurie-Krebs.pdf
    • http://cefasfese.4pu.com/5730732739735737/Letters-from-Egypt-A-Journey-on-the-Nile-1849-1850-A-Journey-on-the-Nile-1849-50-by-Florence-Nightingale.pdf
    • http://cefasfese.4pu.com/1731737732732732733/People-of-the-Nile-Everyday-Life-in-Ancient-Egypt-by-John-Romer.pdf
    • http://cefasfese.4pu.com/2738732736734/The-Rape-of-the-Nile-Tomb-Robbers-Tourists-and-Archaeologists-in-Egypt-by-Brian-M-Fagan.pdf
    • http://cefasfese.4pu.com/3730732734731733/Egypt-A-Journey-Back-in-Time-by-Gary-Wonning.pdf
    • http://cefasfese.4pu.com/5730732739736734/The-Fires-of-Spring-A-Post-Arab-Spring-Journey-Through-the-Turbulent-New-Middle-East---Turkey-Iraq-Qatar-Jordan-Egypt-and-Tunisia-by-Shelly-Culbertson.pdf
    • http://cefasfese.4pu.com/1730733732736735736/Studentenverbindungen-in-Deutschland-Ein-kritischer-berblick-aus-antifaschistischer-Sicht-by-Felix-Krebs.pdf
    • http://cefasfese.4pu.com/1731736736733736732/Diagnose-Krebs-Eine-neue-Chance-zu-leben-Gl-cklicher-dankbarer-bewusster-by-Viktor-Felix.pdf
    • http://cefasfese.4pu.com/8732734736739730/Ben-Jonson-s-The-fountaine-of-self-loue-or-Cynthias-revels-Nach-der-quarto-1601-in-neudruck-hrsg-von-W-Bang-und-L-Krebs-by-Ben-Jonson.pdf
    • http://cefasfese.4pu.com/1731736738737733739/Sailing-For-Beginners-by-Moulton-Farnham.pdf
    • http://cefasfese.4pu.com/1731738732733734/Sailing-into-the-Abyss-by-Judy-Marks.pdf
    • http://cefasfese.4pu.com/9732732737734739/Sailing-to-America-by-Robert-Gernhardt.pdf
    • http://cefasfese.4pu.com/9739739738739732/Sailing-the-Optimist-by-Marjolijn-Sonnema.pdf
    • http://cefasfese.4pu.com/1739736731734730/Sailing-for-Gold-by-Deborah-Hopkinson.pdf
    • http://cefasfese.4pu.com/9734736736732735/Sailing-Alone-Around-the-World-by-Joshua-Slocum.pdf
    • http://cefasfese.4pu.com/8731730732734736/Sailing-Through-Six-Sigma-by-Michael-Brassard.pdf
    • http://cefasfese.4pu.com/3730732738732734/Sailing-to-Sarantium-The-Sarantine-Mosaic-1-by-Guy-Gavriel-Kay.pdf
    • http://cefasfese.4pu.com/1736730737732734/KODOKU-Sailing-Alone-Across-the-Pacific-by-Kenichi-Horie.pdf
    • http://cefasfese.4pu.com/1731732737738735735/The-Complete-Sailor-Learning-the-Art-of-Sailing-by-David-Seidman.pdf
    • http://cefasfese.4pu.com/2731732736731736/The-Sinbad-Chronicles-Sailing-to-Atlantis-by-Janeen-Webb.pdf
    • http://cefasfese.4pu.com/5730732739736734/The-Fires-of-Spring-A-Post-Arab-Spring-Journey-Through-the-Turbulent-New-Middle-East---Turk