Malicious PDF — malware analysis report

Static analysis result for SHA-256 a56de2cc8fbe943f…

MALICIOUS

PDF

19.0 KB Created: 2019-04-30 10:30:00 +01:00 Authoring application: mPDF 5.7
MD5: 2c4a19dd7bae170f118428fa1b73eea3 SHA-1: c084725b55323ebff436ad13416d9bada1c8e213 SHA-256: a56de2cc8fbe943f1e1be5970c4dc8f9997129bbf57eef236d3500dfcdf042b2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link farm with 32 external links, predominantly using numeric slugs, indicating a likely attempt to lure users to malicious content. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8733737736736732/Moderate-Radical-Tobie-Matthew-and-the-English-Reformation-by-Rosamund-Oates.pdf
    • http://cefasfese.4pu.com/1731737734731738731/Five-Women-of-the-English-Reformation-by-Paul-F-M-Zahl.pdf
    • http://cefasfese.4pu.com/1731732738734733/The-Voices-of-Morebath-Reformation-and-Rebellion-in-an-English-Village-by-Eamon-Duffy.pdf
    • http://cefasfese.4pu.com/9731732739730732/English-German-Russian-Bible---The-Gospels-II---Matthew-Mark-Luke-amp-John-Basic-English-1949---Elberfelder-1905-----1876-by-Truthbetold-Ministry.pdf
    • http://cefasfese.4pu.com/2733732734731731/The-Growth-of-English-Schooling-1340-1548-Learning-Literacy-and-Laicization-in-Pre-Reformation-York-Diocese-by-Jo-Ann-Hoeppner-Moran.pdf
    • http://cefasfese.4pu.com/8733737736735736/Ten-Classic-Pasta-Recipes-with-Tobie-Puttock-Ten-Classic-Pasta-Recipes-with-Tobie-Puttock-by-Tobie-Puttock.pdf
    • http://cefasfese.4pu.com/8733737736735735/Ten-Old-School-Dessert-Recipes-with-Tobie-Puttock-Ten-Old-School-Dessert-Recipes-with-Tobie-Puttock-by-Tobie-Puttock.pdf
    • http://cefasfese.4pu.com/2731735735739/The-Journal-of-Joyce-Carol-Oates-1973-1982-by-Joyce-Carol-Oates.pdf
    • http://cefasfese.4pu.com/1737736730738731/Sister-by-Rosamund-Lupton.pdf
    • http://cefasfese.4pu.com/2733737733730737/The-Karma-Suture-by-Rosamund-Kendal.pdf
    • http://cefasfese.4pu.com/4733730738737734/The-Storyteller-s-Apprentice-by-Rosamund-Hodge.pdf
    • http://cefasfese.4pu.com/1731732736739730/Tolstoy-A-Russian-Life-by-Rosamund-Bartlett.pdf
    • http://cefasfese.4pu.com/2737731733734730/The-Murder-of-Norman-Ware-by-Rosamund-Kendal.pdf
    • http://cefasfese.4pu.com/3738739735737739/In-Passing-by-Tobie-Hewitt.pdf
    • http://cefasfese.4pu.com/8733737735735734/The-Unknown-by-Tobie-Raye.pdf
    • http://cefasfese.4pu.com/1737730737736733/Emerge-Mer-Chronicles-1-by-Tobie-Easton.pdf
    • http://cefasfese.4pu.com/8733737735737732/cook-like-an-italian-by-Tobie-Puttock.pdf
    • http://cefasfese.4pu.com/8733737736734735/Soul-on-Bikes-by-Tobie-Levingston.pdf
    • http://cefasfese.4pu.com/2731739734732737/Submerge-Mer-Chronicles-2-by-Tobie-Easton.pdf
    • http://cefasfese.4pu.com/8733737735736734/Zawsze-Wierni-Tobie-Polsko-by-Krzysztof-Bulzacki.pdf