Malicious PDF — malware analysis report

Static analysis result for SHA-256 a626f35b72e7138d…

MALICIOUS

PDF

21.4 KB Created: 2019-05-03 23:19:56 +01:00 Authoring application: mPDF 5.7
MD5: bb0ee6d9b2775185bbe931deb043bbae SHA-1: 0be8c20c2b0428b1a5638ab2470bc5750e13dc72 SHA-256: a626f35b72e7138d0c437bbba9302088ca92b36ebb488d2c4859b9f53d4a8f20
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary attack pattern involves directing users to a domain hosting numerous PDF files, likely as a lure or to distribute further malware. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9732731737735734/Jesus-Christus-R-ckkehr-ins-heilige-Land-Roman-by-Anne-Rice.pdf
    • http://cefasfese.4pu.com/1731733736731739734/Jesus-Christus-A-Classic-Meditation-on-Christ-by-Romano-Guardini.pdf
    • http://cefasfese.4pu.com/1730737730737730734/Wenn-das-wahr-ist-Fragen-und-Fakten-ber-Jesus-Christus-by-L-on-Taschi.pdf
    • http://cefasfese.4pu.com/1731736733737730735/In-Israel-sprechen-die-Steine-Eine-arch-ologische-Pilgerreise-durch-das-Heilige-Land-by-Hanna-Klenk.pdf
    • http://cefasfese.4pu.com/1731736733737731738/Peregrinatio-in-Terram-Sanctam-Eine-Pilgerreise-Ins-Heilige-Land-Fr-Hneuhochdeutscher-Text-Und-Bersetzung-by-Bernhard-von-Breydenbach.pdf
    • http://cefasfese.4pu.com/8738730731731737/Die-Botschaft-der-11-Gew-rze-der-Bibel-die-auf-Christus-und-Sein-Werk-hinweisen-Zeugen-der-Weisheit-Gottes-offenbaren-Seinen-Heilsratschluss-in-der-Herrlichkeit-des-Christus-und-verbreiten-den-Wohlgeruch-Seines-Namens-by-Jochen-Schneider.pdf
    • http://cefasfese.4pu.com/2735739737731738/Belinda-Anne-Rice-writing-as-Anne-Rampling-by-Anne-Rampling.pdf
    • http://cefasfese.4pu.com/1731739736739732736/Jesus-Christ-Superstar-Edition-A-Rock-Opera-by-Tim-Rice.pdf
    • http://cefasfese.4pu.com/1731731737731731739/Tales-from-a-Land-That-Time-Forgot-by-Edgar-Rice-Burroughs.pdf
    • http://cefasfese.4pu.com/4732739734731730/Violin-by-Anne-Rice.pdf
    • http://cefasfese.4pu.com/3738733738735/Cry-to-Heaven-by-Anne-Rice.pdf
    • http://cefasfese.4pu.com/1731731737731732731/The-Land-That-Time-Forgot-Collection-Caspak-1-3-by-Edgar-Rice-Burroughs.pdf
    • http://cefasfese.4pu.com/1731733739739734734/Memnoch-the-Devil-by-Anne-Rice.pdf
    • http://cefasfese.4pu.com/3736732732737/The-Feast-of-All-Saints-by-Anne-Rice.pdf
    • http://cefasfese.4pu.com/4735730738736735/The-Feast-of-All-Saints-by-Anne-Rice.pdf
    • http://cefasfese.4pu.com/7737737734733734/Anne-Of-Green-Gablesan-Interactive-Cd-Rom-Novel-Anne-La-Maison-Au-Pignons-Verts-Un-Roman-Interactif-Sur-Cd-Rom-by-Renaissance-Interactive-Studios.pdf
    • http://cefasfese.4pu.com/5730739731734734/Breaking-the-Land-The-Transformation-of-Cotton-Tobacco-and-Rice-Cultures-since-1880-by-Pete-Daniel.pdf
    • http://cefasfese.4pu.com/3733734739731/The-Mummy-Ramses-the-Damned-1-by-Anne-Rice.pdf
    • http://cefasfese.4pu.com/2733737737730731/Pandora-New-Tales-of-the-Vampires-1-by-Anne-Rice.pdf
    • http://cefasfese.4pu.com/3738734738734736/Merrick-The-Vampire-Chronicles-7-by-Anne-Rice.pdf
    • http://cefasfese.4pu.com/8738730731731737/Die-Botschaft-der-11-Gew-rze-der-Bibel-die-auf-Christus-und-Sein-Werk-hinweisen-Zeugen-der-Weisheit-Gottes-o