Malicious PDF — malware analysis report

Static analysis result for SHA-256 a8de1b6517546234…

MALICIOUS

PDF

16.1 KB Created: 2020-01-01 23:19:48 +00:00 Authoring application: mPDF 5.7
MD5: a612b723d385ee7f503be0a90cd91b12 SHA-1: 1ebc34abad5c987e0e699e44946ee0f4007f9cd9 SHA-256: a8de1b65175462348b799c8cbcd201b8a53500b3169f897ac72e298569b0f555
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a significant number of embedded URLs, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these URLs were classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO abuse or to serve as a lure for further malicious downloads. The ML classifier and ClamAV detection strongly support the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7612145-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7612145-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4p
    • http://cefasfese.4pu.com/4733739735737737/The-Canal-by-Daniel-Morris.pdf
    • http://cefasfese.4pu.com/7732735738738735/Our-Canal-The-Rideau-Canal-in-Ottawa-by-Peter-Conroy.pdf
    • http://cefasfese.4pu.com/7732735734737737/Diary-and-Letters-of-Gouverneur-Morris-Volume-1-by-Anne-Cary-Morris.pdf
    • http://cefasfese.4pu.com/7732735734738730/Diary-and-Letters-of-Gouverneur-Morris-Volume-2-by-Anne-Cary-Morris.pdf
    • http://cefasfese.4pu.com/4734736730732732/Outpassage-by-Jante-Morris-Chris-Morris.pdf
    • http://cefasfese.4pu.com/7732735734738737/The-Diary-and-Letters-of-Gouverneur-Morris-Minister-of-the-United-States-to-France-Volume-2-by-Gouverneur-Morris.pdf
    • http://cefasfese.4pu.com/6736731731732739/News-from-Nowhere-or-an-Epoch-of-Rest-Being-Some-Chapters-from-a-Utopian-Romance-1890-by-William-Morris-by-William-Morris.pdf
    • http://cefasfese.4pu.com/3736739731734737/The-Cowboy-and-the-Canal-by-J-M-Carlisle.pdf
    • http://cefasfese.4pu.com/1731733737732730/Gunfight-at-the-Old-Leake-Canal-by-G-B-Hope.pdf
    • http://cefasfese.4pu.com/1731737735734732735/Along-the-Bude-Canal-by-Joan-Rendell.pdf
    • http://cefasfese.4pu.com/5738730734733733/From-Canal-Boy-to-President-by-Horatio-Alger-Jr-.pdf
    • http://cefasfese.4pu.com/2736734737739733/Dance-by-the-Canal-by-Kerstin-Hensel.pdf
    • http://cefasfese.4pu.com/5738730734731730/Cruising-Panama-s-Canal-by-Al-Lockwood.pdf
    • http://cefasfese.4pu.com/1732731732731737/Morris-As-Elvis-The-World-s-Greatest-Elvis-Impersonator-by-Morris-Bates.pdf
    • http://cefasfese.4pu.com/5738730734732732/The-Hauntings-of-Hood-Canal-by-Jack-Cady.pdf
    • http://cefasfese.4pu.com/5738730733736731/The-Canal-Boat-Caf-by-Cressida-McLaughlin.pdf
    • http://cefasfese.4pu.com/5738730734730736/Canal-House-Cooks-Every-Day-by-Melissa-Hamilton.pdf
    • http://cefasfese.4pu.com/5738730734732733/Canal-Town-by-Samuel-Hopkins-Adams.pdf
    • http://cefasfese.4pu.com/5738730734732730/Root-Canal-Cover-Up-by-George-E-Meinig.pdf
    • http://cefasfese.4pu.com/1730732736732/Gulp-Adventures-on-the-Alimentary-Canal-by-Mary-Roach.pdf