Malicious PDF — malware analysis report

Static analysis result for SHA-256 a9a33c206251701d…

MALICIOUS

PDF

17.7 KB Created: 2019-05-03 23:28:37 +01:00 Authoring application: mPDF 5.7
MD5: db3b755ac2eb562e791e6c4b93b9e02a SHA-1: 80047a93fa4601020c9c0cfc54a073b1a56f6ee8 SHA-256: a9a33c206251701d5afa0e1fe8057a5435cd19e279b8143c2da7b42907d73411
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. While the document body is heavily obfuscated, the presence of numerous external links suggests a malicious intent, possibly for SEO manipulation or to redirect users to malicious sites. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4739737737737731/Letters-Summer-1926-by-Boris-Pasternak.pdf
    • http://cefasfese.4pu.com/6731737734731735/Four-of-Us-Pasternak-Akhmatova-Tsvetaeva-Mandelstam-by-Boris-Pasternak.pdf
    • http://cefasfese.4pu.com/1730739738735731734/Pasternak-On-Art-And-Creativity-by-Boris-Pasternak.pdf
    • http://cefasfese.4pu.com/3734733736739737/My-Sister---Life-by-Boris-Pasternak.pdf
    • http://cefasfese.4pu.com/1730739738733735737/Selected-Poems-by-Boris-Pasternak.pdf
    • http://cefasfese.4pu.com/1733737735732735/Doctor-Zhivago-by-Boris-Pasternak.pdf
    • http://cefasfese.4pu.com/3732735739732738/Adolescence-Of-Zhenya-Luvers-by-Boris-Pasternak.pdf
    • http://cefasfese.4pu.com/1730739738735731730/Understanding-Boris-Pasternak-by-Larissa-Rudova.pdf
    • http://cefasfese.4pu.com/1731736734737733730/Doktor-Faustus-und-Doktor-Schiwago-Versuch-ber-zwei-Zeitromane-aus-Exilsicht-PdR-Press-publications-on-Boris-Pasternak-2-by-Henrik-Birnbaum.pdf
    • http://cefasfese.4pu.com/5735737736737731/Boris-Sees-the-Light-Boris-4-by-Andrew-Joyner.pdf
    • http://cefasfese.4pu.com/5736733737739734/Twin-Visions-The-Magical-Art-of-Boris-Vallejo-and-Julie-Bell-by-Boris-Vallejo.pdf
    • http://cefasfese.4pu.com/5736733737734733/Superheroes-The-Heroic-Visions-of-Boris-Vallejo-and-Julie-Bell-by-Boris-Vallejo.pdf
    • http://cefasfese.4pu.com/5736733737739739/Imaginistix-Boris-Vallejo-and-Julie-Bell-The-All-New-Collection-by-Boris-Vallejo.pdf
    • http://cefasfese.4pu.com/1731731737739738734/Boris-Akunin-Books-Checklist-Reading-Order-of-An-Erast-Fandorin-Mystery-Series-and-List-of-All-Boris-Akunin-Books-by-Kevin-Hanson.pdf
    • http://cefasfese.4pu.com/8735731736734735/Boris-Mikhailov-Suzi-Et-Cetera-by-Boris-Mikhailov.pdf
    • http://cefasfese.4pu.com/3739738735736738/As-I-See-The-Fantastic-World-of-Boris-Artzybasheff-by-Boris-Artzybasheff.pdf
    • http://cefasfese.4pu.com/5735737738730737/The-Fantastic-Art-Of-Boris-Vallejo-by-Boris-Vallejo.pdf
    • http://cefasfese.4pu.com/5736733737739732/Boris-Vallejo-s-3D-Magic-by-Boris-Vallejo.pdf
    • http://cefasfese.4pu.com/5735735734736731/Sex-Gender-and-Kinship-A-Cross-Cultural-Perspective-by-Burton-Pasternak.pdf
    • http://cefasfese.4pu.com/3736734731739730/Summer-s-Journey-Volume-One---Losing-Control-Summer-s-Journey-1-by-Summer-Daniels.pdf
    • http://cefasfese.4pu.com/1731736734737733730/Doktor-Faustus-und-Doktor-Schiwago-Versuch-ber-zwei