Malicious PDF — malware analysis report

Static analysis result for SHA-256 aae1badda37996c3…

MALICIOUS

PDF

20.8 KB Created: 2019-06-09 11:40:15 +01:00 Authoring application: mPDF 5.7
MD5: a298b5c26ebb0388723948c2dadce6d8 SHA-1: 2dd59e7fb7f91d7ceb5af46199081829e931ca00 SHA-256: aae1badda37996c32c6f1c3205f67ba542a12f46c76b1e39e3af2ed3fa3a2f85
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these specific URLs are marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to serve as a lure for further malicious activity. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1738737733730731/Hidden-Keys-of-a-Loving-Lasting-Marriage-by-Gary-Smalley.pdf
    • http://cefasfese.4pu.com/3736734733733736/Love-as-a-Way-of-Life-Seven-Keys-to-Transforming-Every-Aspect-of-Your-Life-by-Gary-Chapman.pdf
    • http://cefasfese.4pu.com/7738731734739/Before-The-Proof-by-Gary-Williams.pdf
    • http://cefasfese.4pu.com/7739739735730/Death-in-the-Beginning-by-Gary-Williams.pdf
    • http://cefasfese.4pu.com/8737731739730/Victim-The-Other-Side-of-Murder-by-Gary-Kinder.pdf
    • http://cefasfese.4pu.com/1737733735736/Blood-Will-Tell-The-Murder-Trials-of-T-Cullen-Davis-by-Gary-Cartwright.pdf
    • http://cefasfese.4pu.com/3738735733731733/Guardian-of-Guadalcanal-The-World-War-II-Story-of-Douglas-A-Munro-United-States-Coast-Guard-by-Gary-Williams.pdf
    • http://cefasfese.4pu.com/5733737736737738/Sherlock-Holmes-Reader-Murder-at-Moulin-Rouge-by-Gary-Reed.pdf
    • http://cefasfese.4pu.com/2733736738736731/Scherzo-Murder-and-Mystery-in-18th-Century-Venice-by-Jim-Williams.pdf
    • http://cefasfese.4pu.com/4730733737739734/Gary-Gygax-s-Extraordinary-Book-of-Names-Gygaxian-Fantasy-Worlds-Volume-IV-by-Gary-Gygax.pdf
    • http://cefasfese.4pu.com/3730739737732738/Cooking-at-Home-Williams-Sonoma-by-Chuck-Williams.pdf
    • http://cefasfese.4pu.com/5736737734735739/The-Gary-Snyder-Reader-Prose-Poetry-and-Translations-by-Gary-Snyder.pdf
    • http://cefasfese.4pu.com/1730731734730739730/The-Complete-Short-Stories-of-Gary-Troia-by-Gary-Troia.pdf
    • http://cefasfese.4pu.com/3739731739736732/A-Narrative-of-Events-since-the-First-of-August-1834-by-James-Williams-an-Apprenticed-Labourer-in-Jamaica-by-James-Williams.pdf
    • http://cefasfese.4pu.com/4731737739739730/The-Complete-Writings-of-Roger-Williams---Volume-3-Bloudy-Tenent-of-Persecution-by-Roger-Williams.pdf
    • http://cefasfese.4pu.com/4739731733737733/Murder-Imperfect-Libby-Sarjeant-Murder-Mystery-Series-by-Lesley-Cookman.pdf
    • http://cefasfese.4pu.com/4739731735735739/Murder-in-the-Green-Libby-Sarjeant-Murder-Mystery-Series-by-Lesley-Cookman.pdf
    • http://cefasfese.4pu.com/6730735736738736/Murder-on-the-Green-A-gripping-crime-mystery-full-of-cooking-and-murder-by-H-V-Coombs.pdf
    • http://cefasfese.4pu.com/1731739738735730/Murder-Becomes-Manhattan-A-Dalton-Lee-Mystery-The-Murder-Becomes-series-Book-1-by-Jeffrey-Eaton.pdf
    • http://cefasfese.4pu.com/6735736739739/Sex-Murder-And-A-Double-Latte-A-Sophie-Katz-Murder-Mystery-1-by-Kyra-Davis.pdf
    • http://cefasfese.4pu.com/4730733737739734/Gary-Gygax-s-Extraordinary-Book-of-Names-Gygaxian-Fantasy-Wor