Malicious PDF — malware analysis report

Static analysis result for SHA-256 adb6cabd3ade1e4b…

MALICIOUS

PDF

16.7 KB Created: 2019-05-03 17:54:49 +01:00 Authoring application: mPDF 5.7
MD5: b5522504645a2b6fbe65697aecf95f2f SHA-1: 1e6bb6e43037ae4bccdeab06343390502027c4ff SHA-256: adb6cabd3ade1e4b9fe30690a93a8c4b253057466d59bbd4806ce74338b2475e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves appear benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to redirect users to malicious sites. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9913

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2735738730739739/Revenge-Blood-and-Honor-1-by-Dana-Delamar.pdf
    • http://cefasfese.4pu.com/3733733739734737/Malavita-Blood-and-Honor-0-5-by-Dana-Delamar.pdf
    • http://cefasfese.4pu.com/2738737737735/Redemption-Blood-and-Honor-3-by-Dana-Delamar.pdf
    • http://cefasfese.4pu.com/4735736734739730/Retribution-Blood-and-Honor-2-by-Dana-Delamar.pdf
    • http://cefasfese.4pu.com/7739732738739735/Malavita-Blood-and-Honor-0-5-by-Dana-Delamar.pdf
    • http://cefasfese.4pu.com/2739730737733/Retribution-Blood-and-Honor-2-by-Dana-Delamar.pdf
    • http://cefasfese.4pu.com/1730730736737734734/Her-Two-Men-in-Tahiti-Total-Indulgence-2-by-Dana-Delamar.pdf
    • http://cefasfese.4pu.com/9733736735737738/Jewish-Honor-Courts-Revenge-Retribution-and-Reconciliation-in-Europe-and-Israel-After-the-Holocaust-by-Laura-Jockusch.pdf
    • http://cefasfese.4pu.com/7737731735732739/Taint-in-the-Blood-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/8734736730736/Blood-Will-Tell-Kate-Shugak-6-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/8735738738733/A-Taint-In-The-Blood-Kate-Shugak-14-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/1734733733736739/Whisper-To-The-Blood-Kate-Shugak-16-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/9737732736735738/Blood-amp-Honor-by-Reinhold-Kerstan.pdf
    • http://cefasfese.4pu.com/8735734735736730/Of-Blood-and-Honor-WarCraft-0-by-Chris-Metzen.pdf
    • http://cefasfese.4pu.com/6732734733731/Blood-and-Honor-Riding-the-Line-4-by-Jayna-Vixen.pdf
    • http://cefasfese.4pu.com/3736736736738735/Blood-and-Honor-Forest-Kingdom-2-by-Simon-R-Green.pdf
    • http://cefasfese.4pu.com/3733738731732733/Blackjack-Blood-and-Honor-The-Graphic-Novel-by-Alex-Simmons.pdf
    • http://cefasfese.4pu.com/6731733738730731/Blood-Justice-The-True-Story-of-Multiple-Murder-and-a-Family-s-Revenge-by-Tom-Henderson.pdf
    • http://cefasfese.4pu.com/1731735735734739730/Blood-and-Honor-Inside-the-Scarfo-Mob--The-Mafia-s-Most-Violent-Family-by-George-Anastasia.pdf
    • http://cefasfese.4pu.com/2733730732735732/Dracul-s-Blood-Dracul-s-Revenge-1-by-Carol-Lynne.pdf