Malicious PDF — malware analysis report

Static analysis result for SHA-256 ae8d3b11fa5fb049…

MALICIOUS

PDF

18.3 KB Created: 2019-11-08 00:21:42 +00:00 Authoring application: mPDF 5.7
MD5: bd628792e89a8d2fa4dee6729c26887b SHA-1: b5dbe079b37e53d2b341f0717ac670c4272b8305 SHA-256: ae8d3b11fa5fb049a0470e2610504966375c40e309439919ccd877512eb491a6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by an ML classifier as malicious and contains a large number of embedded external links. The document body, though partially corrupted, shows these links pointing to various PDF files hosted on the same domain. This suggests a link farm or SEO manipulation tactic, potentially to distribute further malicious content or to obscure the true malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9737737735/Citizen-Scientist-Searching-for-Heroes-and-Hope-in-an-Age-of-Extinction-by-Mary-Ellen-Hannibal.pdf
    • http://cefasfese.4pu.com/1739734733738734/Social-Problem-Solving-and-Offending-Evidence-Evaluation-and-Evolution-by-Mary-McMurran.pdf
    • http://cefasfese.4pu.com/2735738733738735/Mary-Ellen-s-Best-of-Helpful-Hints-by-Mary-Ellen-Pinkham.pdf
    • http://cefasfese.4pu.com/3739739737731735/The-Greatest-Show-on-Earth-The-Evidence-for-Evolution-by-Richard-Dawkins.pdf
    • http://cefasfese.4pu.com/8736739738731735/Stones-amp-Bones-Powerful-Evidence-Against-Evolution-by-Carl-Wieland.pdf
    • http://cefasfese.4pu.com/7731733735731730/Evolution-of-Living-Organisms-Evidence-for-a-New-Theory-of-Transformation-by-Pierre-P-Grasse.pdf
    • http://cefasfese.4pu.com/3734738735734/The-Blind-Watchmaker-Why-the-Evidence-of-Evolution-Reveals-a-Universe-Without-Design-by-Richard-Dawkins.pdf
    • http://cefasfese.4pu.com/8738730734738738/Hannibal-Of-Carthage-by-Mary-Dolan.pdf
    • http://cefasfese.4pu.com/8738730734735735/The-Hannibal-Files-The-Unauthorised-Guide-to-the-Hannibal-Lecter-Trilogy-by-Daniel-O-39-Brien.pdf
    • http://cefasfese.4pu.com/3736734735736732/Hannibal-Rising-Hannibal-Lecter-4-by-Thomas-Harris.pdf
    • http://cefasfese.4pu.com/3736734734738/Hannibal-Rising-Hannibal-Lecter-4-by-Thomas-Harris.pdf
    • http://cefasfese.4pu.com/3731736736733730/Hannibal-Rising-Hannibal-Lecter-4-by-Thomas-Harris.pdf
    • http://cefasfese.4pu.com/8735735738733/Hannibal-Fields-of-Blood-Hannibal-2-by-Ben-Kane.pdf
    • http://cefasfese.4pu.com/8738730735730732/Hannibal-Hannibal-in-psihoanaliza-by-Mitja-Reichenberg.pdf
    • http://cefasfese.4pu.com/3736734732731730/Hannibal-Hannibal-Lecter-3-by-Thomas-Harris.pdf
    • http://cefasfese.4pu.com/3738738738731733/Evolution-s-Embers-by-Mary-Wine.pdf
    • http://cefasfese.4pu.com/8738730733731738/Hannibal-The-Patrol-Hannibal-1-5-by-Ben-Kane.pdf
    • http://cefasfese.4pu.com/8735737738739/Hannibal-Clouds-of-War-Hannibal-3-by-Ben-Kane.pdf
    • http://cefasfese.4pu.com/2739734739730734/The-Apple-of-My-Eye-by-Mary-Ellen-Bramwell.pdf
    • http://cefasfese.4pu.com/7732731738733734/The-Lovely-Ambition-by-Mary-Ellen-Chase.pdf
    • http://cefasfese.4pu.com/3734738735734/The-B