Malicious PDF — malware analysis report

Static analysis result for SHA-256 af5865b9d08d1bb0…

MALICIOUS

PDF

19.3 KB Created: 2019-05-02 06:07:02 +01:00 Authoring application: mPDF 5.7
MD5: 269b7c4bda8de85978c7c65bf9d883e7 SHA-1: 098bc957d338ed797d31b78e2c229672c5fe311c SHA-256: af5865b9d08d1bb02aa7dfaa98b4bd2c5aaa6b2362d899c0564c54b6d662d8d6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged by a critical heuristic for containing a large number of external links, suggesting a link farm or SEO manipulation tactic. The ML classifier also indicated a high probability of maliciousness. While no scripts were extracted, the structure and embedded URLs point towards a delivery mechanism for potentially malicious content disguised as legitimate documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3732735738730732/Happy-Birthday-Felicity-A-Springtime-Story-American-Girls-Felicity-4-by-Valerie-Tripp.pdf
    • http://cefasfese.4pu.com/3734739738735735/Happy-Birthday-Felicity-A-Springtime-Story-American-Girls-Felicity-4-by-Valerie-Tripp.pdf
    • http://cefasfese.4pu.com/1735733733739736/Changes-for-Felicity-A-Winter-Story-American-Girls-Felicity-6-by-Valerie-Tripp.pdf
    • http://cefasfese.4pu.com/3732735737739733/Happy-Birthday-Josefina-A-Springtime-Story-American-Girls-Josefina-4-by-Valerie-Tripp.pdf
    • http://cefasfese.4pu.com/1734739739731732/Meet-Felicity-An-American-Girl-The-American-Girls-Felicity-1-by-Valerie-Tripp.pdf
    • http://cefasfese.4pu.com/1737732732733734/Meet-Felicity-An-American-Girl-American-Girls-Felicity-1-by-Valerie-Tripp.pdf
    • http://cefasfese.4pu.com/3732735737739731/Happy-Birthday-Samantha-A-Springtime-Story-by-Valerie-Tripp.pdf
    • http://cefasfese.4pu.com/5739735734736738/Felicity-Takes-a-Dare-by-Valerie-Tripp.pdf
    • http://cefasfese.4pu.com/8736737736734/Changes-for-Kit-A-Winter-Story-American-Girls-Kit-6-by-Valerie-Tripp.pdf
    • http://cefasfese.4pu.com/1735733735736732/Molly-Learns-a-Lesson-A-School-Story-American-Girls-Molly-2-by-Valerie-Tripp.pdf
    • http://cefasfese.4pu.com/1735733738732733/Brave-Emily-American-Girls-Molly-7-by-Valerie-Tripp.pdf
    • http://cefasfese.4pu.com/2733737733734733/Meet-Molly-An-American-Girl-American-Girls-Molly-1-by-Valerie-Tripp.pdf
    • http://cefasfese.4pu.com/5739735734737733/Felicity-A-Sparrow-s-Tale-Felicity-1-by-Loralee-Evans.pdf
    • http://cefasfese.4pu.com/5739735734736736/Felicity-and-the-Featherless-Two-Foot-Felicity-2-by-Loralee-Evans.pdf
    • http://cefasfese.4pu.com/1739735739736732/Felicity-and-the-Fire-Stoppers-Felicity-3-by-Loralee-Evans.pdf
    • http://cefasfese.4pu.com/3732735737739739/Changes-for-Kit-A-Winter-Story-by-Valerie-Tripp.pdf
    • http://cefasfese.4pu.com/1734733737738738/Josefina-s-Short-Story-Collection-by-Valerie-Tripp.pdf
    • http://cefasfese.4pu.com/1738730737735738/Lady-Margaret-s-Ghost-A-Felicity-Mystery-American-Girl-Mysteries-by-Elizabeth-McDavid-Jones.pdf
    • http://cefasfese.4pu.com/2734738734733733/BACKWATER-by-Felicity-Lennie.pdf
    • http://cefasfese.4pu.com/2737736739732/Worst-of-Friends-Thomas-Jefferson-John-Adams-and-the-True-Story-of-an-American-Feud-by-Suzanne-Tripp-Jurmain.pdf