Malicious PDF — malware analysis report

Static analysis result for SHA-256 b1798b1c03f7dba1…

MALICIOUS

PDF

17.6 KB Created: 2019-05-03 09:19:07 +01:00 Authoring application: mPDF 5.7
MD5: 0c4edc5c2593fcc61665360e00d76ca2 SHA-1: ad6eda0e0c2f3dae284b7a8bc59978e8bc5d985b SHA-256: b1798b1c03f7dba1cef8ebdb0298ecf2f927524813f5c4f1a0db4b313dd97b7c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malware. The ML classifier strongly indicated maliciousness. While the document body is unreadable, the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm, and the embedded URLs are the primary indicators of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfes
    • http://cefasfese.4pu.com/1731731738730736739/Anne-p-egen-hand-Anne-of-Green-Gables-4-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/8735737738735739/Anne-of-Windy-Poplars-Anne-s-House-of-Dreams-Anne-of-Ingleside-Anne-of-Green-Gables-4-6-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/3732738739731/The-Complete-Anne-of-Green-Gables-Boxed-Set-Anne-of-Green-Gables-1-8-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/2733736733732736/Anne-of-Green-Gables-amp-Anne-of-Avonlea-Anne-of-Green-Gables-1-2-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/7733734733737/Anne-of-Green-Gables-Anne-Shirley-Series---The-Complete-Collection-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/7737737734734737/Anne-des-Pignons-Verts-Anne-of-Green-Gables-French-edition-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/9735730733738738/Anne-of-Green-Gables-The-Complete-Anne-Shirley-Series-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/3734735731739/Anne-s-House-of-Dreams-Anne-of-Green-Gables-5-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/2736731738734730/Anne-of-Windy-Poplars-Anne-of-Green-Gables-4-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/6730733730738735/Anne-of-Avonlea-Anne-of-Green-Gables-Series-2-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/4733735739734738/Anne-s-House-of-Dreams-Anne-of-Green-Gables-5-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/3739733732738/Anne-of-Windy-Poplars-Anne-of-Green-Gables-4-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/1735739734734732/Anne-of-the-Island-Anne-of-Green-Gables-3-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/8730738733739730/Anne-p-Gr-nkulla-Anne-of-Green-Gables-1-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/3732739737738/Anne-of-the-Island-Anne-of-Green-Gables-3-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/7730731733736736/Anne-of-the-Island-Anne-of-Green-Gables-3-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/2731733730736736/Anne-of-Avonlea-Anne-of-Green-Gables-2-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/2736735739737736/Anne-of-Avonlea-Anne-of-Green-Gables-2-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/6730733730739730/Anne-of-the-Island-Anne-of-Green-Gables-3-by-L-M-Montgomery.pdf
    • http://cefasfese.4pu.com/3737731738737732/Anne-of-Green-Gables-Anne-of-Green-Gables-1-by-L-M-Montgomery.pdf