Malicious PDF — malware analysis report

Static analysis result for SHA-256 b18e666f2be4010c…

MALICIOUS

PDF

17.3 KB Created: 2019-08-02 07:38:08 +01:00 Authoring application: mPDF 5.7
MD5: a56fda3ac7d8d12ae19afa23af612432 SHA-1: 99e408ec53f82a8cd65221807fd3a349f9933668 SHA-256: b18e666f2be4010c292ce794dfaa656dd5bfa48601204b4a8f8d6b75e35b7546
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a link farm with 23 external links, all pointing to PDF files. This heuristic suggests a tactic to distribute malicious content or engage in SEO abuse. The ML classifier also flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4
    • http://cefasfese.4pu.com/1730735730739737/A-Children-s-Treasury-of-Milligan-Classic-Stories-and-Poems-by-Spike-Milligan-by-Spike-Milligan.pdf
    • http://cefasfese.4pu.com/6738739734737736/Milligan-s-Meaning-of-Life-An-Autobiography-of-Sorts-by-Spike-Milligan.pdf
    • http://cefasfese.4pu.com/4735739738738737/The-Nation-s-Favourite-Children-s-Poems-by-Spike-Milligan.pdf
    • http://cefasfese.4pu.com/4733731739732734/The-Essential-Spike-Milligan-by-Spike-Milligan.pdf
    • http://cefasfese.4pu.com/4736739730737736/Spike-Milligan-Man-of-Letters-by-Spike-Milligan.pdf
    • http://cefasfese.4pu.com/2736730739737730/Where-Have-All-the-Bullets-Gone-War-Memoirs-5-by-Spike-Milligan.pdf
    • http://cefasfese.4pu.com/2735735733736734/The-Bald-Twit-Lion-by-Spike-Milligan.pdf
    • http://cefasfese.4pu.com/8738738733731/Monty-His-Part-In-My-Victory-War-Memoirs-3-by-Spike-Milligan.pdf
    • http://cefasfese.4pu.com/3731734739730739/Unspun-Socks-From-A-Chicken-s-Laundry-by-Spike-Milligan.pdf
    • http://cefasfese.4pu.com/4737738736733/-Rommel-Gunner-Who-A-Confrontation-in-the-Desert-by-Spike-Milligan.pdf
    • http://cefasfese.4pu.com/1730739733732735/The-Rasping-of-Gilman-by-J-Michael-Milligan.pdf
    • http://cefasfese.4pu.com/4734731736732732/X-Statix-Omnibus-by-Peter-Milligan.pdf
    • http://cefasfese.4pu.com/4737739731730735/The-Discipline-Volume-One-The-Seduction-by-Peter-Milligan.pdf
    • http://cefasfese.4pu.com/3730738732735734/Batman-Legends-of-the-Dark-Knight-Vol-3-by-Peter-Milligan.pdf
    • http://cefasfese.4pu.com/6736732735737731/Johnny-Nemo-Existentialist-hitman-of-the-future-by-Peter-Milligan.pdf
    • http://cefasfese.4pu.com/3731733731739738/Brigid-s-Cloak-An-Ancient-Irish-Story-by-Bryce-Milligan.pdf
    • http://cefasfese.4pu.com/1731735733738733735/Hocus-Pocus-Versus-the-Stinky-Pong-by-Laura-Milligan.pdf
    • http://cefasfese.4pu.com/8736735731735738/Greek-Street-Volume-3-Medea-s-Luck-by-Peter-Milligan.pdf
    • http://cefasfese.4pu.com/2731735736735733/The-Ghastly-One-The-Sex-Gore-Netherworld-of-Filmmaker-Andy-Milligan-by-Jimmy-McDonough.pdf
    • http://cefasfese.4pu.com/8733734738739736/Learning-Tableau---How-Data-Visualization-Brings-Business-Intelligence-to-Life-by-Joshua-N-Milligan.pdf