Malicious PDF — malware analysis report

Static analysis result for SHA-256 b2108a0d1dc58d55…

MALICIOUS

PDF

22.2 KB Created: 2019-11-07 20:55:20 +00:00 Authoring application: mPDF 5.7
MD5: e69b588a6023554ebca8ca20d78cadd3 SHA-1: 9e05461e861bdb3dfc400b80f5e8e2a4bd3201a6 SHA-256: b2108a0d1dc58d5588a1e1e5d0e05c1b847c09bb5a53dc99b26d27760b98a7ac
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign content, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malware. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3733739734733733/Happy-Valley-A-Southern-Country-Novel-1-by-Diana-Anderson.pdf
    • http://cefasfese.4pu.com/2738731732733738/A-Southern-Country-Novel-Series-Books-1-3-Boxed-Set-Happy-Valley-Mississippi-Gambler-Mississippi-Bluff-by-Diana-Anderson.pdf
    • http://cefasfese.4pu.com/2738731730735736/Famous-in-a-Small-Town-An-Entering-Southern-Country-Novel-1-by-Diana-Anderson.pdf
    • http://cefasfese.4pu.com/2738731731739730/Ghost-in-a-Small-Town-An-Entering-Southern-Country-Novel-Book-2-by-Diana-Anderson.pdf
    • http://cefasfese.4pu.com/3738731734732738/Summer-in-Snow-Valley-Snow-Valley-Romance-Anthologies-2-by-Cindy-Roland-Anderson.pdf
    • http://cefasfese.4pu.com/8739731735732/Sweet-Valley-Twins-Collection-Jessica-s-No-Angel-Happy-Mother-s-Day-Lila-Jessica-Takes-Charge-Sweet-Valley-Twins-Super-Edition-11-115-116-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/1732736733736734/Happy-Valley-A-Novel-by-Sugar-Ray-Dodge.pdf
    • http://cefasfese.4pu.com/4730737738731730/Child-Of-The-Happy-Valley-by-Juanita-Carberry.pdf
    • http://cefasfese.4pu.com/1730739730737730/Southern-Christmas-Happy-Holidays-Y-all-by-David-Matheny.pdf
    • http://cefasfese.4pu.com/1732737737739736/Saving-the-Valley-Satu-Country-2-by-Rebecca-Jane.pdf
    • http://cefasfese.4pu.com/2738731731738732/Remember-When-by-Diana-Anderson.pdf
    • http://cefasfese.4pu.com/1730733738730739730/Country-Days-Chronicles-Of-Knysna-amp-The-Southern-Cape-by-Hjalmar-Thesen.pdf
    • http://cefasfese.4pu.com/2738738731730731/The-Bristol-Sessions-Writings-About-the-Big-Bang-of-Country-Music-Contributions-to-Southern-Appalachian-Studies-by-Ted-Olson.pdf
    • http://cefasfese.4pu.com/5732735730737733/An-Independent-Women-s-World-From-the-12th-Century-to-the-Present-The-Beguines-and-Beguinages-in-the-Southern-Low-Country-by-Genevieve-de-Cant.pdf
    • http://cefasfese.4pu.com/3734731737735739/An-Unexpected-Kiss-Christmas-in-Snow-Valley-1-by-Cindy-Roland-Anderson.pdf
    • http://cefasfese.4pu.com/2737733739730733/Operation-Kiss-the-Girl-Snow-Valley-Romance-by-Cindy-Roland-Anderson.pdf
    • http://cefasfese.4pu.com/7734730739736734/A-New-Religious-America-How-a-quot-Christian-Country-quot-Has-Become-the-World-s-Most-Religiously-Diverse-Nation-by-Diana-L-Eck.pdf
    • http://cefasfese.4pu.com/2730731739731733/Country-Brides-A-Little-Bit-Country-Country-Bride-by-Debbie-Macomber.pdf
    • http://cefasfese.4pu.com/1730733730734734731/Works-by-Poul-Anderson-Book-Guide-Novellas-by-Poul-Anderson-Novels-by-Poul-Anderson-Short-Stories-by-Poul-Anderson-by-Source-Wikipedia.pdf
    • http://cefasfese.4pu.com/3730739731735/Happy-Happy-Happy-by-Phil-Robertson.pdf
    • http://cefasfese.4pu.com/8739731735732/Sweet-Valley-Twins-Collection-Jessica-s-No-Angel-Happy-Mother-s-Day-Lila-Jessica-Takes-Charge-Sweet-Valley-Twins-Super-Edition-11-115-116-by