Malicious PDF — malware analysis report

Static analysis result for SHA-256 b41ce100d3276d7b…

MALICIOUS

PDF

20.3 KB Created: 2020-01-02 06:04:03 +00:00 Authoring application: mPDF 5.7
MD5: 2ec03445c3b9144507d3ac69b4400a2a SHA-1: e49c47110bf05ec7e32a632d9f05b5f2533b26f5 SHA-256: b41ce100d3276d7b58d93b8d56394ad7af93628c1149bcb9afa2d2178da13392
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. While no scripts were extracted, the structure suggests a malicious intent to redirect users to potentially harmful content or to manipulate search engine results.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5730733731734734/Sofia-the-First-Sofia-s-First-Christmas-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/5730733731734735/Walt-Disney-s-Christmas-Parade-2-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/5730733731735730/Merry-Christmas-Uncle-Scrooge-McDuck-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/3734739736735730/Story-Walt-Disney-Animation-Studios-The-Archive-Series-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/3734739736737732/Design-Walt-Disney-Animation-Studios-The-Archive-Series-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/3731731735731730/Cooking-with-Mickey-Around-our-World-The-Most-Requested-Recipes-from-Walt-Disney-World-and-Disneyland-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/3734739736735733/Animation-Walt-Disney-Animation-Studios-The-Archive-Series-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/4730732736732737/Walt-Disney-s-America-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/2735734739733739/The-Haunted-House-Disney-s-Wonderful-World-of-Reading-33-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/1730736738732730734/Gulliver-Mickey-Disney-s-Wonderful-World-of-Reading-27-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/2731735733730732/The-Emperor-s-New-Clothes-Disney-s-wonderful-world-of-reading-29-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/8736736731734731/Peter-Pan-Disney-Classics-Collection-Storybook-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/6736730736730/Disney-s-DuckTales-The-Hunt-for-the-Giant-Pearl-A-Little-Golden-Book-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/4737730731732731/Let-Your-Heart-Be-Your-Guide-Stories-About-Happiness-Disney-s-Family-Storybook-Library-11-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/4736731734730733/Mickey-and-the-Roadster-Racers-Race-for-the-Rigatoni-Ribbon-Disney-Storybook-eBook-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/3730732732738730/The-Little-Mermaid-Disney-Princess-2-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/6736738735732731/Cendrillon---Disney-Cin-ma-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/8732739733739/Fantasyland-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/1737730731739733/Cinderella-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/8736736731735731/Toy-Story-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/2735734739733739/The-Haunted-House-Disney-s-Wonderf