Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba6491811008491e…

MALICIOUS

PDF

19.0 KB Created: 2019-05-02 05:27:23 +01:00 Authoring application: mPDF 5.7
MD5: c01cd59bc274240e18f5deaa06b8409f SHA-1: 47350f16e42cb64b6ff4b41fca98bae82881e796 SHA-256: ba6491811008491e637dfe459331abc4573f8b1257de78c8285b62aa9fa42a2a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated and unreadable, the presence of numerous external links suggests a malicious intent, possibly for SEO manipulation or to distribute further malware. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu
    • http://cefasfese.4pu.com/5732734731738/Elon-Musk-Inventing-the-Future-by-Ashlee-Vance.pdf
    • http://cefasfese.4pu.com/4734738733734730/Elon-Musk-Tesla-SpaceX-and-the-Quest-for-a-Fantastic-Future-by-Ashlee-Vance.pdf
    • http://cefasfese.4pu.com/4730739731738739/Elon-Musk-How-the-Billionaire-CEO-of-SpaceX-and-Tesla-is-Shaping-our-Future-by-Ashlee-Vance.pdf
    • http://cefasfese.4pu.com/7737736733/The-Space-Barons-Elon-Musk-Jeff-Bezos-and-the-Quest-to-Colonize-the-Cosmos-by-Christian-Davenport.pdf
    • http://cefasfese.4pu.com/3734737738732736/Inventing-the-Future-Postcapitalism-and-a-World-Without-Work-by-Nick-Srnicek.pdf
    • http://cefasfese.4pu.com/1736732739737732/Eighteenth-Century-Women-Poets-and-Their-Poetry-Inventing-Agency-Inventing-Genre-by-Paula-R-Backscheider.pdf
    • http://cefasfese.4pu.com/7734739735737733/The-Vance-Stance-by-Vance-Bonner.pdf
    • http://cefasfese.4pu.com/6732730732735733/The-Mystery-of-the-Shemitah-Updated-Edition-The-3-000-Year-Old-Mystery-That-Holds-the-Secret-of-America-s-Future-the-World-s-Future-and-Your-Future-by-Jonathan-Cahn.pdf
    • http://cefasfese.4pu.com/4732733737732736/The-Mystery-of-the-Shemitah-The-3-000-Year-Old-Mystery-That-Holds-the-Secret-of-America-s-Future-the-World-s-Future-and-Your-Future-by-Jonathan-Cahn.pdf
    • http://cefasfese.4pu.com/1730735736738736737/Herzl-by-Amos-Elon.pdf
    • http://cefasfese.4pu.com/4732736734737735/A-Is-for-Musk-Ox-by-Erin-Cabatingan.pdf
    • http://cefasfese.4pu.com/4735733730738731/Uninvited-by-Justine-Musk.pdf
    • http://cefasfese.4pu.com/8735731738731737/The-Poet-Man-Et-Cetera-by-Elon-Allan-Richards.pdf
    • http://cefasfese.4pu.com/4732736732736732/Musk-Ox-Counts-by-Erin-Cabatingan.pdf
    • http://cefasfese.4pu.com/1739738733738738/The-Word-Changers-by-Ashlee-Willis.pdf
    • http://cefasfese.4pu.com/1730731739738733/The-Word-Changers-by-Ashlee-Willis.pdf
    • http://cefasfese.4pu.com/2737736734732737/Curvy-Girls-Rock-by-Ashlee-Alexander.pdf
    • http://cefasfese.4pu.com/8739730739739737/Seduced-The-Vampire-Huntress-2-by-Ashlee-Sinn.pdf
    • http://cefasfese.4pu.com/1730735734734731737/Out-of-the-Shadows-The-Moments-We-Stand-2-by-Ashlee-Birk.pdf
    • http://cefasfese.4pu.com/8739730738737732/Desired-by-the-Bear-The-Alaska-Shifters-4-by-Ashlee-Sinn.pdf