Malicious PDF — malware analysis report

Static analysis result for SHA-256 bbb9abd6f52fa40f…

MALICIOUS

PDF

17.1 KB Created: 2019-04-30 19:28:16 +01:00 Authoring application: mPDF 5.7
MD5: ba25b9a56fe5929059d170d2d8865b46 SHA-1: 397a834a0d28d2320edb6ffe07c884e9e8cf6354 SHA-256: bbb9abd6f52fa40f1b20bdf82026fbbb8fed5f4d999d1df9a2dd002211a37ebe
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded links, forming a link farm. These links, such as http://cefasfese.4pu.com/5732738738733736/Louise-Bourgeois-The-Insomnia-Drawings-by-Louise-Bourgeois.pdf, likely serve to direct users to malicious content or facilitate further infection. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5732738738733736/Louise-Bourgeois-The-Insomnia-Drawings-by-Louise-Bourgeois.pdf
    • http://cefasfese.4pu.com/5732738737732735/Louise-Bourgeois-by-Ulf-K-ster.pdf
    • http://cefasfese.4pu.com/5732738738732738/Louise-Bourgeois-by-Marie-Laure-Bernadac.pdf
    • http://cefasfese.4pu.com/9733730735731736/The-Bourgeois-Gentleman-by-Moli-re.pdf
    • http://cefasfese.4pu.com/4738731738738739/Franklin-In-The-Dark-by-Paulette-Bourgeois.pdf
    • http://cefasfese.4pu.com/5732738736738730/Franklin-Goes-to-School-by-Paulette-Bourgeois.pdf
    • http://cefasfese.4pu.com/5732738737732730/Franklin-s-Thanksgiving-by-Paulette-Bourgeois.pdf
    • http://cefasfese.4pu.com/5732738736738735/Hurry-Up-Franklin-by-Paulette-Bourgeois.pdf
    • http://cefasfese.4pu.com/5732738737736736/Franklin-s-Blanket-by-Paulette-Bourgeois.pdf
    • http://cefasfese.4pu.com/9734736734731739/Louise-Amended-by-Louise-Krug.pdf
    • http://cefasfese.4pu.com/5732738737732731/How-Revolutionary-Were-the-Bourgeois-Revolutions-by-Neil-Davidson.pdf
    • http://cefasfese.4pu.com/2736733737738735/Franklin-s-Christmas-Gift-by-Paulette-Bourgeois.pdf
    • http://cefasfese.4pu.com/5732738737738731/Fairly-Hexed-Witches-of-Winterfield-3-by-Sara-Bourgeois.pdf
    • http://cefasfese.4pu.com/5732738737731733/Pretty-Hexed-Witches-of-Winterfield-1-by-Sara-Bourgeois.pdf
    • http://cefasfese.4pu.com/5732738739732736/Brewing-Love-Tree-s-Hollow-Witches-1-by-Sara-Bourgeois.pdf
    • http://cefasfese.4pu.com/5732738739733731/Pleasure-Wars-The-Bourgeois-Experience-Victoria-to-Freud-by-Peter-Gay.pdf
    • http://cefasfese.4pu.com/5738732731738737/Furetiere-s-Roman-Bourgeois-and-the-Problem-of-Exchange-Titular-Economies-by-Craig-Moyes.pdf
    • http://cefasfese.4pu.com/4736739731733731/Journey-Around-My-Room-The-Autobiography-of-Louise-Bogan-by-Louise-Bogan.pdf
    • http://cefasfese.4pu.com/1736738738738739/Disturbing-the-Peace-The-Story-of-Father-Roy-Bourgeois-and-the-Movement-to-Close-the-School-of-the-Americas-by-James-Hodge.pdf
    • http://cefasfese.4pu.com/9732733737734734/The-Problematic-Bourgeois-Twentieth-Century-Criticism-on-Thomas-Mann-s-Buddenbrooks-and-the-Magic-Mountain-by-Hugh-Ridley.pdf