Malicious PDF — malware analysis report

Static analysis result for SHA-256 c16a03d061b9c0b3…

MALICIOUS

PDF

27.0 KB Created: 2019-05-02 06:59:42 +01:00 Authoring application: mPDF 5.7
MD5: f055c214bf0b523cd7a9e6e2b392d215 SHA-1: ffc271fa4847f98e4ed26d5af92b4f4a08e9099f SHA-256: c16a03d061b9c0b39501c0222e10d9a281e0c27f25acf65cfc15244378139bb6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be directing users to a vast number of external links, likely for SEO poisoning or to host further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731733737735739737/Le-guide-complet-du-Pal-o-Manger-bien-pour-vivre-mieux-by-Benjamin-Gallier.pdf
    • http://cefasfese.4pu.com/7739739730739735/BIEN-MANGER-guide-pas-pas-perdre-du-poids-manger-plaisir-pas-de-r-gime-plusieurs-quiz-Mon-coach-mon-bien--tre-t-2-by-Ambre-Souverain.pdf
    • http://cefasfese.4pu.com/8731734736730738/J-ai-choisi-de-bien-vieillir-Vivre-plus-longtemps-et-mieux-by-Fran-oise-Pr-Forette.pdf
    • http://cefasfese.4pu.com/6735736731732731/13-Secrets-pour-mieux-vivre-by-Lyzon-Daigle.pdf
    • http://cefasfese.4pu.com/7731738733733734/CYCLES-BIOLOGIQUES-CELLULAIRES-MEMORISES-7-Cl-s-pour-vivre-mieux-t-2-by-Marie-Del-Sol.pdf
    • http://cefasfese.4pu.com/8731733732735732/Guide-des-13-herbes-miraculeuses-pour-votre-bien--tre-Guides-pratiques-du-bien--tre-by-Julie-Duchesnay.pdf
    • http://cefasfese.4pu.com/7735738737732735/Face-aux-narcissiques-Mieux-les-comprendre-pour-mieux-les-d-sarmer-by-Wendy-T-Behary.pdf
    • http://cefasfese.4pu.com/7730736736736732/Comment-bien-vous-nourrir-pour-bien-nourrir-votre-b-b-venir-by-John-Hamilton.pdf
    • http://cefasfese.4pu.com/5733730734734737/Des-vies-en-mieux-d-Anna-Gavalda-R-sum-complet-et-analyse-d-taill-e-de-l-oeuvre-by-El-onore-Quinaux.pdf
    • http://cefasfese.4pu.com/7731731731738739/Eat-and-Run-Manger-pour-gagner-Terra-nova-by-Scott-Jurek.pdf
    • http://cefasfese.4pu.com/8732732730734739/Manager-avec-les-philosophes-6-pratiques-pour-mieux-tre-et-agir-au-travail-by-Flora-Bernard.pdf
    • http://cefasfese.4pu.com/7736730735737736/Wake-up-4-principes-fondamentaux-pour-arr-ter-de-vivre-sa-sa-vie-moiti-endormi-by-Christine-Lewicki.pdf
    • http://cefasfese.4pu.com/5735731739736734/Les-112-Secrets-des-As-de-la-Vente-D-couvrez-les-astuces-des-Pros-de-la-vente-pour-n-gocier-et-mieux-vendre-by-Fr-d-ric-Canevet.pdf
    • http://cefasfese.4pu.com/5738735737732732/ADIEU-LES-IMPATIENCES-Rem-des-Naturels-Pour-Soigner-Le-Syndrome-Des-Jambes-Sans-Repos-Sant-amp-Bien-Etre-Naturel-t-2-by-Mich-le-Bellay.pdf
    • http://cefasfese.4pu.com/8735730730735732/GUIDE-COMPLET-DU-JARDINAGE-QUEBEC-by-Ga-tan-Desch-nes.pdf
    • http://cefasfese.4pu.com/6739734730737734/Evolution-of-a-Wine-Drinker-Alicia-Bien-s-Amazing-Tales-of-Learning-How-to-Drink-with-Taste-Legally-by-Alicia-Bien.pdf
    • http://cefasfese.4pu.com/7736736733737736/L-orthographe-Plus-aucun-doute-pour-crire-et-peler-les-mots-de-la-langue-fran-aise-Petit-guide-t-131-by-Petit-Guide.pdf
    • http://cefasfese.4pu.com/1730734739733738735/Make-Your-Own-Field-Guide-by-Benjamin-Harper.pdf
    • http://cefasfese.4pu.com/6739734738734735/Guide-proph-tique-pour-la-fin-des-temps-Affronter-l-avenir-sans-crainte-by-Derek-Prince.pdf
    • http://cefasfese.4pu.com/7738730736732738/Guide-du-d-butant-en-cholocalisation-pour-les-Aveugles-et-les-Mal-voyants-Apprenez-voir-avec-les-oreilles-by-Tim-Johnson.pdf
    • http://cefasfese.4pu.com/8731733732735732/Guide-des-13-herbes-miraculeuses-pour-votre-bien--tre-Guides-pratiques-du-bien--tre-by-