Malicious PDF — malware analysis report

Static analysis result for SHA-256 c398915e8d1525df…

MALICIOUS

PDF

18.3 KB Created: 2019-09-06 18:48:45 +01:00 Authoring application: mPDF 5.7
MD5: d39d980c9e17a0de766c6ff24eb9310e SHA-1: 2cd572321ae79367523fc4111bbe3816fedeb9db SHA-256: c398915e8d1525df2f2b1dc581d18a1fc8dd69a818016682785f118f5168c083
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, likely for SEO manipulation or to serve as a distribution point for further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5734733733733731/Romain-Rolland-And-A-World-At-War-by-William-T-Starr.pdf
    • http://cefasfese.4pu.com/6732737731739737/Romain-Rolland-Oeuvres-Majeures-L-dition-int-grale-Jean-Christophe-Au-dessus-de-la-m-l-e-Vie-de-Tolsto-Vie-de-Beethoven-Colas-Breugnon--L-me-enchant-by-Romain-Rolland.pdf
    • http://cefasfese.4pu.com/5734733732730730/Robespierre-by-Romain-Rolland.pdf
    • http://cefasfese.4pu.com/5734733732734733/Cl-rambault-by-Romain-Rolland.pdf
    • http://cefasfese.4pu.com/5733736735734738/Jean-Christophe-Journey-s-End-by-Romain-Rolland.pdf
    • http://cefasfese.4pu.com/5734733731738738/Life-of-Vivekananda-and-the-Universal-Gospel-by-Romain-Rolland.pdf
    • http://cefasfese.4pu.com/9738730731735732/Two-Plays-of-the-French-Revolution-The-Fourteenth-of-July-and-Danton-by-Romain-Rolland.pdf
    • http://cefasfese.4pu.com/5734733732735732/Romain-Rolland-and-the-Politics-of-Intellectual-Engagement-by-David-James-Fisher.pdf
    • http://cefasfese.4pu.com/1731733732730731736/Johann-Christof-Johann-Christof-Kinder-Und-Jugendjahre---2-johann-Christof-in-Paris---3-johann-Christof-Am-Ziel-by-Romain-Rolland.pdf
    • http://cefasfese.4pu.com/1733739730733733/David-Starr-Space-Ranger-Lucky-Starr-1-by-Isaac-Asimov.pdf
    • http://cefasfese.4pu.com/1734735734738730/Starr-Fated-Starr-1-by-G-E-Griffin.pdf
    • http://cefasfese.4pu.com/9735734730734731/William-Gilbert-Galileo-Galilei-William-Harvey-Great-Books-of-the-Western-World-28-by-William-Gilbert.pdf
    • http://cefasfese.4pu.com/5737730736737/Lucky-Starr-and-the-Big-Sun-of-Mercury-Lucky-Starr-4-by-Isaac-Asimov.pdf
    • http://cefasfese.4pu.com/5734733732733739/Rosie-and-Rolland-in-the-Legendary-Show-and-Tell-by-Jon-Berg.pdf
    • http://cefasfese.4pu.com/5738730735736/The-Ski-Bum-by-Romain-Gary.pdf
    • http://cefasfese.4pu.com/4733730730733732/The-Way-of-the-World-by-William-Congreve.pdf
    • http://cefasfese.4pu.com/1738737733731737/New-World-Order-by-William-T-Still.pdf
    • http://cefasfese.4pu.com/5734733732737734/George-MacDonald-Victorian-Mythmaker-by-Rolland-Hein.pdf
    • http://cefasfese.4pu.com/3739735732735731/The-Life-Before-Us-by-Romain-Gary.pdf
    • http://cefasfese.4pu.com/6732739738735/The-Life-Before-Us-by-Romain-Gary.pdf
    • http://cefasfese.4pu.com/1731733732730731736/Johann-Christof-Johann-Christof-Kinder-Und-Jugendjahre---2-johann-Christof-in-Paris---3-johann-Christof-Am-Ziel-by-Ro