Malicious PDF — malware analysis report

Static analysis result for SHA-256 c49158020869e022…

MALICIOUS

PDF

22.2 KB Created: 2019-05-02 05:07:56 +01:00 Authoring application: mPDF 5.7
MD5: 0e46e0d68b0701ae3891c0fff917acba SHA-1: a0df843faa7fbeded44b9c0896441278e5ce2306 SHA-256: c49158020869e022518c2694e298402c17fe8dd3452de0df130f3d73adfb5974
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs were classified as benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO spam or to redirect users to malicious sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6737737736735739/Great-Political-Wit-Laughing-Almost-All-the-Way-to-the-White-House-by-Bob-Dole.pdf
    • http://cefasfese.4pu.com/3730730733735731/Great-Political-Wit-by-Bob-Dole.pdf
    • http://cefasfese.4pu.com/3730730733735733/Great-Presidential-Wit-I-Wish-I-Was-in-the-Book-A-Collection-of-Humorous-Anecdotes-and-Quotations-by-Bob-Dole.pdf
    • http://cefasfese.4pu.com/6737737736736733/The-Dole-Nutrition-Handbook-by-Dole-Nutrition-Institute.pdf
    • http://cefasfese.4pu.com/2739738733731/Will-Rogers-A-Political-Life-by-Richard-D-White-Jr-.pdf
    • http://cefasfese.4pu.com/5730739735739739/The-Great-Law-And-The-Longhouse-A-Political-History-Of-The-Iroquois-Confederacy-by-William-N-Fenton.pdf
    • http://cefasfese.4pu.com/7730735739732737/Great-Dynasties-Capets-Hohenstaufens-Plantagenets-Hapsburgs-Valois-Stuarts-Tudors-Bourbons-of-France-Romanovs-Braganzas-Bourbons-of-Spain-Hohenzollerns-House-of-Savoy-House-of-Hanover-Windsor-Bourbons-of-Naples-Bonapartes-by-R-gine-Pernoud.pdf
    • http://cefasfese.4pu.com/3736734733735737/PATRIARCHS-AND-PROPHETS-PROPHETS-AND-KINGS-THE-DESIRE-OF-AGES-THE-ACTS-OF-THE-APOSTLES-THE-GREAT-CONTROVERSY-BY-ELLEN-G-WHITE-CONFLICT-OF-THE-AGES-SERIES-5-VOL-VOL-1-2-3-4-5-by-Ellen-G-White.pdf
    • http://cefasfese.4pu.com/3738739737737734/Great-House-by-Nicole-Krauss.pdf
    • http://cefasfese.4pu.com/1733739735732738/The-Great-White-Hope-by-Howard-Sackler.pdf
    • http://cefasfese.4pu.com/3736738738738730/The-White-House-Mess-by-Christopher-Buckley.pdf
    • http://cefasfese.4pu.com/4738734736/Commander-in-Chief-White-House-2-by-Katy-Evans.pdf
    • http://cefasfese.4pu.com/5731738735730737/Teddy-Roosevelt-s-Great-White-Fleet-by-James-R-Reckner.pdf
    • http://cefasfese.4pu.com/9734737738735731/Unbelievers-The-Great-White-Throne-Judgment-by-Robb-Moser.pdf
    • http://cefasfese.4pu.com/3738738735733733/The-Great-God-Pan-The-Shining-Pyramid-The-White-People-by-Arthur-Machen.pdf
    • http://cefasfese.4pu.com/1731734732739734738/Thirty-Six-Years-in-the-White-House-Annotated-by-Thomas-F-Pendel.pdf
    • http://cefasfese.4pu.com/2738735735732732/Murder-in-the-White-House-Capital-Crimes-1-by-Margaret-Truman.pdf
    • http://cefasfese.4pu.com/9735735734731735/The-White-Knight-1942-The-House-of-Winslow-40-by-Gilbert-Morris.pdf
    • http://cefasfese.4pu.com/3739735735739737/The-White-Horse-King-The-Life-of-Alfred-the-Great-by-Benjamin-R-Merkle.pdf
    • http://cefasfese.4pu.com/2735739737732734/Silver-White-The-Great-North-Woods-Pack-1-by-Shawn-Underhill.pdf
    • http://cefasfese.4pu.com/7730735739732737/Great-Dy