Malicious PDF — malware analysis report

Static analysis result for SHA-256 c73c7dd36d212abf…

MALICIOUS

PDF

20.9 KB Created: 2019-11-07 13:40:19 +00:00 Authoring application: mPDF 5.7
MD5: e673592cea572af175fd501d8c5a5c8e SHA-1: d29434df6fd632f2e74521d2bcda0e552f973cb8 SHA-256: c73c7dd36d212abf3cbdcb45cc233851622644ce3cb32f75c5cde134a2e887d0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS classifier also flagged this file with high confidence. The embedded URLs, such as http://cefasfese.4pu.com/5732733733739738/The-Chronicles-Of-Narnia-The-Magician-s-Nephew-The-Lion-The-Witch-and-The-Wardrobe-The-Horse-and-His-Boy-Prince-Caspian-The-Voyage-of-The-Dawn-Treader-The-Silver-Chair-The-Last-Battle-The-Chronicles-of-Narnia-1-7-by-C-S-Lewis.pdf, likely lead to malicious content or further infection vectors.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5732733733739738/The-Chronicles-Of-Narnia-The-Magician-s-Nephew-The-Lion-The-Witch-and-The-Wardrobe-The-Horse-and-His-Boy-Prince-Caspian-The-Voyage-of-The-Dawn-Treader-The-Silver-Chair-The-Last-Battle-The-Chronicles-of-Narnia-1-7-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/7732734732739738/THE-LION-THE-WITCH-AND-THE-WARDROBE-THE-CHRONICLES-OF-NARNIA-Tome-1-THE-CHRONICLES-OF-NARNIA-1-7-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/7732739730730/The-Lion-the-Witch-and-the-Wardrobe-The-Chronicles-of-Narnia-1-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/1730738735731738738/The-Lion-the-Witch-and-the-Wardrobe-Chronicles-of-Narnia-1-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/4731734732734735/The-Lion-the-Witch-and-the-Wardrobe-Chronicles-of-Narnia-2-or-1-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/2735731735732/The-Lion-the-Witch-and-the-Wardrobe-Chronicles-of-Narnia-1-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/4732737731739733/The-Lion-The-Witch-And-The-Wardrobe-Chronicles-of-Narnia-1-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/7738732734735/The-Lion-the-Witch-and-the-Wardrobe-The-Chronicles-of-Narnia-1-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/8739733738733731/The-Lion-the-Witch-and-the-Wardrobe-The-Chronicles-of-Narnia-Chronological-Order-2-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/8737730734732/Piano-Vocal-Guitar-Sheet-Music-The-Chronicles-of-Narnia-The-Lion-the-Witch-and-The-Wardrobe-by-Harry-Gregson-Williams.pdf
    • http://cefasfese.4pu.com/8738733731730737/Inside-Narnia-A-Guide-to-Exploring-The-Lion-the-Witch-and-the-Wardrobe-by-Devin-Brown.pdf
    • http://cefasfese.4pu.com/5735734735737738/The-Lion-the-Witch-And-the-Wardrobe-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/6734738734738732/The-Lion-the-Witch-and-the-Wardrobe-A-Story-For-Children-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/1739739734737737/The-Lion-The-Witch-and-the-Wardrobe-by-Robin-Lawrie.pdf
    • http://cefasfese.4pu.com/4730736733733739/The-Chronicles-of-Narnia-Including-an-Essay-on-Writing-by-C-S-Lewis-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/9730738731734732/Prince-Caspian-the-Chronicles-of-Narnia---C-S-Lewis-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/3732730737731/The-Chronicles-of-Narnia-Chronicles-of-Narnia-1-7-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/7739731732736730/The-Chronicles-of-Narnia-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/3731737738733739/The-Last-Battle-The-Chronicles-of-Narnia-7-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/3731737732733/The-Last-Battle-Chronicles-of-Narnia-7-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/4732737731739733/The-Lion-The-Witch-And-The-Wardrobe-Chronicles-of-Narnia-1-by-C-S-Lewis.pd