Malicious PDF — malware analysis report

Static analysis result for SHA-256 caa7fad656e3aa3e…

MALICIOUS

PDF

19.9 KB Created: 2019-06-04 10:27:43 +01:00 Authoring application: mPDF 5.7
MD5: 12cd6b9fb0d8c33f94ba2d4e92b4f634 SHA-1: f6cfa2285a841a89be744cc3668dfea8695dda67 SHA-256: caa7fad656e3aa3e24a46dc2d54a08edb3becb572569ae1e46315ef704ecde94
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign content, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a lure for further malicious activity. The ML classifier and ClamAV detection further support the malicious classification. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-9646404-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-9646404-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5738731739738737/Audrey-Hepburn-An-Intimate-Portrait-by-Diana-Maychick.pdf
    • http://cefasfese.4pu.com/5738732730733733/Audrey-and-Bill-A-Romantic-Biography-of-Audrey-Hepburn-and-William-Holden-by-Edward-Z-Epstein.pdf
    • http://cefasfese.4pu.com/5738732730733738/Audrey-A-Biography-Of-Audrey-Hepburn-by-Charles-Higham.pdf
    • http://cefasfese.4pu.com/1731739736738738730/Meryl-Streep-The-Reluctant-Superstar-by-Diana-Maychick.pdf
    • http://cefasfese.4pu.com/5738731739738736/Audrey-Hepburn-by-F-X-Feeney.pdf
    • http://cefasfese.4pu.com/5738731739737739/Enchantment-The-Life-of-Audrey-Hepburn-by-Donald-Spoto.pdf
    • http://cefasfese.4pu.com/5738732730731731/Audrey-Hepburn-A-Life-in-Pictures-by-Pierre-Henri-Verlhac.pdf
    • http://cefasfese.4pu.com/4730737734737738/A-Star-Danced-The-Life-Of-Audrey-Hepburn-by-Robyn-Karney.pdf
    • http://cefasfese.4pu.com/3735736739738735/Fifth-Avenue-5-A-M-Audrey-Hepburn-Breakfast-at-Tiffany-s-and-The-Dawn-of-the-Modern-Woman-by-Sam-Wasson.pdf
    • http://cefasfese.4pu.com/7736733733730738/Intimate-Intuition-Lotus-House-6-by-Audrey-Carlan.pdf
    • http://cefasfese.4pu.com/9731733734738737/Verlieben-sie-sich-nie-in-ein-wildes-Gesch-pf-Audrey-Hepburn-und-quot-Fr-hst-ck-bei-Tiffany-quot-by-Sam-Wasson.pdf
    • http://cefasfese.4pu.com/1738731734736/The-Life-of-an-Oak-An-Intimate-Portrait-by-Glenn-Keator.pdf
    • http://cefasfese.4pu.com/9734731734737739/The-Hidden-Hitler-An-Intimate-Portrait-by-Lothar-Machtan.pdf
    • http://cefasfese.4pu.com/1734730739732736/Franklin-and-Winston-An-Intimate-Portrait-of-an-Epic-Friendship-by-Jon-Meacham.pdf
    • http://cefasfese.4pu.com/7739731731730738/Winston-Churchill-An-Intimate-Portrait-by-Violet-Bonham-Carter.pdf
    • http://cefasfese.4pu.com/5730732735733736/An-Elephant-s-Life-An-Intimate-Portrait-from-Africa-by-Caitlin-O-39-Connell.pdf
    • http://cefasfese.4pu.com/2737732738736733/Griefland-An-Intimate-Portrait-of-Love-Loss-and-Unlikely-Friendship-by-Armen-Bacon.pdf
    • http://cefasfese.4pu.com/1738733731731/Holmespun-An-Intimate-Portrait-of-an-Amish-and-Mennonite-Community-by-Laura-Hurwitz.pdf
    • http://cefasfese.4pu.com/5730730738730737/Ponce-de-Leon-An-Intimate-Portrait-of-Atlanta-s-Most-Famous-Avenue-by-George-Mitchell.pdf
    • http://cefasfese.4pu.com/2731738736731/The-Five-of-Hearts-An-Intimate-Portrait-of-Henry-Adams-and-His-Friends-1880-1918-by-Patricia-O-39-Toole.pdf
    • http://cefasfese.4pu.com/4730737734737738/A-Star-Danc