Malicious PDF — malware analysis report

Static analysis result for SHA-256 d0fd88df67c3c52e…

MALICIOUS

PDF

19.3 KB Created: 2019-05-02 06:48:32 +01:00 Authoring application: mPDF 5.7
MD5: f281bd176f64ab7ad209740875b43915 SHA-1: 7b60968660758c95a1ae558a97c23b0b6243c294 SHA-256: d0fd88df67c3c52eedffdd3c87fc61194e7fc890fbd495dc1220bf3891910a4f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier as malicious. It contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM' heuristic, pointing to various external PDF documents. These links likely serve as a lure to direct users to potentially malicious content or phishing sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730739732735739733/Yo-Soy-Muslim-A-Father-s-Letter-to-His-Daughter-by-Mark-Gonzales.pdf
    • http://cefasfese.4pu.com/7736732734731731/Letters-Message-Letter-Lettre-de-Cachet-Pen-Pal-Zinoviev-Letter-Chain-Letter-Letter-of-Marque-Letter-of-Credence-by-Source-Wikipedia.pdf
    • http://cefasfese.4pu.com/3737730731734/Letter-to-His-Father-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/1730739732736734731/Gonzales-Rodriguez-Uncut-amp-Uncensored-by-Patrisia-Gonzales.pdf
    • http://cefasfese.4pu.com/1731739730735732/Letter-to-My-Daughter-by-George-Bishop.pdf
    • http://cefasfese.4pu.com/9739735732731/Letter-to-My-Daughter-by-Maya-Angelou.pdf
    • http://cefasfese.4pu.com/6733736738730/Zenzele-A-Letter-for-My-Daughter-by-J-Nozipo-Maraire.pdf
    • http://cefasfese.4pu.com/1737735736730731/Father-s-Arcane-Daughter-by-E-L-Konigsburg.pdf
    • http://cefasfese.4pu.com/4739734739734737/Father-Melancholy-s-Daughter-by-Gail-Godwin.pdf
    • http://cefasfese.4pu.com/5732737735731/Father-Melancholy-s-Daughter-by-Gail-Godwin.pdf
    • http://cefasfese.4pu.com/8735732738730/Father-Daughter-Incest-by-Judith-Lewis-Herman.pdf
    • http://cefasfese.4pu.com/3739731734734730/The-Maharaja-s-Household-A-Daughter-s-Memories-of-Her-Father-by-Binodini.pdf
    • http://cefasfese.4pu.com/2737738730733736/First-They-Killed-My-Father-A-Daughter-of-Cambodia-Remembers-by-Loung-Ung.pdf
    • http://cefasfese.4pu.com/5730731733738739/My-Father-Had-a-Daughter-Judith-Shakespeare-s-Tale-by-Grace-Tiffany.pdf
    • http://cefasfese.4pu.com/1731730733734731/The-Year-We-Disappeared-A-Father---Daughter-Memoir-by-Cylin-Busby.pdf
    • http://cefasfese.4pu.com/1730731732736735735/Father-Daughter-Mother-Son-Freeing-Ourselves-from-the-Complexes-That-Bind-Us-by-Verena-Kast.pdf
    • http://cefasfese.4pu.com/4737733732733730/Good-Muslim-Bad-Muslim-America-the-Cold-War-and-the-Roots-of-Terror-by-Mahmood-Mamdani.pdf
    • http://cefasfese.4pu.com/5730735738731733/Trespassing-on-Einstein-s-Lawn-A-Father-a-Daughter-the-Meaning-of-Nothing-and-the-Beginning-of-Everything-by-Amanda-Gefter.pdf
    • http://cefasfese.4pu.com/3737734734732735/You-ll-Never-Know-The-Campaign-to-Understand-My-WWII-Veteran-Father-A-Daughter-s-Memoir-by-Carol-Tyler.pdf
    • http://cefasfese.4pu.com/1731737731734735733/The-Muslim-Woman-s-and-Muslim-Man-s-Dress-by-Jamal-Badawi.pdf
    • http://cefasfese.4pu.com/6733736738730/Zenzele-A-Letter-for-My-Daughter-by-J-Nozipo-Maraire