Malicious PDF — malware analysis report

Static analysis result for SHA-256 d8215ac816a2c68f…

MALICIOUS

PDF

21.7 KB Created: 2019-05-02 06:06:59 +01:00 Authoring application: mPDF 5.7
MD5: 305a373856311e8fcf2b01121ae495ad SHA-1: 7f048edec766f5d748b1157e315bab079daaffed SHA-256: d8215ac816a2c68fab7dd3ed1735859ee1af8cf9164197773ea2569067132964
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the extracted URLs themselves are currently flagged as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9796

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5730733738738733/From-Ouisconsin-to-Caughnawaga-Or-Tales-of-the-Great-Lakes-First-Nations-by-David-D-Plain.pdf
    • http://cefasfese.4pu.com/6734731736732736/Season-of-the-Witch-A-Great-Lakes-Shipwreck-Tale-by-Mark-David-Veum.pdf
    • http://cefasfese.4pu.com/5736733730736/Cargoes-on-the-Great-Lakes-by-Marie-McPhedran.pdf
    • http://cefasfese.4pu.com/3733733735734736/The-Death-and-Life-of-the-Great-Lakes-by-Dan-Egan.pdf
    • http://cefasfese.4pu.com/3734731735732731/The-Great-Lakes-Water-Wars-by-Peter-Annin.pdf
    • http://cefasfese.4pu.com/1730739736737730732/Odyssey-of-A-Great-Lakes-Sailor-by-Ranga-Iyer.pdf
    • http://cefasfese.4pu.com/8731732734731733/Mammals-of-the-Great-Lakes-Region-by-Allen-Kurta.pdf
    • http://cefasfese.4pu.com/8731732735738737/Amphibians-and-Reptiles-of-the-Great-Lakes-Region-by-James-H-Harding.pdf
    • http://cefasfese.4pu.com/1731735738734737732/Tales-And-Legends-Of-The-English-Lakes-by-Wilson-Armistead.pdf
    • http://cefasfese.4pu.com/5730738738737738/Masters-of-Empire-Great-Lakes-Indians-and-the-Making-of-America-by-Michael-A-McDonnell.pdf
    • http://cefasfese.4pu.com/1731738733739730731/November-s-Fury-The-Deadly-Great-Lakes-Hurricane-of-1913-by-Michael-Schumacher.pdf
    • http://cefasfese.4pu.com/8731739731732735/The-Upper-Country-French-Enterprise-in-the-Colonial-Great-Lakes-by-Claiborne-A-Skinner.pdf
    • http://cefasfese.4pu.com/5735735735734733/Great-Women-from-our-First-Nations-by-Kelly-Fournel.pdf
    • http://cefasfese.4pu.com/7732735739737732/When-The-Fish-Are-Rising---Tales-of-the-Rideau-Lakes-by-Clint-Fleming.pdf
    • http://cefasfese.4pu.com/7730736732735731/Know-Your-Ships-2006-Guide-to-Boats-amp-Boatwatching-Great-Lakes-amp-St-Lawrence-Seaway-by-Roger-Lelievre.pdf
    • http://cefasfese.4pu.com/7730736732736735/Know-Your-Ships-2005-Guide-to-Boats-amp-Boatwatching-Great-Lakes-amp-St-Lawrence-Seaway-by-Roger-A-Lelievre.pdf
    • http://cefasfese.4pu.com/7730736731739730/Know-Your-Ships---Guide-to-Boats-amp-Boatwatching-Great-Lakes-amp-St-Lawrence-Seaway-41st-Edition-by-Roger-A-Lelievre.pdf
    • http://cefasfese.4pu.com/3730735738737733/Plain-Tales-from-the-Hills-by-Rudyard-Kipling.pdf
    • http://cefasfese.4pu.com/7734731733733733/Smithsonian-Guides-to-Historic-America-The-Great-Lakes-States---Ohio-Indiana-Illinois-Michigan-Wisconsin-Minnesota-by-Suzanne-Winckler.pdf
    • http://cefasfese.4pu.com/1730735732733739731/David-Cusick-s-Sketches-of-Ancient-History-of-the-Six-Nations-by-David-Cusick.pdf
    • http://cefasfese.4pu.com/1731735738734737732/Tales-And-Legends-Of-The-English-Lakes-