Malicious PDF — malware analysis report

Static analysis result for SHA-256 d90717c194d1824f…

MALICIOUS

PDF

21.1 KB Created: 2019-05-02 16:39:30 +01:00 Authoring application: mPDF 5.7
MD5: f3614d297fde4f02b73de897726c5ceb SHA-1: 0553bb6c83fe13e9b7ea89c850d5c269b52a4bca SHA-256: d90717c194d1824f06cc53b39a32b99218f2bafad9301b468448b9c5197721c0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs are presented as links to various dictionaries, likely as a lure to direct users to potentially malicious websites. The ML classifier also flagged this PDF as malicious with a high probability. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9447

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9734731739739738/Norwegian-English-Dictionary-A-Pronouncing-and-Translating-Dictionary-of-Modern-Norwegian-Bokm-l-and-Nynorsk-with-a-Historical-and-Grammatical-Introduction-by-Einar-Ingvald-Haugen.pdf
    • http://cefasfese.4pu.com/6739733734733733/Quebecois-Dictionary-amp-Phrasebook-English-Quebecois-Quebecois-English-Hippocrene-Dictionary-amp-Phrasebooks-by-Renata-Isajlovic.pdf
    • http://cefasfese.4pu.com/7733730730730736/Dictionary-of-Physics-Derived-from-the-Concise-Science-Dictionary-by-Oxford-University-Press.pdf
    • http://cefasfese.4pu.com/1731736739739730735/The-Backwords-Dictionary-A-Word-Ending-Dictionary-by-Richard-D-Ekstrom.pdf
    • http://cefasfese.4pu.com/1730737735736739733/Historical-Dictionary-Of-Guinea-by-Thomas-O-39-Toole.pdf
    • http://cefasfese.4pu.com/4730731734737739/Historical-Dictionary-of-the-Cooperative-Movement-by-Jack-Shaffer.pdf
    • http://cefasfese.4pu.com/4738736739738735/Arabic-English-Dictionary-by-Hans-Wehr.pdf
    • http://cefasfese.4pu.com/2737735738730731/The-Oxford-Dictionary-of-English-Etymology-by-C-T-Onions.pdf
    • http://cefasfese.4pu.com/8730737736737739/Korean-English-Dictionary-by-Leon-Kuperman.pdf
    • http://cefasfese.4pu.com/6732739731730732/The-Evasion-English-Dictionary-by-Maggie-Balistreri.pdf
    • http://cefasfese.4pu.com/1731730730739736738/An-Historical-Dictionary-of-German-Figurative-Usage-Fascicle-44-From-Sang-to-Schief-by-Keith-Spalding.pdf
    • http://cefasfese.4pu.com/8732730737731736/A-Tagalog-English-and-English-Tagalog-Dictionary---Scholar-s-Choice-Edition-by-Charles-Nigg.pdf
    • http://cefasfese.4pu.com/6737734732734/A-Concise-Chinese-English-Dictionary-for-Lovers-by-Xiaolu-Guo.pdf
    • http://cefasfese.4pu.com/4730734737738731/A-Concise-Chinese-English-Dictionary-for-Lovers-by-Xiaolu-Guo.pdf
    • http://cefasfese.4pu.com/1731738733739737738/The-Student-s-English-Sanskrit-Dictionary-by-Vaman-Apte.pdf
    • http://cefasfese.4pu.com/1739737733735734/Dictionary-Of-Smoky-Mountain-English-by-Michael-B-Montgomery.pdf
    • http://cefasfese.4pu.com/2732736735734731/American-Dictionary-of-the-English-Language-by-Noah-Webster.pdf
    • http://cefasfese.4pu.com/1731737730731736734/The-Making-of-the-Oxford-English-Dictionary-by-Peter-Gilliver.pdf
    • http://cefasfese.4pu.com/6736730735737730/Dictionary-of-Modern-Political-Ideologies-by-Michael-A-Riff.pdf
    • http://cefasfese.4pu.com/6735735738730736/Focl-ir-P-ca-Irish-English-English-Irish-Dictionary-by-Lelia-Ruckenstein.pdf
    • http://cefasfese.4pu.com/1