Malicious PDF — malware analysis report

Static analysis result for SHA-256 d9101b3afe9da79f…

MALICIOUS

PDF

16.0 KB Created: 2019-05-02 17:04:08 +01:00 Authoring application: mPDF 5.7
MD5: 0c7bb0ebe52670fa2ee456d929f522b2 SHA-1: 9d2ecd8e676bf47a6b80dd31430b763e854bc0a9 SHA-256: d9101b3afe9da79fdc0088bd4d019f7fa64cd3d8d81dfc1ca3a55fff7156b952
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While most of these links point to benign content, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO poisoning or to act as a landing page for further exploitation. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1733731735732739/Point-of-Honour-Sarah-Tolerance-1-by-Madeleine-E-Robins.pdf
    • http://cefasfese.4pu.com/2730734737731739/Sold-for-Endless-Rue-by-Madeleine-E-Robins.pdf
    • http://cefasfese.4pu.com/5736732730735731/A-Light-So-Lovely-The-Spiritual-Legacy-of-Madeleine-L-Engle-Author-of-A-Wrinkle-in-Time-by-Sarah-Arthur.pdf
    • http://cefasfese.4pu.com/1737732732739736/Reckless-Point-Cross-Point-Village-1-by-Cora-Brent.pdf
    • http://cefasfese.4pu.com/2733734730734732/Counter-Point-Heath-s-Point-Suspense-1-by-Marji-Laine.pdf
    • http://cefasfese.4pu.com/5739738739739731/Madeleine-L-Engle-Herself-Reflections-on-a-Writing-Life-by-Madeleine-L-39-Engle.pdf
    • http://cefasfese.4pu.com/3739733738730734/Point-of-No-Return-Turning-Point-1-by-N-R-Walker.pdf
    • http://cefasfese.4pu.com/5737736737739/Point-of-No-Return-Turning-Point-1-by-N-R-Walker.pdf
    • http://cefasfese.4pu.com/1730733738737737737/Egyptian-Statues-by-Gay-Robins.pdf
    • http://cefasfese.4pu.com/3735739730733738/Reprisal-by-Alfie-Robins.pdf
    • http://cefasfese.4pu.com/4733736739739735/I-Can-Face-Tomorrow-by-H-C-Robins.pdf
    • http://cefasfese.4pu.com/2736734733735738/The-Convert-by-Elizabeth-Robins.pdf
    • http://cefasfese.4pu.com/5736734735733/What-a-Girl-Wants-by-Selena-Robins.pdf
    • http://cefasfese.4pu.com/2736739734733735/What-a-Girl-Wants-by-Selena-Robins.pdf
    • http://cefasfese.4pu.com/5735735738738738/Wrecked-Under-the-Green-Point-Light-The-Background-to-the-Green-and-Mouille-Point-Lights-and-Stories-of-Six-Shipwrecks-in-the-Area-by-John-T-Dimond.pdf
    • http://cefasfese.4pu.com/6735736732/White-Bodies-by-Jane-Robins.pdf
    • http://cefasfese.4pu.com/5736734732737/The-Incomplete-Anglers-by-John-D-Robins.pdf
    • http://cefasfese.4pu.com/2731738731734735/Zero-Tolerance-by-Jonathan-Maberry.pdf
    • http://cefasfese.4pu.com/2732738731731732/The-Intolerance-of-Tolerance-by-D-A-Carson.pdf
    • http://cefasfese.4pu.com/4738734732739738/Fall-Line-Downhill-1-by-Tudor-Robins.pdf
    • http://cefasfese.4pu.com/4733736739739735/I-Can-Face-Tomorrow-by-H-C-Rob