Malicious PDF — malware analysis report

Static analysis result for SHA-256 e0fdf05be7e7932a…

MALICIOUS

PDF

27.9 KB Created: 2019-05-03 16:07:38 +01:00 Authoring application: mPDF 5.7
MD5: ddbad37f48550094d21cbf9e0292ba72 SHA-1: c8b1d4b668bd6c86cfeb115eb0470b98f2056f66 SHA-256: e0fdf05be7e7932a973bfcc8cf1097ec857623f369f1919d484aaecca0c5be12
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which point to external PDF files. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the sheer volume of links suggests a potential attempt to direct users to malicious content or to manipulate search engine results.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4732730731738732/The-Complete-Works-of-Jane-Austen-All-Novels-Short-Stories-Unfinished-Works-Juvenilia-Letters-Poems-Prayers-Memoirs-and-Biographies---Fully-Illustrated-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/3732737739730730/Jane-Austen-Complete-Novels-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/3736730738734736/Jane-Austen-Her-Complete-Novels-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/1731737736739733731/The-Complete-Works-of-Jane-Austen-In-One-Volume-Sense-and-Sensibility-Pride-and-Prejudice-Mansfield-Park-Emma-Northanger-Abbey-Persuasion-Lady-Sandition-and-the-Complete-Juvenilia-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/1731737736739738737/Jane-Austen-Collection-Emma-Mansfield-Park-Northanger-Abbey-Biography-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/6734739732733738/Emma-by-Jane-Austen-a-Novel-about-Youthful-Hubris-and-the-Perils-of-Misconstrued-Romance-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/8736733730734734/Die-Jane-Austen-Collection-Gesamtausgabe-Stolz-und-Vorurteil-Verstand-und-Gef-hl-Emma-berredung-Mansfield-Park-Die-Abtei-von-Northanger-IDP-Classics-German-Edition-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/8736734739733/Confessions-of-a-Jane-Austen-Addict-Jane-Austen-Addict-1-by-Laurie-Viera-Rigler.pdf
    • http://cefasfese.4pu.com/1731737737730739736/NORTHANGER-ABBEY-By-Jane-Austen-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/8730733738730735/Mansfield-Park-by-Jane-Austen-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/1731731739738736732/Northanger-Abbey-by-Jane-Austen-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/3738739735731732/The-Three-Colonels-Jane-Austen-s-Fighting-Men-Jane-Austen-s-Fighting-Men-1-by-Jack-Caldwell.pdf
    • http://cefasfese.4pu.com/1730739735738738738/Strandlekt-re-Mein-Austen-Bront-Lesebuch-Die-besten-Werke-in-einem-Band-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/2735732738731732/Dinner-with-Mr-Darcy-Recipes-inspired-by-the-novels-of-Jane-Austen-by-Pen-Vogler.pdf
    • http://cefasfese.4pu.com/4737739731731731/Old-Friends-And-New-Fancies-An-Imaginary-Sequel-To-The-Novels-Of-Jane-Austen-by-Sybil-G-Brinton.pdf
    • http://cefasfese.4pu.com/7731734730737735/Mansfield-Park-Complete-amp-Unabridged-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/5734733732736739/Persuasion-by-Jane-Austen-1818-Original-Version-Persuasion-by-Jane-Austen-1818-Original-Version-Volume-1-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/3738739734733733/A-Jane-Austen-Education-How-Six-Novels-Taught-Me-About-Love-Friendship-and-the-Things-That-Really-Matter-by-William-Deresiewicz.pdf
    • http://cefasfese.4pu.com/2736734732737739/Jane-Austen-s-Letters-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/2736734738735732/Jane-and-the-Unpleasantness-at-Scargrave-Manor-Jane-Austen-Mysteries-1-by-Stephanie-Barron.pdf
    • http://cefasfese.4pu.com/1731737736739733731/The-Complete-Works-of-Jane-Austen-In-One-Volume-Sense-and-Sensibility-Pride-and-Prejudice-Mansfield-Park-Emma-Northanger-Abbey-Persuasion-Lady-Sa