Malicious PDF — malware analysis report

Static analysis result for SHA-256 e80105dc5a16036d…

MALICIOUS

PDF

20.9 KB Created: 2019-05-02 06:06:27 +01:00 Authoring application: mPDF 5.7
MD5: a6bbb326d809a4940d1b73959109336f SHA-1: 0c0bcb15704a518000166b8f1f9068b51d73a492 SHA-256: e80105dc5a16036d5c719f721256057dcaf982f0aefe0a1556bf50a4f90e96eb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of external links, indicating a link farm. The primary purpose appears to be directing users to a multitude of other PDF documents hosted externally. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5734732733739732/Asterix-On-Top-Asterix-The-Gaul-Asterix-And-The-Golden-Sickle-Asterix-And-The-Banquet-Asterix-And-The-Normans-Asterix-And-The-Roman-Agent-Asterix-And-Caesar-s-Gift-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/3733736733738738/Asterix-and-the-Roman-Agent-Ast-rix-15-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/6739739739733734/Fiction-Set-in-Roman-Gaul-Asterix-Novels-Set-in-Roman-Gaul-Rene-Goscinny-Albert-Uderzo-Obelix-List-of-Asterix-Characters-Humour-in-Asterix-by-Source-Wikipedia.pdf
    • http://cefasfese.4pu.com/7730730731732731/Asterix-the-Gaul-Series-6-Collection-5-Books-Set-26-30-Asterix-and-the-Black-Gold-Asterix-and-Son-Asterix-and-the-Magic-Carpet-Asterix-and-the-Secret-Weapon-Asterix-and-Obelix-All-at-Sea-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/3738732735734731/Asterix-and-the-Great-Crossing-Asterix-22-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/5734732734738739/Asterix-the-Champion-quot-Asterix-the-Gaul-quot-quot-Asterix-in-Spain-quot-quot-Asterix-in-Britain-quot-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/9731734737733734/Asterix-02-Asterix-und-Kleopatra-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/3738732735733736/Asterix-and-the-Soothsayer-Asterix-19-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/4739736734730734/Asterix-in-Spain-Asterix-14-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/2733737733732734/Asterix-and-the-Cauldron-Asterix-13-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/8737734737739/Asterix-in-Belgium-Asterix-24-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/7731733737733733/Ast-rix---Ast-rix-le-Gaulois---n-1-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/4738731733737/Asterix-the-Gaul-Asterix-1-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/8732731738734/Asterix-and-Cleopatra-Asterix-6-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/9731734735734731/Asterix-01-Asterix-der-Gallier-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/9731734737734734/Asterix-08-Asterix-bei-den-Briten-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/2733735738738735/Asterix-the-Gladiator-Asterix-4-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/5734732734732733/Asterix-Omnibus-7-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/3736736734732734/Asterix-the-Gladiator-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/2733739735738735/Obelix-and-Co-Asterix-23-by-Ren-Goscinny.pdf
    • http://cefasfese.4pu.com/7730730731732731/Asterix-the-Gaul-Series-6-Collection-5-Books-Set-26-30-Asterix-and-the-Black-Gold-