Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8a94eb4aceec0b6…

MALICIOUS

PDF

17.2 KB Created: 2020-01-02 06:03:20 +00:00 Authoring application: mPDF 5.7
MD5: 2d41883486c06a5a5280654145364b13 SHA-1: bbd23a2fcad8a39c539bdf8f8677d712cc2f466f SHA-256: e8a94eb4aceec0b6894c6f0717057ce26f77d77f8c194cb4931d7cecdb21720c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, directing users to various external websites. The ML_NYX_PDF_MALICIOUS classifier also flagged this document with high confidence. The embedded links are likely intended to lead users to malicious content or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3730730733739734/My-Fair-Highlander-English-Tudor-2-by-Mary-Wine.pdf
    • http://cefasfese.4pu.com/2733735738735735/To-Conquer-a-Highlander-Highlander-1-by-Mary-Wine.pdf
    • http://cefasfese.4pu.com/3733738739736737/Mary-Tudor-The-Spanish-Tudor-by-H-F-M-Prescott.pdf
    • http://cefasfese.4pu.com/3738738738731733/Evolution-s-Embers-by-Mary-Wine.pdf
    • http://cefasfese.4pu.com/2732737732738731/In-The-Warrior-s-Bed-McJames-2-by-Mary-Wine.pdf
    • http://cefasfese.4pu.com/2732737733733735/In-Bed-With-A-Stranger-McJames-1-by-Mary-Wine.pdf
    • http://cefasfese.4pu.com/4734735737733734/Dream-Shadow-by-Mary-Wine.pdf
    • http://cefasfese.4pu.com/4732735731733735/Mary-Tudor-England-s-First-Queen-by-Anna-Whitelock.pdf
    • http://cefasfese.4pu.com/3739737736735733/Bedding-the-Enemy-McJames-3-by-Mary-Wine.pdf
    • http://cefasfese.4pu.com/3730730733739730/The-Trouble-With-Highlanders-The-Sutherlands-2-by-Mary-Wine.pdf
    • http://cefasfese.4pu.com/1735732734734737/Mary-Tudor-Princess-Bastard-Queen-by-Anna-Whitelock.pdf
    • http://cefasfese.4pu.com/2739731735738736/A-Lady-Can-Never-Be-Too-Curious-Steam-Guardians-1-by-Mary-Wine.pdf
    • http://cefasfese.4pu.com/1733738735736/Bartholomew-Fair-by-Mary-Stolz.pdf
    • http://cefasfese.4pu.com/3733739739730739/Reforming-Catholicism-in-the-England-of-Mary-Tudor-The-Achievement-of-Friar-Bartolom-Carranza-by-John-Edwards.pdf
    • http://cefasfese.4pu.com/2737734732730732/The-Sisters-Who-Would-Be-Queen-Mary-Katherine-and-Lady-Jane-Grey-A-Tudor-Tragedy-by-Leanda-de-Lisle.pdf
    • http://cefasfese.4pu.com/1733734738738730/Mary-Queen-Of-Scots-The-Fair-Devil-Of-Scotland-by-Jean-Plaidy.pdf
    • http://cefasfese.4pu.com/1735732731733735/The-Last-Tudor-The-Plantagenet-and-Tudor-Novels-14-by-Philippa-Gregory.pdf
    • http://cefasfese.4pu.com/1731734736733735737/Sips-The-Unsnooty-Book-of-Wine-The-Easy-Way-To-Be-Wine-Savvy-One-Sip-At-A-Time-by-Kenneth-Ohr.pdf
    • http://cefasfese.4pu.com/1731732738738736739/World-Wine-Challenge-The-Ultimate-Game-of-Wine-Knowledge-by-Barry-Wiss.pdf
    • http://cefasfese.4pu.com/6736730731732731/Wine-Lessons-Ten-Questions-to-Guide-Your-Appreciation-of-Wine-by-Clara-Orban.pdf