Malicious PDF — malware analysis report

Static analysis result for SHA-256 e968f7d00dc560fa…

MALICIOUS

PDF

18.4 KB Created: 2019-05-02 17:49:40 +01:00 Authoring application: mPDF 5.7
MD5: af643830fdd81cba8d0dc368a31a26d4 SHA-1: 61277a876aba87bf4362c101fc89957c0dc419df SHA-256: e968f7d00dc560fabc7132b3f0925ebf3315adfd69a4e4bb9e2b14fa32f8ef4a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF was flagged by an ML classifier as malicious and contains a large number of embedded URLs. The heuristic 'PDF_SEO_LINK_FARM' indicates that the PDF is designed to host a mass of external links, with 22 of them using numeric slugs. While the extracted URLs themselves are currently classified as benign, the sheer volume and structure suggest a malicious intent, likely to manipulate search engine results or redirect users to harmful content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730734739734739736/Expositon-Of-Isaiah-Volume-2-Only-Chapters-40-66-by-Herbert-C-Leupold.pdf
    • http://cefasfese.4pu.com/1730734739734739737/Exposition-of-Psalms-by-Herbert-C-Leupold.pdf
    • http://cefasfese.4pu.com/1730734739734734739/Exposition-of-Daniel-by-Herbert-C-Leupold.pdf
    • http://cefasfese.4pu.com/1730733737739735737/The-Crooked-Timber-of-Humanity-Chapters-in-the-History-of-Ideas-by-Isaiah-Berlin.pdf
    • http://cefasfese.4pu.com/6732737734738731/The-Crooked-Timber-of-Humanity-Chapters-in-the-History-of-Ideas-by-Isaiah-Berlin.pdf
    • http://cefasfese.4pu.com/6737735732731731/Isaiah-Jeremiah-Lamentations-Ezekiel-Volume-6-by-Geoffrey-W-Grogan.pdf
    • http://cefasfese.4pu.com/3738735732737731/First-5-Chapters---Volume-3-by-S-M-Hineline.pdf
    • http://cefasfese.4pu.com/2734733730739737/First-5-Chapters-Volume-1-by-Patti-Roberts.pdf
    • http://cefasfese.4pu.com/8739730737738739/Chemistry-and-Chemical-Reactivity-Volume-1-with-Chapters-13-amp-14-by-John-C-Kotz.pdf
    • http://cefasfese.4pu.com/1730734739734734738/Memori-dari-Kalimantan-1921---1927-Dokumentasi-Foto-oleh-Ahli-Geologi-Swiss-Wolfgang-Leupold-Memories-from-Borneo-1921---1927-Photographs-by-the-Swiss-Geologist-Wolfgang-Leupold-by-Paola-von-Wyss-Giacosa.pdf
    • http://cefasfese.4pu.com/7731734733730/Lucid-Exposition-of-the-Middle-Way-The-Essential-Chapters-From-The-Prasannapada-of-Candrakirti-Volume-18-by-Mervyn-Sprung.pdf
    • http://cefasfese.4pu.com/5733732736735734/Mining-For-Treasure-Herbert-s-Family-Vacation-Herbert-Books-Book-2-by-Carol-Eyster.pdf
    • http://cefasfese.4pu.com/1730734739734739730/Destillate-by-Dagmar-Leupold.pdf
    • http://cefasfese.4pu.com/1730734739734733737/Exposition-Of-Genesis-by-H-C-Leupold.pdf
    • http://cefasfese.4pu.com/2737737735739734/Isaiah-s-Haven-Legacy-2-by-N-J-Walters.pdf
    • http://cefasfese.4pu.com/6732737734738730/The-Roots-of-Romanticism-by-Isaiah-Berlin.pdf
    • http://cefasfese.4pu.com/2739733733737734/The-Troubles-of-Johnny-Cannon-by-Isaiah-Campbell.pdf
    • http://cefasfese.4pu.com/1731736733731736734/Letters-1928-1946-by-Isaiah-Berlin.pdf
    • http://cefasfese.4pu.com/4739737735733736/The-Struggles-of-Johnny-Cannon-by-Isaiah-Campbell.pdf
    • http://cefasfese.4pu.com/1730735736739739736/Herzl-s-Political-Activity-by-Isaiah-Friedman.pdf
    • http://cefasfese.4pu.com/1730734739734734738/Memori-dari-Kalimantan-1921---1927-Dokumentasi-Foto-oleh-Ahli-Geologi-Swiss-Wolfgang-Leupold-Memories-from-Borneo-1921---1927-Photographs-by-the-Swiss-Geologist-Wolfgang-Leupold-by-Paola-von-Wyss-Giaco