Malicious PDF — malware analysis report

Static analysis result for SHA-256 e9c4a62ca2faf1d8…

MALICIOUS

PDF

16.3 KB Created: 2019-05-02 17:29:38 +01:00 Authoring application: mPDF 5.7
MD5: 1d45a15137df0853458a37690c02cb40 SHA-1: c5751ffce0c187ec4ecd8d9476cb314fc8413cc2 SHA-256: e9c4a62ca2faf1d8e799d36df74df238914002e2a5db5fcff5498089357abb2e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded URLs, forming a link farm. The primary heuristic indicates a 'PDF_SEO_LINK_FARM' with 22 external links, predominantly using numeric slugs in the URL path. While the document body text is heavily obfuscated, the presence of numerous links suggests a lure or redirection mechanism. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9734739738737736/Spider-Man-2099-Volume-5-Civil-War-II-by-Peter-David.pdf
    • http://cefasfese.4pu.com/4731732736738735/Spider-Man-2099-Volume-3-Smack-to-the-Future-by-Peter-David.pdf
    • http://cefasfese.4pu.com/1731736732734737730/Spider-Woman-Shifting-Gears-Volume-2-Civil-War-II-by-Dennis-Hopeless.pdf
    • http://cefasfese.4pu.com/3733732739731735/Spider-Man-2-by-Peter-David.pdf
    • http://cefasfese.4pu.com/4734732738735736/Spider-Man-The-Other-by-Peter-David.pdf
    • http://cefasfese.4pu.com/3733731739730737/Spider-Man-by-Peter-David.pdf
    • http://cefasfese.4pu.com/3730736733731736/X-Factor-by-Peter-David-The-Complete-Collection-Volume-2-by-Peter-David.pdf
    • http://cefasfese.4pu.com/1739733732738732/Spider-Woman-Volume-1-Spider-Verse-by-Dennis-Hopeless.pdf
    • http://cefasfese.4pu.com/1730737739733736738/She-Hulk-Volume-9-Lady-Liberators-by-Peter-David.pdf
    • http://cefasfese.4pu.com/6738734732738738/Spider-Man-Spider-Verse---Fearsome-Foes-Spider-Man-Enter-The-Spider-Verse-2018-Book-1-by-Stan-Lee.pdf
    • http://cefasfese.4pu.com/3732738732734731/The-Incredible-Hulk-Visionaries-Peter-David-Vol-4-by-Peter-David.pdf
    • http://cefasfese.4pu.com/7736733730739/The-Spider-s-Web-Sister-Fidelma-5-by-Peter-Tremayne.pdf
    • http://cefasfese.4pu.com/4734734733737733/The-Best-of-Spider-Man-Volume-1-by-J-Michael-Straczynski.pdf
    • http://cefasfese.4pu.com/4730730739735734/Peter-Parker-Spider-Man-Vol-3-Return-Of-The-Goblin-by-Paul-Jenkins.pdf
    • http://cefasfese.4pu.com/2732735736739/Big-Lizard-Hidden-Spider-And-Other-Unprincipled-Persons-that-Flustered-the-Cat-by-Peter-Gikandi.pdf
    • http://cefasfese.4pu.com/6730739733738734/Taimashin-The-Red-Spider-Exorcist-Volume-1-by-Hideyuki-Kikuchi.pdf
    • http://cefasfese.4pu.com/3733732739731731/Spider-Girl-Volume-4-Turning-Point-by-Tom-DeFalco.pdf
    • http://cefasfese.4pu.com/8738739737735734/Amazing-Spider-Man-Volume-1-The-Parker-Luck-by-Dan-Slott.pdf
    • http://cefasfese.4pu.com/3736738738736739/Spider-Man-Vs-Venom-by-David-Michelinie.pdf
    • http://cefasfese.4pu.com/3737731739737734/The-Girl-in-the-Spider-s-Web-by-David-Lagercrantz.pdf
    • http://cefasfese.4pu.com/6738734732738738/Spider-Man-Spider-Verse---Fearsome-Foes-Spider-Man-Enter-The-Spider-Verse-