Malicious PDF — malware analysis report

Static analysis result for SHA-256 ed8e9ec086f4135c…

MALICIOUS

PDF

20.6 KB Created: 2019-06-13 16:06:37 +01:00 Authoring application: mPDF 5.7
MD5: c351aeb9632dffd1d752e38464481fd5 SHA-1: 2af628a5970e20dc9ce0ab84a5a09a87cfbeca52 SHA-256: ed8e9ec086f4135c994934cc8eab7e5c167ea28a23b724b43e3f433749533455
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently classified as benign, the sheer volume and the heuristic firing of PDF_SEO_LINK_FARM suggest a malicious intent, likely for SEO manipulation or to redirect users to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6733739739732736/Beat-Generation-Glory-Days-in-Greenwich-Village-by-Fred-W-McDarrah.pdf
    • http://cefasfese.4pu.com/6733738736732732/Kerouac-and-Friends-A-Beat-Generation-Album-by-Fred-W-McDarrah.pdf
    • http://cefasfese.4pu.com/6733739739732738/Greenwich-Village-And-How-It-Got-That-Way-by-Terry-Miller.pdf
    • http://cefasfese.4pu.com/6733739739733735/Millay-In-Greenwich-Village-by-A-Cheney.pdf
    • http://cefasfese.4pu.com/6733739739733737/Love-in-Greenwich-Village-by-Floyd-Dell.pdf
    • http://cefasfese.4pu.com/6733739739736734/Greenwich-Village-Vignettes-by-Alfred-Canecchia.pdf
    • http://cefasfese.4pu.com/6733739738739733/Greenwich-Village-Stories-A-Collection-of-Memories-by-Judith-Stonehill.pdf
    • http://cefasfese.4pu.com/4732733732732736/Kafka-Was-the-Rage-A-Greenwich-Village-Memoir-by-Anatole-Broyard.pdf
    • http://cefasfese.4pu.com/1736731738735735/A-Freewheelin-Time-Greenwich-Village-in-the-Sixties-Bob-Dylan-and-Me-by-Suze-Rotolo.pdf
    • http://cefasfese.4pu.com/1739738735732/Masked-Culture-The-Greenwich-Village-Halloween-Parade-by-Jack-Kuglemass.pdf
    • http://cefasfese.4pu.com/6733739739737738/Greenwich-Village-A-Guide-to-America-s-Legendary-Left-Bank-by-Judith-Stonehill.pdf
    • http://cefasfese.4pu.com/6733739739736739/Limelight-A-Greenwich-Village-Photography-Gallery-and-Coffeehouse-in-the-Fifties-a-Memoir-by-Helen-Gee.pdf
    • http://cefasfese.4pu.com/6734730730732734/Greenwich-Village-1963-Avant-Garde-Performance-and-the-Effervescent-Body-by-Sally-Banes.pdf
    • http://cefasfese.4pu.com/3736738735739733/The-Confessions-and-Diaries-of-a-New-York-Veteran-of-the-Greenwich-Village-Stonewall-Inn-Raid-of-June-28-1969-Souvenirs-by-Scott-G-Brown.pdf
    • http://cefasfese.4pu.com/6733738735737731/Beat-Generation-by-Jack-Kerouac.pdf
    • http://cefasfese.4pu.com/8735739738735737/On-the-Road-The-Classic-Novel-of-the-Beat-Generation-by-Jack-Kerouac.pdf
    • http://cefasfese.4pu.com/1731732730731735734/Warten-Auf-Kerouac-Ein-Leben-In-Der-Beat-Generation-by-Joyce-Johnson.pdf
    • http://cefasfese.4pu.com/1735733731734733/My-Red-Blood-A-Memoir-of-Growing-Up-Communist-Coming-Onto-the-Greenwich-Village-Folk-Scene-and-Coming-Out-in-the-Feminist-Movement-by-Alix-Dobkin.pdf
    • http://cefasfese.4pu.com/1730731735733739731/The-Beats-From-Kerouac-to-Kesey-an-Illustrated-Journey-through-the-Beat-Generation-by-Mike-Evans.pdf
    • http://cefasfese.4pu.com/1736737733736738/The-Last-Generation-How-Nature-Will-Take-Her-Revenge-for-Climate-Change-by-Fred-Pearce.pdf
    • http://cefasfese.4pu.com/1739738735732/Masked-Culture-The-Greenwich-Village-Halloween-Parade-by-Jack