Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef363584f2d7b7e1…

MALICIOUS

PDF

22.6 KB Created: 2019-11-09 22:18:32 +00:00 Authoring application: mPDF 5.7
MD5: b11e68f2d55cb44790c5e12166b8d81c SHA-1: e48237d420c1fdd79be6aec01f1f8757d6771efd SHA-256: ef363584f2d7b7e17832f9b05cf7d231edb355dda72552e383f11fcd1a3bddcb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these specific URLs were flagged as benign, the sheer volume and structure suggest a link farm intended to manipulate search engine results or to serve as a distribution point for malicious content. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the file. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9784

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4731738739739733/Eagle-The-Making-Of-An-Asian-American-President-Volume-1-Candidate-by-Kaiji-Kawaguchi.pdf
    • http://cefasfese.4pu.com/7731732739739734/Madan-no-Ou-to-Vanadis-Volume-4-by-Tsukasa-Kawaguchi.pdf
    • http://cefasfese.4pu.com/7731732739735734/Madan-no-Ou-to-Vanadis-Volume-3-by-Tsukasa-Kawaguchi.pdf
    • http://cefasfese.4pu.com/7731732739739739/Madan-no-Ou-to-Vanadis-Volume-6-by-Tsukasa-Kawaguchi.pdf
    • http://cefasfese.4pu.com/2739737732731736/Seduced-By-The-Candidate-The-Candidate-1-by-Beth-Klein.pdf
    • http://cefasfese.4pu.com/3737730737737731/The-Making-of-the-President-1972-by-Theodore-H-White.pdf
    • http://cefasfese.4pu.com/3736738737739731/The-Making-of-the-President-1968-by-Theodore-H-White.pdf
    • http://cefasfese.4pu.com/3730736739731735/Secret-Identities-The-Asian-American-Superhero-Anthology-by-Jeff-Yang.pdf
    • http://cefasfese.4pu.com/2736732738735737/Making-Plans-Making-Memories-Reprisal-Volume-1-by-Sam-Lang.pdf
    • http://cefasfese.4pu.com/4734732736736738/Dragon-Ladies-Asian-American-Feminists-Breathe-Fire-by-Sonia-Shah.pdf
    • http://cefasfese.4pu.com/3733736736737/Amok-Essays-from-an-Asian-American-Perspective-With-an-Introduction-by-Ishmael-Reed-by-Emil-Guillermo.pdf
    • http://cefasfese.4pu.com/4738738731730734/Charlie-Chan-is-Dead-An-Anthology-of-Contemporary-Asian-American-Fiction-by-Jessica-Hagedorn.pdf
    • http://cefasfese.4pu.com/3730731737738730/The-Case-of-Abraham-Lincoln-A-Story-of-Adultery-Murder-and-the-Making-of-a-Great-President-by-Julie-M-Fenster.pdf
    • http://cefasfese.4pu.com/1730732734732734731/The-Bald-Eagle-An-American-Symbol-by-Alison-Eldridge.pdf
    • http://cefasfese.4pu.com/6730730737732737/Small-and-Medium-Enterprises-in-Asian-Pacific-Countries-Volume-2-by-Moha-Asri-Abdullah.pdf
    • http://cefasfese.4pu.com/2737734737734737/The-Eagle-and-the-Lion-The-Tragedy-of-American-Iranian-Relations-by-James-A-Bill.pdf
    • http://cefasfese.4pu.com/4730733738732738/The-Academy-Making-of-a-Ruler-The-Eagle-King-s-Academy-1-by-C-C-Mon-.pdf
    • http://cefasfese.4pu.com/8733732738739736/The-American-President-From-Teddy-Roosevelt-to-Bill-Clinton-by-William-E-Leuchtenburg.pdf
    • http://cefasfese.4pu.com/5739736732735733/President-Trump-and-the-2nd-American-Revolution-Book-2-Raw-Milk-Uncensored-Edition-by-Joe-Nickolas-Pelech.pdf
    • http://cefasfese.4pu.com/4732736731739735/Lyndon-Johnson-and-the-American-Dream-The-Most-Revealing-Portrait-of-a-President-and-Presidential-Power-Ever-Written-by-Doris-Kearns-Goodwin.pdf
    • http://cefasfese.4pu.com/3730736739731735/Secret-Identities-The-Asian-American-Superhero-Anthology-by-