Malicious PDF — malware analysis report

Static analysis result for SHA-256 f5a73e0f1b641fe1…

MALICIOUS

PDF

25.7 KB Created: 2019-05-03 20:21:53 +01:00 Authoring application: mPDF 5.7
MD5: 058c63d857d4713aba4922f3057fff3b SHA-1: 156131714220ad8c56780f02414d8b27a47f0486 SHA-256: f5a73e0f1b641fe1d6088ee01ae8464d399cc143db0783c433b9945f14b52582
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While many of the linked URLs were classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO spam or to distribute further malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5730736733735735/A-Christmas-Dozen-Christmas-Stories-to-Warm-the-Heart-by-Steve-Burt.pdf
    • http://cefasfese.4pu.com/3738735732735737/Chicken-Soup-for-the-Soul-The-Book-of-Christmas-Virtues-Inspirational-Stories-to-Warm-the-Heart-by-Jack-Canfield.pdf
    • http://cefasfese.4pu.com/3738734737730732/Christmas-Fireside-Stories-A-Collection-of-Heart-Warming-Christmas-Short-Stories-From-Six-Bestselling-Authors-by-Margaret-Dickinson.pdf
    • http://cefasfese.4pu.com/3738738732730/Even-Odder-More-Stories-to-Chill-the-Heart-by-Steve-Burt.pdf
    • http://cefasfese.4pu.com/3737735734734/Oddest-Yet-Even-More-Stories-to-Chill-the-Heart-by-Steve-Burt.pdf
    • http://cefasfese.4pu.com/1730738733734732735/A-Sprinkling-of-Christmas-Magic-Christmas-Cinderella-Finding-Forever-at-Christmas-The-Captain-s-Christmas-Angel-by-Elizabeth-Rolls.pdf
    • http://cefasfese.4pu.com/1738738732733733/One-Sweet-Christmas-Captain-s-Point-Stories-52-Annie-Acorn-s-Christmas-Shorts-8-by-Charlotte-Kent.pdf
    • http://cefasfese.4pu.com/8739733733735734/A-Christmas-Carol-And-Other-Christmas-Stories-by-Charles-Dickens.pdf
    • http://cefasfese.4pu.com/3739735737738739/A-Christmas-Garland-Christmas-Stories-10-by-Anne-Perry.pdf
    • http://cefasfese.4pu.com/3738734732732734/A-Christmas-Odyssey-Christmas-Stories-8-by-Anne-Perry.pdf
    • http://cefasfese.4pu.com/3738734732732737/A-Christmas-Secret-Christmas-Stories-4-by-Anne-Perry.pdf
    • http://cefasfese.4pu.com/1738739730733734/Coming-Home-for-Christmas-A-Christmas-in-Paradise-O-Christmas-Tree-No-Crib-for-a-Bed-by-Carla-Kelly.pdf
    • http://cefasfese.4pu.com/6731738730737/The-Christmas-Box-Collection-The-Christmas-Box-Timepiece-The-Letter-The-Christmas-Box-1-3-by-Richard-Paul-Evans.pdf
    • http://cefasfese.4pu.com/3737732739731737/A-Regency-Christmas-Scarlet-Ribbons-Christmas-Promise-A-Little-Christmas-by-Lyn-Stone.pdf
    • http://cefasfese.4pu.com/2739736737730733/Home-For-Christmas-Bar-V5-Dude-Ranch-1-Copper-Mountain-Christmas-2-by-Melissa-McClone.pdf
    • http://cefasfese.4pu.com/8733732732737736/Delivered-By-Christmas-Bluebird-Winter-The-Gift-Of-Joy-A-Christmas-To-Treasure-by-Linda-Howard.pdf
    • http://cefasfese.4pu.com/5738734737730732/Christmas-Holiday-Special-Selection-volume-5-Countdown-to-Christmas-sample-by-Amu-Taniguchi.pdf
    • http://cefasfese.4pu.com/5730732736730732/We-Wish-You-a-Merry-Christmas-A-Traditional-Christmas-Carol-by-Tracey-Campbell-Pearson.pdf
    • http://cefasfese.4pu.com/8736733737734739/We-Wish-You-a-Murderous-Christmas-A-Year-Round-Christmas-Mystery-2-by-Vicki-Delany.pdf
    • http://cefasfese.4pu.com/5735730738732737/A-Christmas-Carol-in-Prose-Being-a-Ghost-Story-of-Christmas-by-Charles-Dickens.pdf