Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6915866c0feb1c1…

MALICIOUS

PDF

15.4 KB Created: 2019-05-02 05:22:55 +01:00 Authoring application: mPDF 5.7
MD5: 9bae89555424690bc5958a607ca7abff SHA-1: ba386fa3c323833cba9eba90d0f436b27f5a2892 SHA-256: f6915866c0feb1c154b8a237939cd137ec4c241c1d3cb8bc1cd65c28cb2b468e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious. While the document body is heavily obfuscated, the presence of numerous links suggests a link farm or SEO poisoning attempt to drive traffic to potentially malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7735730733738730/My-Life-with-John-Steinbeck-The-Story-of-John-Steinbeck-s-Forgotten-Wife-by-Gwyn-Conger-Steinbeck.pdf
    • http://cefasfese.4pu.com/7735730733733731/The-Other-Side-of-Eden-Life-With-John-Steinbeck-by-John-Steinbeck-IV.pdf
    • http://cefasfese.4pu.com/7735730733738736/The-Essential-Steinbeck-Four-Complete-Novels-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/7731736733735737/Of-Mice-and-Men-Steinbeck-Tribute-Edition-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/4732731737731733/The-Steinbeck-Centennial-Collection-The-Grapes-of-Wrath-Of-Mice-and-Men-East-of-Eden-The-Pearl-Cannery-Row-Travels-With-Charley-in-Search-of-America-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/1739730734739733/The-Log-from-the-Sea-of-Cortez-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/5736733739737/Omnibus-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/3734733732734/To-a-God-Unknown-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/4730734736731736/Of-Mice-and-Men-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/6738736735736734/The-Pearl-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/8733735734734738/La-perle-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/2736732736738738/The-Wayward-Bus-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/6732734733739734/-st-for-Paradis-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/5733730739732739/Of-Mice-and-Men-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/4730730737730/The-Moon-Is-Down-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/5739734734733737/Of-Mice-and-Men-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/4734733730732736/The-Pearl-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/7735730733733732/The-Gift-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/5739738732734737/Of-Mice-and-Men-by-John-Steinbeck.pdf
    • http://cefasfese.4pu.com/5738736730731737/The-Pearl-by-John-Steinbeck.pdf