Malicious PDF — malware analysis report

Static analysis result for SHA-256 f9d971b72fb13117…

MALICIOUS

PDF

22.0 KB Created: 2019-04-30 08:30:00 +01:00 Authoring application: mPDF 5.7
MD5: d7b406657e44f6d0d40c09fbe3432987 SHA-1: b012dbc3d2a46755937183ced060ff363d063c70 SHA-256: f9d971b72fb1311712ea6a5e9982faf3286bbfd7e9114de8b8e1b3893157da2e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF document was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM'. While the specific intent of these links is unclear due to the benign reputation of the initial URLs, the sheer volume and the ML classification suggest a malicious purpose, possibly for SEO abuse or to distribute further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2735735734736738/The-Battle-of-New-Market-by-William-C-Davis.pdf
    • http://cefasfese.4pu.com/1731738730733737/The-Battle-of-New-Market-A-Story-of-V-M-I-by-Paxton-Davis.pdf
    • http://cefasfese.4pu.com/2735735732733730/Battle-at-Bull-Run-A-History-of-the-First-Major-Campaign-of-the-Civil-War-by-William-C-Davis.pdf
    • http://cefasfese.4pu.com/4737738739735735/The-Grimoire-of-Kensington-Market-by-Lauren-B-Davis.pdf
    • http://cefasfese.4pu.com/2735735737730730/Valley-Thunder-The-Battle-of-New-Market-and-the-Opening-of-the-Shenandoah-Valley-Campaign-May-1864-by-Charles-R-Knight.pdf
    • http://cefasfese.4pu.com/4732739739735738/The-Final-Battle-Legion-2-by-William-C-Dietz.pdf
    • http://cefasfese.4pu.com/5734733731733735/Tactical-Management-in-the-Secular-Bear-Market-How-Tactical-Management-and-Market-Phases-Can-Help-Manage-Risk-and-Make-Money-in-the-Secular-Bear-Market-by-Tahar-Mjigal.pdf
    • http://cefasfese.4pu.com/1733737730737732/Enemy-at-the-Gates-The-Battle-for-Stalingrad-by-William-Craig.pdf
    • http://cefasfese.4pu.com/1731732736732735/Return-of-a-King-The-Battle-for-Afghanistan-by-William-Dalrymple.pdf
    • http://cefasfese.4pu.com/4736731733730/Nicholas-St-North-and-the-Battle-of-the-Nightmare-King-The-Guardians-1-by-William-Joyce.pdf
    • http://cefasfese.4pu.com/2735734736737734/Look-Away-A-History-of-the-Confederate-States-of-America-by-William-C-Davis.pdf
    • http://cefasfese.4pu.com/7733737738731733/A-Philosophy-of-Wealth-Accusation-for-Dentists-by-William-J-Davis.pdf
    • http://cefasfese.4pu.com/7733734735731733/The-Dictator-s-Learning-Curve-Inside-the-Global-Battle-for-Democracy-by-William-J-Dobson.pdf
    • http://cefasfese.4pu.com/2735735737732738/Bloody-Hill-The-Civil-War-Battle-of-Wilson-s-Creek-by-William-Riley-Brooksher.pdf
    • http://cefasfese.4pu.com/3736738731739738/Arguing-about-Slavery-The-Great-Battle-in-the-United-States-Congress-by-William-Lee-Miller.pdf
    • http://cefasfese.4pu.com/3736730734734733/Pagan-Moon-Mike-Gage-Thrillers-1-by-William-G-Davis.pdf
    • http://cefasfese.4pu.com/7731732733732/You-Can-Be-a-Stock-Market-Genius-Uncover-the-Secret-Hiding-Places-of-Stock-Market-Profits-by-Joel-Greenblatt.pdf
    • http://cefasfese.4pu.com/9737736733734/An-American-Insurrection-James-Meredith-and-the-Battle-of-Oxford-Mississippi-1962-by-William-Doyle.pdf
    • http://cefasfese.4pu.com/2735735734738730/The-Image-of-War-1861-1865-Volume-1-Shadows-of-the-Storm-by-William-C-Davis.pdf
    • http://cefasfese.4pu.com/1738735731738739/To-Market-To-Market-by-Anne-Miranda.pdf
    • http://cefasfese.4pu.com/57347337