Malicious PDF — malware analysis report

Static analysis result for SHA-256 0047afe9bbb4e680…

MALICIOUS

PDF

22.0 KB Created: 2019-06-04 19:26:13 +01:00 Authoring application: mPDF 5.7
MD5: fd97b2ff8dfe1b879bf8664639c2bcd0 SHA-1: 06331bfae65776f0f795987a178631dd4d422d5d SHA-256: 0047afe9bbb4e6807a1350b15ed07657ae1d3d6cacc82ce21138c4286a27d6f0
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2737731737739732/Doctor-Who-Ten-Little-Aliens-by-Stephen-Cole.pdf
    • http://cefasfese.4pu.com/3730737737739731/Doctor-Who-Timeless-by-Stephen-Cole.pdf
    • http://cefasfese.4pu.com/3732737736739735/Doctor-Who-Short-Trips-and-Side-Steps-by-Stephen-Cole.pdf
    • http://cefasfese.4pu.com/3737735736734731/Doctor-How-and-the-Illegal-Aliens-Doctor-How-1-by-Mark-Speed.pdf
    • http://cefasfese.4pu.com/4734737732734738/If-the-Universe-Is-Teeming-with-Aliens-Where-Is-Everybody-Fifty-Solutions-to-the-Fermi-Paradox-and-the-Problem-of-Extraterrestrial-Life-by-Stephen-Webb.pdf
    • http://cefasfese.4pu.com/9735739735/Doctor-Sleep-The-Shining-2-by-Stephen-King.pdf
    • http://cefasfese.4pu.com/1731732739738734734/Rush-Revolution-Madness-and-the-Visionary-Doctor-Who-Became-a-Founding-Father-by-Stephen-Fried.pdf
    • http://cefasfese.4pu.com/1732736736738731/Aliens-vs-Predator-Prey-Aliens-Vs-Predator-1-by-Steve-Perry.pdf
    • http://cefasfese.4pu.com/2739734737731730/Doctor-Who-The-Road-to-the-Thirteenth-Doctor-2-The-Eleventh-Doctor-by-James-Peaty.pdf
    • http://cefasfese.4pu.com/2731731731733738/Doctor-Who-Timeframe-The-Illustrated-History-Doctor-Who-30th-Anniversary-by-David-J-Howe.pdf
    • http://cefasfese.4pu.com/4730737735732/Curing-Doctor-Vincent-The-Good-Doctor-Trilogy-1-by-Renea-Mason.pdf
    • http://cefasfese.4pu.com/2733737736730738/Becoming-a-Doctor-From-Student-to-Specialist-Doctor-Writers-Share-Their-Experiences-by-Lee-Gutkind.pdf
    • http://cefasfese.4pu.com/7737735731731732/Doctor-Doctor-A-True-Story-of-Obsession-Addiction-and-Psychological-Manipulation-by-Merry-Freer.pdf
    • http://cefasfese.4pu.com/7738739730734738/Doctor-at-Sea-First-Time-Backdoor-Medical-Fetish-Story-The-Doctor-s-Travels-Book-3-by-Liv-Jonasson.pdf
    • http://cefasfese.4pu.com/1730737730731739734/Who-is-the-Doctor-The-Unofficial-Guide-to-Doctor-Who-The-New-Series-by-Graeme-Burk.pdf
    • http://cefasfese.4pu.com/1734737734737735/Doctor-Who-The-Eleventh-Doctor-The-Sapling-Vol-2-Roots-by-Simon-Spurrier.pdf
    • http://cefasfese.4pu.com/2730738731738733/Doctor-Who-Hunters-of-Earth-Destiny-of-the-Doctor-1-by-Nigel-Robinson.pdf
    • http://cefasfese.4pu.com/1735733730734733/Doctor-How-and-the-Kennedy-Assassination-Conspiracy-Doctor-How-0-1-by-Mark-Speed.pdf
    • http://cefasfese.4pu.com/1734736735735734/Doctor-Who-The-Tenth-Doctor-Complete-Year-One-by-Nick-Abadzis.pdf
    • http://cefasfese.4pu.com/7738739730734733/Kelly-and-the-Doctor-s-Visit-A-Backdoor-MfM-Menage-Medical-Fetish-Erotic-Story-The-Doctor-s-Travels-Book-2-by-Liv-Jonasson.pdf