Malicious PDF — malware analysis report

Static analysis result for SHA-256 04e0782aafb8eb58…

MALICIOUS

PDF

24.3 KB Created: 2019-11-07 12:41:30 +00:00 Authoring application: mPDF 5.7
MD5: 3bacc342e7f24de6c567a817c6c80bdb SHA-1: 94070f9552936a88d0ded5b2f8d535f002b00781 SHA-256: 04e0782aafb8eb5817a7bb373cc5f1916cb335db5502aa1f414c2b6527ca67f3
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. These URLs point to various PDF documents, suggesting a tactic to manipulate search engine results or to distribute further content. The ML classifier also flagged this PDF as malicious, supporting the suspicious nature of the link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9808

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730738739730739/Boost-A-Haunted-Addiction-1-by-D-A-Paul.pdf
    • http://cefasfese.4pu.com/2739731735732739/The-Addiction-Spectrum-A-Compassionate-Holistic-Approach-to-Recovery-by-Paul-Thomas.pdf
    • http://cefasfese.4pu.com/2739731735732736/Addiction-Recovery-DIY-Do-it-Yourself---Conquer-Your-Drug-or-Alcohol-Addiction-at-Home-by-K-J-Gordon.pdf
    • http://cefasfese.4pu.com/2739731735731735/Ripped-cause-any-addiction-is-a-good-addiction-by-Gian-Andrea.pdf
    • http://cefasfese.4pu.com/1736733736731/Midnight-in-Peking-How-the-Murder-of-a-Young-Englishwoman-Haunted-the-Last-Days-of-Old-China-by-Paul-French.pdf
    • http://cefasfese.4pu.com/1732734732732730/Midnight-in-Peking-How-the-Murder-of-a-Young-Englishwoman-Haunted-the-Last-Days-of-Old-China-by-Paul-French.pdf
    • http://cefasfese.4pu.com/2732731734738739/Midnight-in-Peking-How-the-Murder-of-a-Young-Englishwoman-Haunted-the-Last-Days-of-Old-China-by-Paul-French.pdf
    • http://cefasfese.4pu.com/7736735730732736/Sugar-Addiction-How-to-Overcome-a-Sugar-Addiction-the-Natural-Way-by-Gabby-Roles.pdf
    • http://cefasfese.4pu.com/6732733738731732/INTERNET-ADDICTION-DEAL-WITH-YOUR-INTERNET-ADDICTION-REASONS-AND-SYMPTOMS-by-S-FATOU.pdf
    • http://cefasfese.4pu.com/2731736734737737/Flip-That-Haunted-House-Haunted-Renovation-Mystery-1-by-Rose-Pressey.pdf
    • http://cefasfese.4pu.com/7731737734736734/Haunted-Ohio-IV-Restless-Spirits-Haunted-Ohio-Series-by-Chris-Woodyard.pdf
    • http://cefasfese.4pu.com/1731731731735733/Sweet-Addiction-Sweet-Addiction-1-by-J-Daniels.pdf
    • http://cefasfese.4pu.com/1731735732736732734/Beyond-the-C-Standard-Library-An-Introduction-to-Boost-by-Bj-rn-Karlsson.pdf
    • http://cefasfese.4pu.com/3732730733731739/7-Day-Confidence-and-Ego-Boost-Affirmation-Plan-by-Stephen-Richards.pdf
    • http://cefasfese.4pu.com/3731730733730735/Use-It-or-Lose-It---Boost-Your-Sexual-Energy-by-Violet-Karma.pdf
    • http://cefasfese.4pu.com/1731732731731730733/Self-Confidence-How-To-Overcome-Shyness-Worry-And-Boost-Your-Self-Esteem-by-Anastasia-Verg.pdf
    • http://cefasfese.4pu.com/9732734736739732/Strong-Nine-Workout-Programs-for-Women-to-Burn-Fat-Boost-Metabolism-and-Build-Strength-for-Life-by-Lou-Schuler.pdf
    • http://cefasfese.4pu.com/1730731733735732731/Gabby-s-Haunted-House-Series-Gabby-s-Haunted-House-1-5-by-Lorrie-Bannett.pdf
    • http://cefasfese.4pu.com/2735733730737732/Fat-for-Fuel-A-Revolutionary-Diet-to-Combat-Cancer-Boost-Brain-Power-and-Increase-Your-Energy-by-Joseph-Mercola.pdf
    • http://cefasfese.4pu.com/5734731734739738/The-Bone-Broth-Miracle-How-an-Ancient-Remedy-Can-Improve-Health-Fight-Aging-and-Boost-Beauty-by-Ariane-Resnick.pdf