Malicious PDF — malware analysis report

Static analysis result for SHA-256 0553fe2210caf1ea…

MALICIOUS

PDF

15.3 KB Created: 2019-05-03 16:10:48 +01:00 Authoring application: mPDF 5.7
MD5: 6b788b92dc39843addcd6c987601b065 SHA-1: 86a9f79ffa44bff2162d93b4a54d4ffeac199bc8 SHA-256: 0553fe2210caf1ea4fef7b3b727b11e4403ea84391a7f4102027953db8037dd8
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. This heuristic, combined with the ML classifier, indicates a malicious intent to redirect users to potentially harmful content. The document body confirms the presence of these external links, suggesting a phishing or content-luring attack vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1739736732739737/Through-Glass-Episode-One-Through-Glass-1-by-Rebecca-Ethington.pdf
    • http://cefasfese.4pu.com/1731732733733738730/Kiln-Firing-Glass-Glass-Fusing-Book-One-by-Boyce-Lundstrom.pdf
    • http://cefasfese.4pu.com/1731738736736739/Maine-On-Glass-The-Early-Twentieth-Century-in-Glass-Plate-Photography-by-William-H-Bunting.pdf
    • http://cefasfese.4pu.com/1735737733739732/Glass-After-Glass-Autobiographical-Reflections-by-Barbara-Blackman.pdf
    • http://cefasfese.4pu.com/4734733738734734/Shards-of-Glass-The-Glass-Trilogy-1-by-Arianne-Richmonde.pdf
    • http://cefasfese.4pu.com/3735731739733/Storm-Glass-Glass-1-by-Maria-V-Snyder.pdf
    • http://cefasfese.4pu.com/3737732731734739/Storm-Glass-Glass-1-by-Maria-V-Snyder.pdf
    • http://cefasfese.4pu.com/1733731735734732/Into-the-Looking-Glass-Looking-Glass-1-by-John-Ringo.pdf
    • http://cefasfese.4pu.com/2731733735739736/Sea-Glass-Glass-2-by-Maria-V-Snyder.pdf
    • http://cefasfese.4pu.com/1737739739734736/The-Looking-Glass-The-Looking-Glass-1-by-Jessica-Arnold.pdf
    • http://cefasfese.4pu.com/4737732730734733/Sea-Glass-Glass-2-by-Maria-V-Snyder.pdf
    • http://cefasfese.4pu.com/1736739731735736/Scorched-Treachery-Imdalind-3-by-Rebecca-Ethington.pdf
    • http://cefasfese.4pu.com/4738734735733731/Kiss-of-Fire-Imdalind-1-by-Rebecca-Ethington.pdf
    • http://cefasfese.4pu.com/1731736734735732/Eyes-of-Ember-Imdalind-2-by-Rebecca-Ethington.pdf
    • http://cefasfese.4pu.com/1732739738734739/The-Glass-Swallow-Dragonfly-amp-The-Glass-Swallow-2-by-Julia-Golding.pdf
    • http://cefasfese.4pu.com/4735738731731/The-Glass-Swallow-Dragonfly-amp-The-Glass-Swallow-2-by-Julia-Golding.pdf
    • http://cefasfese.4pu.com/1735736734737737/The-Glass-Apple-The-Glass-Apple-1-by-Robert-J-Franks.pdf
    • http://cefasfese.4pu.com/4732737734738737/The-Looking-Glass-Wars-The-Looking-Glass-Wars-1-by-Frank-Beddor.pdf
    • http://cefasfese.4pu.com/1732732732731735/Girl-of-Glass-Girl-of-Glass-1-by-Megan-O-39-Russell.pdf
    • http://cefasfese.4pu.com/7731738734735/Throne-of-Glass-Throne-of-Glass-1-by-Sarah-J-Maas.pdf