Malicious PDF — malware analysis report

Static analysis result for SHA-256 07b17d3a86f3f250…

MALICIOUS

PDF

23.9 KB Created: 2019-05-01 18:54:13 +01:00 Authoring application: mPDF 5.7
MD5: 127ee909b6fa8f465110adfd5dc472cf SHA-1: 12c2ee9a6e87535ea6ec8ce408d2af5ac0bdffa8 SHA-256: 07b17d3a86f3f25098c63898b7cf10d624122315ac6895254652b36d8264e104
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles, but the sheer volume and the nature of the heuristic suggest a link farm or SEO manipulation tactic. The ML classifier also flagged the document as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3738736730730730/The-Rabbit-s-Adventure-by-Betty-Ren-Wright.pdf
    • http://cefasfese.4pu.com/3731732739730739/Children-s-Learning-Adventure-Bundle-with-15-stories-Beginner-readers-Adventure-Animal-stories-Teach-Values-Book-Funny-free-story-prime-Rhymes-Fantasy-Education-by-Betty-J-Byers.pdf
    • http://cefasfese.4pu.com/1734738733735731/The-Ghosts-of-Mercy-Manor-by-Betty-Ren-Wright.pdf
    • http://cefasfese.4pu.com/3736736733733736/Ghosts-Beneath-Our-Feet-by-Betty-Ren-Wright.pdf
    • http://cefasfese.4pu.com/3735733738735730/Rabbit-Novels-Rabbit-Run-and-Rabbit-Redux-by-John-Updike.pdf
    • http://cefasfese.4pu.com/2739735734731734/The-Odyssey-of-the-Dragolitha-A-Fantasy-Adventure-by-Caleb-Wright.pdf
    • http://cefasfese.4pu.com/3735737738738732/The-Key-to-the-Ranch-An-Alexander-Wright-Mystery-Adventure-6-by-William-L-Mansfield.pdf
    • http://cefasfese.4pu.com/3736730730735733/Terror-on-the-Northern-Ridge-An-Alexander-Wright-Mystery-Adventure-Book-8-by-William-Mansfield.pdf
    • http://cefasfese.4pu.com/4738737736738730/Snow-Rabbit-Spring-Rabbit-A-Book-of-Changing-Seasons-by-Il-Sung-Na.pdf
    • http://cefasfese.4pu.com/9733732731732736/Rabbit-in-Red-Volume-1-Follow-the-Rabbit-by-Joe-Chianakas.pdf
    • http://cefasfese.4pu.com/3731733735733732/Early-Reading-Challenge-9-15-Books-in-1-Bedtime-story-Beginner-readers-Adventure-Animal-stories-Teach-Values-Book-Funny-free-story-prime-Rhymes-Fantasy-by-Betty-J-Byers.pdf
    • http://cefasfese.4pu.com/3731733734737739/Early-Reading-Challenge-6-15-Books-in-1-Bedtime-story-Beginner-readers-Adventure-Animal-stories-Teach-Values-Book-free-story-prime-Rhymes-Fantasy-Education-by-Betty-J-Byers.pdf
    • http://cefasfese.4pu.com/3731733733731734/Early-Reading-Challenge-10-Bundle-with-15-stories-Beginner-readers-Adventure-Animal-stories-Teach-Values-Book-Funny-free-story-prime-Rhymes-Fantasy-Education-by-Betty-J-Byers.pdf
    • http://cefasfese.4pu.com/3731732737733732/Awesome-Adventure-Stories-for-Boys-19-Adventurous-Stories-for-Boys-by-Betty-J-Byers.pdf
    • http://cefasfese.4pu.com/1730735732733736737/Betty-and-the-Beast-Betty-and-Veronica-265-by-Dan-Parent.pdf
    • http://cefasfese.4pu.com/4736732738739736/Who-P-P-P-Plugged-Roger-Rabbit-Roger-Rabbit-2-by-Gary-K-Wolf.pdf
    • http://cefasfese.4pu.com/3730733731738730/Who-Censored-Roger-Rabbit-Roger-Rabbit-1-by-Gary-K-Wolf.pdf
    • http://cefasfese.4pu.com/5733732735735737/Who-Wacked-Roger-Rabbit-Roger-Rabbit-3-by-Gary-K-Wolf.pdf
    • http://cefasfese.4pu.com/3730738735735739/Betty-Crocker-Easy-Everyday-Vegetarian-Meatless-Main-Dishes-You-ll-Love-by-Betty-Crocker.pdf
    • http://cefasfese.4pu.com/9734737735/Wright-Brothers-Wrong-Story-How-Wilbur-Wright-Solved-the-Problem-of-Manned-Flight-by-William-Hazelgrove.pdf