Malicious PDF — malware analysis report

Static analysis result for SHA-256 087742b7d6e25284…

MALICIOUS

PDF

17.3 KB Created: 2019-05-02 07:43:31 +01:00 Authoring application: mPDF 5.7
MD5: 844bfe7a38d71ac0339e50011d934d9c SHA-1: 2a185e6dc250e59badc1f7c180538a7953b2638c SHA-256: 087742b7d6e2528462a80361c42974100b69155b39003df2b0d1a147fbeb24fd
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document was flagged by a machine learning classifier and contains a large number of embedded external links, indicative of a link farm or SEO spam campaign. The primary heuristic identified a link farm with 23 external PDF links, many of which point to book titles. While the URLs themselves are marked as benign, the sheer volume and structure suggest a malicious intent to manipulate search engine results or distribute unwanted content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8734730731739734/Mortals-and-Magic-The-Arcadia-Falls-Chronicles-8-by-Jennifer-Malone-Wright.pdf
    • http://cefasfese.4pu.com/1732736730739736/Vampire-Apocalypse-The-Arcadia-Falls-Chronicles-3-by-Jennifer-Malone-Wright.pdf
    • http://cefasfese.4pu.com/2737736732731732/Damnation-by-Janice-Lee.pdf
    • http://cefasfese.4pu.com/2739732731739/Damnation-Road-by-Max-McCoy.pdf
    • http://cefasfese.4pu.com/3735739732734737/Damnation-Theirs-Not-to-Reason-Why-5-by-Jean-Johnson.pdf
    • http://cefasfese.4pu.com/2732737734733733/Damnation-Alley-by-Roger-Zelazny.pdf
    • http://cefasfese.4pu.com/6737739734732/Obsession-Falls-Virtue-Falls-2-by-Christina-Dodd.pdf
    • http://cefasfese.4pu.com/1732739732734739/The-Harbingers-The-damnation-Chronicles-4-by-Joseph-Sweet.pdf
    • http://cefasfese.4pu.com/3734737735733730/The-Flesh-Cartel-Season-1-Damnation-by-Rachel-Haimowitz.pdf
    • http://cefasfese.4pu.com/4731733735732733/Anthology-of-Ichor-III-Gears-of-Damnation-by-Trevor-E-Donaldson.pdf
    • http://cefasfese.4pu.com/9739739731735737/Damnation-Street-Weiss-amp-Bishop-3-by-Andrew-Klavan.pdf
    • http://cefasfese.4pu.com/9734737735/Wright-Brothers-Wrong-Story-How-Wilbur-Wright-Solved-the-Problem-of-Manned-Flight-by-William-Hazelgrove.pdf
    • http://cefasfese.4pu.com/2734732735733737/The-Wright-One-Wright-Love-Duet-2-by-K-A-Linde.pdf
    • http://cefasfese.4pu.com/4731738731732738/A-Firefighter-s-Christmas-Gift-Holidays-in-Heart-Falls-1-Heart-Falls-3-by-Vivian-Arend.pdf
    • http://cefasfese.4pu.com/7732732730731734/Droga-do-Lake-Falls-Szepty-w-ciemno-ciach-Lake-Falls-3-by-Artur-K-Dormann.pdf
    • http://cefasfese.4pu.com/7738737735737735/Christmas-in-Icicle-Falls-Life-in-Icicle-Falls-11-by-Sheila-Roberts.pdf
    • http://cefasfese.4pu.com/9737739737738732/The-Two-Edwards-How-King-Edward-VII-and-Foreign-Secretary-Sir-Edward-Grey-Fomented-the-First-World-War-by-Peter-Hof.pdf
    • http://cefasfese.4pu.com/1737736734736736/Harbour-Falls-A-Harbour-Falls-Mystery-1-by-S-R-Grey.pdf
    • http://cefasfese.4pu.com/4736737733736734/Mystery-Falls-Mystery-Falls-1-by-Marilyn-Phillips.pdf
    • http://cefasfese.4pu.com/2734735733736736/Darkness-Falls-Darkness-Falls-1-by-Jessica-Sorensen.pdf