Malicious PDF — malware analysis report

Static analysis result for SHA-256 08ba27ed28fc2f34…

MALICIOUS

PDF

20.3 KB Created: 2019-11-07 16:07:14 +00:00 Authoring application: mPDF 5.7
MD5: af2e8d37effd926db21939c436f8978a SHA-1: e1b46d85a1777a22306de0fa6887456ce1b4b0d9 SHA-256: 08ba27ed28fc2f3478748103f9bf557c508a86bb63479d62410958e451d8518b
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which point to other PDF documents. While the document body is heavily obfuscated, the presence of numerous external links suggests a malicious intent to redirect users to potentially harmful content or engage in SEO spam. The ML_NYX_PDF_MALICIOUS heuristic further supports the classification of this file as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9805

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3733731736731736/Weird-Texas-Your-travel-guide-to-Texas-s-Local-Legends-and-Best-Kept-Secrets-by-Wesley-Treat.pdf
    • http://cefasfese.4pu.com/3738734731737739/Weird-N-J-Volume-2-Your-Travel-Guide-to-New-Jersey-s-Local-Legends-and-Best-Kept-Secrets-by-Mark-Moran.pdf
    • http://cefasfese.4pu.com/3733731736732733/Weird-Florida-Your-Travel-Guide-to-Florida-s-Local-Legends-and-Best-Kept-Secrets-by-Charlie-Carlson.pdf
    • http://cefasfese.4pu.com/2735731730730738/Weird-Civil-War-Your-Travel-Guide-to-the-Ghostly-Legends-and-Best-Kept-Secrets-of-the-American-Civil-War-by-Mark-Sceurman.pdf
    • http://cefasfese.4pu.com/4733731736735733/Heart-of-Texas-Vol-2-Caroline-s-Child-Dr-Texas-Heart-of-Texas-3-4-by-Debbie-Macomber.pdf
    • http://cefasfese.4pu.com/1731733730737736737/Texas-Lucky-Texas-Tyler-Family-Saga-1-by-Sandra-Brown.pdf
    • http://cefasfese.4pu.com/4733732739739737/Texas-Destiny-Leigh-Brothers-Texas-Trilogy-1-by-Lorraine-Heath.pdf
    • http://cefasfese.4pu.com/2735735736733/Texas-Glory-Leigh-Brothers-Texas-Trilogy-2-by-Lorraine-Heath.pdf
    • http://cefasfese.4pu.com/4735739730739731/Texas-Bossa-Nova-Texas-Montgomery-Mavericks-5-by-Cynthia-D-39-Alba.pdf
    • http://cefasfese.4pu.com/4737738732737/Texas-Lucky-Texas-Tyler-Family-Saga-1-by-Sandra-Brown.pdf
    • http://cefasfese.4pu.com/1734737737731733/Flirting-with-Texas-Deep-in-the-Heart-of-Texas-5-by-Katie-Lane.pdf
    • http://cefasfese.4pu.com/1735730731738735/Escape-from-Texas-A-Novel-of-Slavery-and-the-Texas-War-of-Independence-by-James-W-Russell.pdf
    • http://cefasfese.4pu.com/1732737732738/Texas-Outlaw-Wild-Texas-Nights-1-by-Adrienne-deWolfe.pdf
    • http://cefasfese.4pu.com/3736734734736734/Texas-Fandango-Texas-Montgomery-Mavericks-3-by-Cynthia-D-39-Alba.pdf
    • http://cefasfese.4pu.com/2737738735730735/Texas-Twist-Texas-Soul-3-by-Sara-York.pdf
    • http://cefasfese.4pu.com/4733733736738734/Texas-True-The-Tylers-of-Texas-1-by-Janet-Dailey.pdf
    • http://cefasfese.4pu.com/4736731736730730/Texas-Legacy-Texas-Soul-6-by-Sara-York.pdf
    • http://cefasfese.4pu.com/3730732732736734/Texas-Hold-Em-Hotter-In-Texas-3-by-Christie-Craig.pdf
    • http://cefasfese.4pu.com/1731734735732734731/Texas-Free-The-Tylers-of-Texas-5-by-Janet-Dailey.pdf
    • http://cefasfese.4pu.com/2730736734736/Texas-Bluff-Texas-Hold-em-5-by-Linda-Warren.pdf