Malicious PDF — malware analysis report

Static analysis result for SHA-256 0e919bfea11c9e43…

MALICIOUS

PDF

27.5 KB Created: 2019-05-02 05:19:24 +01:00 Authoring application: mPDF 5.7
MD5: ec535f2bb8aaf1bebf386324651deac3 SHA-1: 7adbbf31fec4792f32b731ec112e1ccab13b4d9b SHA-256: 0e919bfea11c9e43e729464953040bb6cabe0c6a40daddb0212a58d893fa134e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While many of these URLs were classified as benign, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. The ML classifier also flagged the PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2733730731735736/The-Almost-Complete-Collection-of-True-Singapore-Ghost-Stories-Book-21-by-Russell-Lee.pdf
    • http://cefasfese.4pu.com/2739738736738738/Reunion-at-Dawn-and-Other-Uncollected-Ghost-Stories-by-H-Russell-Wakefield.pdf
    • http://cefasfese.4pu.com/7733734736735738/Edition-1nd-Just-1-hour-Amazing-Singapore-Travelling-Book-Bring-this-book-to-travel-This-book-is-NEW-This-book-includes-7-important-expression-for-this-book-by-Takuji-Ekawa.pdf
    • http://cefasfese.4pu.com/1737739731/Ghostly-A-Collection-of-Ghost-Stories-by-Audrey-Niffenegger.pdf
    • http://cefasfese.4pu.com/4732734735733731/True-Ghost-Stories-by-Marchioness-Townshend-of-Raynham.pdf
    • http://cefasfese.4pu.com/2732738738734734/The-Haunted-Graveyard-and-Other-True-Ghost-Stories-by-Allan-Zullo.pdf
    • http://cefasfese.4pu.com/1730735736737730730/The-Chronicles-of-Narnia-Complete-7-Book-Collection-with-Bonus-Book-Boxen-by-C-S-Lewis.pdf
    • http://cefasfese.4pu.com/1739734733732738/Haunted-Homeland-A-Definitive-Collection-of-North-American-Ghost-Stories-by-Michael-Norman.pdf
    • http://cefasfese.4pu.com/2738730730733733/Murderers-Row-A-Collection-of-Shocking-True-Crime-Stories-by-M-William-Phelps.pdf
    • http://cefasfese.4pu.com/5730732738739735/The-Magic-of-Christmas-Miracles-An-All-New-Collection-Of-Inspiring-True-Stories-by-Jamie-Miller.pdf
    • http://cefasfese.4pu.com/4738733736737736/The-Oxford-Book-of-English-Ghost-Stories-by-Michael-Cox.pdf
    • http://cefasfese.4pu.com/4732735736733733/The-Giant-Book-of-Ghost-Stories-by-Richard-Dalby.pdf
    • http://cefasfese.4pu.com/2739732731731732/The-Mammoth-Book-of-Ghost-Stories-by-Women-by-Marie-O-39-Regan.pdf
    • http://cefasfese.4pu.com/7730737738735732/The-Book-That-Made-Me-A-Collection-of-32-Personal-Stories-by-Judith-Ridge.pdf
    • http://cefasfese.4pu.com/5738731738738/The-Complete-Mother-Daughter-Book-Club-Collection-The-Mother-Daughter-Book-Club-Much-Ado-About-Anne-Dear-Pen-Pal-Pies-amp-Prejudice-Home-for-the-Holidays-Wish-You-Were-Eyre-The-Mother-Daughter-Book-Club-1-6-by-Heather-Vogel-Frederick.pdf
    • http://cefasfese.4pu.com/6732732738736732/The-Snow-Globe-Children-s-Book-Value-Tales-Imagination-Kid-s-Short-Stories-Collection-by-MS-Tammy-Brown-Elkeles.pdf
    • http://cefasfese.4pu.com/5738736735737739/Chameleon-II---True-Stories-of-a-Texas-Undercover-Police-Officer-Chameleon---True-Stories-of-a-Texas-Undercover-Police-Officer-Book-2-by-Ty-Cran.pdf
    • http://cefasfese.4pu.com/9737737733737/Near-Death-Experiences-True-stories-of-Near-Death-Experiences-told-by-real-people-True-stories-of-those-who-went-to-Heaven-by-Tessy-Rawlins.pdf
    • http://cefasfese.4pu.com/3731732733733735/Kids-and-Teens-Story-Collection-5-HUGE-COLLECTION-OF-15-STORIES-by-Betty-J-Byers.pdf
    • http://cefasfese.4pu.com/3731733735732735/Stories-for-Early-Readers-Collection-of-Stories-with-Simple-Vocabulary-for-Intermediate-Readers-17-Different-Stories-Included-in-this-Bundle-by-Betty-J-Byers.pdf