Malicious PDF — malware analysis report

Static analysis result for SHA-256 119feba046d243af…

MALICIOUS

PDF

16.7 KB Created: 2019-11-09 23:28:38 +00:00 Authoring application: mPDF 5.7
MD5: 381eaf79a6685253de058dfbde2d56a8 SHA-1: 96ad7595fd0079ef9846d43f1759f1b761851368 SHA-256: 119feba046d243af9d5fae9cd7c34b20ac30614597f612868f5d4dc04399f29e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which are presented as book titles. While the document body is corrupted, the presence of these links suggests a phishing or redirection attempt. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the file. No scripts were extracted, but the link farm indicates a likely attempt to direct users to malicious websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9810

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5730732732734734/The-Christmas-Spider-s-Miracle-by-Trinka-Hakes-Noble.pdf
    • http://cefasfese.4pu.com/2737739735738/The-Day-Jimmy-s-Boa-Ate-the-Wash-by-Trinka-Hakes-Noble.pdf
    • http://cefasfese.4pu.com/6736739737738736/Jimmy-s-Boa-Bounces-Back-by-Trinka-Hakes-Noble.pdf
    • http://cefasfese.4pu.com/1731731735734736730/Jimmy-s-Boa-and-the-Bungee-Jump-Slam-Dunk-by-Trinka-Hakes-Noble.pdf
    • http://cefasfese.4pu.com/6738734732738738/Spider-Man-Spider-Verse---Fearsome-Foes-Spider-Man-Enter-The-Spider-Verse-2018-Book-1-by-Stan-Lee.pdf
    • http://cefasfese.4pu.com/3730738733737730/A-Christmas-Miracle-by-Willow-Cross.pdf
    • http://cefasfese.4pu.com/8732738731733/Miracle-and-Other-Christmas-Stories-by-Connie-Willis.pdf
    • http://cefasfese.4pu.com/1730731738731732/All-Is-Well-The-Miracle-of-Christmas-in-July-by-Frank-E-Peretti.pdf
    • http://cefasfese.4pu.com/4736739738736730/A-Christmas-Miracle-in-Pajaro-Bay-by-Barbara-Cool-Lee.pdf
    • http://cefasfese.4pu.com/3737734735739730/Choosing-his-Christmas-Miracle-Wolves-of-Stone-Ridge-15-by-Charlie-Richards.pdf
    • http://cefasfese.4pu.com/2730732738734731/A-Callahan-Christmas-Miracle-Callahan-Cowboys-13-by-Tina-Leonard.pdf
    • http://cefasfese.4pu.com/2730732735738735/A-Noble-Deception-Noble-Series-1-by-Sara-Blayne.pdf
    • http://cefasfese.4pu.com/3733737738731736/Ultimate-Comics-Spider-Man-Death-of-Spider-Man-Fallout-by-Brian-Michael-Bendis.pdf
    • http://cefasfese.4pu.com/8730737738738738/Miracle-Gro-Encyclopedia-of-Plant-Care-by-Miracle-Gro.pdf
    • http://cefasfese.4pu.com/1739733732738732/Spider-Woman-Volume-1-Spider-Verse-by-Dennis-Hopeless.pdf
    • http://cefasfese.4pu.com/1730739736737731738/Noble-Retribution-Jack-Noble-6-by-L-T-Ryan.pdf
    • http://cefasfese.4pu.com/1732730733737735/Noble-Intentions-Noble-1-by-Katie-MacAlister.pdf
    • http://cefasfese.4pu.com/4735735732739738/Noble-Intentions-Noble-1-by-Katie-MacAlister.pdf
    • http://cefasfese.4pu.com/1733733733731731/Noble-Intentions-Jack-Noble-4-by-L-T-Ryan.pdf
    • http://cefasfese.4pu.com/1730738733734732735/A-Sprinkling-of-Christmas-Magic-Christmas-Cinderella-Finding-Forever-at-Christmas-The-Captain-s-Christmas-Angel-by-Elizabeth-Rolls.pdf