Malicious PDF — malware analysis report

Static analysis result for SHA-256 149cbfe15626072b…

MALICIOUS

PDF

21.5 KB Created: 2019-05-02 05:42:23 +01:00 Authoring application: mPDF 5.7
MD5: 21e369b863268e57e86a944423387845 SHA-1: 2d97e1abdf7b83a92197825b72d97c2f439ae00a SHA-256: 149cbfe15626072bd96faeaa18505b9f5ba00e9544496a92193d9d500cbd429e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, forming a link farm. While the specific content of these linked PDFs is benign, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' indicate a malicious intent to manipulate search engine results or distribute content through a deceptive link structure. The ML classifier also flagged the document as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9437

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4732733739731736/Generous-Justice-How-God-s-Grace-Makes-Us-Just-by-Timothy-J-Keller.pdf
    • http://cefasfese.4pu.com/5737731735731736/Le-Dieu-prodigue-by-Timothy-J-Keller.pdf
    • http://cefasfese.4pu.com/2737731738738737/Prayer-Experiencing-Awe-and-Intimacy-with-God-by-Timothy-J-Keller.pdf
    • http://cefasfese.4pu.com/2736731737733732/Walking-with-God-through-Pain-and-Suffering-by-Timothy-J-Keller.pdf
    • http://cefasfese.4pu.com/6733738732739/The-Prodigal-God-Recovering-the-Heart-of-the-Christian-Faith-by-Timothy-J-Keller.pdf
    • http://cefasfese.4pu.com/4732733737732734/The-Meaning-of-Marriage-Facing-the-Complexities-of-Commitment-with-the-Wisdom-of-God-by-Timothy-J-Keller.pdf
    • http://cefasfese.4pu.com/4732733739731738/King-s-Cross-The-Story-of-the-World-in-the-Life-of-Jesus-by-Timothy-J-Keller.pdf
    • http://cefasfese.4pu.com/2733734737733739/Center-Church-Doing-Balanced-Gospel-Centered-Ministry-in-Your-City-by-Timothy-J-Keller.pdf
    • http://cefasfese.4pu.com/9739730736735730/Der-zugewandte-Jesus-Unerwartete-Antworten-auf-die-gro-en-Fragen-des-Lebens-by-Timothy-J-Keller.pdf
    • http://cefasfese.4pu.com/3735733735735734/Encounters-with-Jesus-Unexpected-Answers-to-Life-s-Biggest-Questions-by-Timothy-J-Keller.pdf
    • http://cefasfese.4pu.com/1738732739735732/Counterfeit-Gods-The-Empty-Promises-of-Money-Sex-and-Power-and-the-Only-Hope-that-Matters-by-Timothy-J-Keller.pdf
    • http://cefasfese.4pu.com/4733735738739738/More-Than-a-Whisper-One-Woman-s-Journey-Through-Pain-to-Grace-by-Anne-Sano-Keller.pdf
    • http://cefasfese.4pu.com/8733731732733738/Faith-Hope-and-Justice-Saved-by-Grace-and-How-God-Led-Me-Through-Hell-by-Marie-Libellule.pdf
    • http://cefasfese.4pu.com/7736735730733733/Jesus-Justice-and-Gender-Roles-A-Case-for-Gender-Roles-in-Ministry-by-Kathy-Keller.pdf
    • http://cefasfese.4pu.com/4738730738736737/Natural-Born-Keller-by-Amanda-Keller.pdf
    • http://cefasfese.4pu.com/1731738733730731733/Keller-Memento-by-David-H-Keller.pdf
    • http://cefasfese.4pu.com/6730733734735738/The-Miracle-Worker-Selected-Works-of-Helen-Keller-by-Helen-Keller.pdf
    • http://cefasfese.4pu.com/3735738734738731/Generous-Death-Jenny-Cain-1-by-Nancy-Pickard.pdf
    • http://cefasfese.4pu.com/4736731739732731/The-Blessed-Life-Unlocking-the-Rewards-of-Generous-Living-by-Robert-Morris.pdf
    • http://cefasfese.4pu.com/1733735738737733/Feast-Generous-Vegetarian-Meals-for-Any-Eater-and-Every-Appetite-by-Sarah-Copeland.pdf