Malicious PDF — malware analysis report

Static analysis result for SHA-256 1a5f93a8bc6e902d…

MALICIOUS

PDF

16.6 KB Created: 2019-06-04 09:19:18 +01:00 Authoring application: mPDF 5.7
MD5: b74cbb40cfb0b53512e7fb8dee2c59c0 SHA-1: c3d6e931b6812acbe819f8aaa2182978eee95b78 SHA-256: 1a5f93a8bc6e902d34a93014d9146e7aa5b520d4c88fa9cafa7b4db6e971f0d8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier as malicious. It contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM' heuristic, pointing to various book titles hosted on the domain 'cefasfese.4pu.com'. While these specific URLs were labeled as confirmed benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or as a lure for further malicious activity. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9810

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8732737732736731/The-Roman-Hat-Mystery-Ellery-Queen-Detective-1-by-Ellery-Queen.pdf
    • http://cefasfese.4pu.com/1737735733736/The-Player-on-the-Other-Side-Ellery-Queen-Detective-27-by-Ellery-Queen.pdf
    • http://cefasfese.4pu.com/2735730733736733/The-French-Powder-Mystery-by-Ellery-Queen.pdf
    • http://cefasfese.4pu.com/4735732736734731/The-Dutch-Shoe-Mystery-by-Ellery-Queen.pdf
    • http://cefasfese.4pu.com/9737734739731737/Ellery-Queen-s-Mystery-Magazine-January-2001-Vol-117-No-1-Whole-No-713-by-Janet-Hutchings.pdf
    • http://cefasfese.4pu.com/3736732732739734/A-Study-in-Terror-by-Ellery-Queen.pdf
    • http://cefasfese.4pu.com/3735739733736737/Lethal-Letters-A-Books-by-the-Bay-Mystery-by-Ellery-Adams.pdf
    • http://cefasfese.4pu.com/1739737732733736/A-Killer-Plot-A-Books-by-the-Bay-Mystery-1-by-Ellery-Adams.pdf
    • http://cefasfese.4pu.com/2739738734732738/Writing-All-Wrongs-A-Books-by-the-Bay-Mystery-7-by-Ellery-Adams.pdf
    • http://cefasfese.4pu.com/2733734735736737/A-Deadly-Clich-A-Books-by-the-Bay-Mystery-2-by-Ellery-Adams.pdf
    • http://cefasfese.4pu.com/2739738734732735/Lethal-Letters-A-Books-by-the-Bay-Mystery-6-by-Ellery-Adams.pdf
    • http://cefasfese.4pu.com/8730737737738732/Pecan-Pies-and-Homicides-A-Charmed-Pie-Shoppe-Mystery-3-by-Ellery-Adams.pdf
    • http://cefasfese.4pu.com/2735731737734732/Queen-Takes-Queen-Their-Vampire-Queen-3-by-Joely-Sue-Burkhart.pdf
    • http://cefasfese.4pu.com/6731737739734731/Never-The-Always-Series-2-by-Ellery-Rhodes.pdf
    • http://cefasfese.4pu.com/5739736739732/Practicing-the-Truth-by-Ellery-Akers.pdf
    • http://cefasfese.4pu.com/5730731735732732/The-Queen-Mother-The-Untold-Story-of-Elizabeth-Bowes-Lyon-Who-Became-Queen-Elizabeth-The-Queen-Mother-by-Lady-Colin-Campbell.pdf
    • http://cefasfese.4pu.com/4735730732738737/The-Carpenter-and-the-Actor-Ellery-Mountain-3-by-R-J-Scott.pdf
    • http://cefasfese.4pu.com/2731734735737731/Publish-and-Perish-Linnet-Ellery-3-by-Phillipa-Bornikova.pdf
    • http://cefasfese.4pu.com/4738733739735735/Unraveling-Josh-Ellery-College-3-by-Edie-Danford.pdf
    • http://cefasfese.4pu.com/7730730739/The-Vanishing-Season-Ellery-Hathaway-1-by-Joanna-Schaffhausen.pdf
    • http://cefasfese.4pu.com/2733734735736737/A-Deadl