Malicious PDF — malware analysis report

Static analysis result for SHA-256 282897a466ef1a46…

MALICIOUS

PDF

19.9 KB Created: 2019-09-27 13:30:02 +01:00 Authoring application: mPDF 5.7
MD5: c3191b97cc1e57bb0b81980db8f695de SHA-1: bd5c0ed581e1b93187b7fbd80e62a1e9de3ee688 SHA-256: 282897a466ef1a466f115d9794e018b3d88c62c5109725e809037b52a4349337
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs appear to point to benign book titles, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731736731739734/Fighting-to-Survive-As-The-World-Dies-2-by-Rhiannon-Frater.pdf
    • http://cefasfese.4pu.com/2732735734734735/Fighting-to-Survive-As-The-World-Dies-2-by-Rhiannon-Frater.pdf
    • http://cefasfese.4pu.com/2732737739738731/Siege-As-The-World-Dies-3-by-Rhiannon-Frater.pdf
    • http://cefasfese.4pu.com/7739738730730732/Forskanset-bag-muren-As-the-world-dies-2-by-Rhiannon-Frater.pdf
    • http://cefasfese.4pu.com/2734733733733739/Pretty-When-She-Kills-Pretty-When-She-Dies-2-by-Rhiannon-Frater.pdf
    • http://cefasfese.4pu.com/4730736730734730/The-Living-Dead-Boy-by-Rhiannon-Frater.pdf
    • http://cefasfese.4pu.com/5734730735731730/The-Purge-In-Darkness-We-Must-Abide-9-by-Rhiannon-Frater.pdf
    • http://cefasfese.4pu.com/2735738737736736/I-Will-Survive-Tips-and-Hints-to-Help-You-Survive-in-this-Zombie-Infested-World-Survive-1-by-Dana-Burkey.pdf
    • http://cefasfese.4pu.com/4733731737738730/The-Tale-Of-The-Vampire-Bride-Vampire-Bride-1-by-Rhiannon-Frater.pdf
    • http://cefasfese.4pu.com/9736731738731/The-End-How-to-Survive-the-End-of-the-World-by-Jill-M-Roberts.pdf
    • http://cefasfese.4pu.com/5734/The-Queen-of-All-that-Dies-The-Fallen-World-1-by-Laura-Thalassa.pdf
    • http://cefasfese.4pu.com/1730732736738739/The-Fix-How-Nations-Survive-and-Thrive-in-a-World-in-Decline-by-Jonathan-Tepperman.pdf
    • http://cefasfese.4pu.com/4733739734734739/Living-Single-in-a-Married-World-How-to-Survive-and-Thrive-It-s-not-easy-but-it-is-possible-by-H-Roxanne-Banks.pdf
    • http://cefasfese.4pu.com/5731734735735739/Monster-Science-Could-Monsters-Survive-and-Thrive-in-the-Real-World-by-Helaine-Becker.pdf
    • http://cefasfese.4pu.com/1738735732737/A-War-to-be-Won-Fighting-the-Second-World-War-by-Williamson-Murray.pdf
    • http://cefasfese.4pu.com/8731731734734734/The-World-Economic-and-Social-Crisis-its-impact-on-the-underdeveloped-countries-its-somber-prospects-and-the-need-to-struggle-if-we-are-to-survive-by-Fidel-Castro.pdf
    • http://cefasfese.4pu.com/4739737738733731/Fighting-God-An-Atheist-Manifesto-for-a-Religious-World-by-David-Silverman.pdf
    • http://cefasfese.4pu.com/2730732734730733/The-Necessary-War-Canadians-Fighting-the-Second-World-War-1939-1943-Volume-One-by-Tim-Cook.pdf
    • http://cefasfese.4pu.com/1734734736732/The-House-of-Dies-Drear-Dies-Drear-Chronicles-1-by-Virginia-Hamilton.pdf
    • http://cefasfese.4pu.com/3731736733731732/The-Yellow-World-How-Fighting-for-My-Life-Taught-Me-How-to-Live-by-Albert-Espinosa.pdf