Malicious PDF — malware analysis report

Static analysis result for SHA-256 30abf8b670a2b5f3…

MALICIOUS

PDF

18.9 KB Created: 2019-05-01 13:05:59 +01:00 Authoring application: mPDF 5.7
MD5: fb5c8837b54beb6d9cf0fd24a6dff889 SHA-1: aa53e46782a90ee217cd0f0271edcf8c675d4621 SHA-256: 30abf8b670a2b5f384de1709f02b74d18599c267670f18a9b2c8345a06b7b2d7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to book titles and appear benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a landing page for further malicious activity. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4733738736738732/Chasing-Chaos-My-Decade-In-and-Out-of-Humanitarian-Aid-by-Jessica-Alexander.pdf
    • http://cefasfese.4pu.com/5734733730732739/The-Role-and-Status-of-International-Humanitarian-Volunteers-and-Organizations-The-Right-and-Duty-to-Humanitarian-Assistance-by-Yves-Beigbeder.pdf
    • http://cefasfese.4pu.com/1732736730731737/Chasing-Chaos-Hollywood-Lights-3-by-Katie-Rose-Guest-Pryal.pdf
    • http://cefasfese.4pu.com/4730733736738733/Chasing-Ravens-by-Jessica-E-Paige.pdf
    • http://cefasfese.4pu.com/6738733735/The-Chaos-of-Standing-Still-by-Jessica-Brody.pdf
    • http://cefasfese.4pu.com/1732731734735737/Chasing-the-Omega-Small-Town-1-by-Jessica-Edwards.pdf
    • http://cefasfese.4pu.com/3733736736733730/Chasing-the-Witch-Boston-Witches-2-by-Jessica-Gibson.pdf
    • http://cefasfese.4pu.com/3732738736732738/Edge-of-Chaos-Sons-of-Chaos-MC-1-by-Brynn-O-39-Connor.pdf
    • http://cefasfese.4pu.com/2734736733734736/Chasing-Beautiful-The-Prelude-Chasing-0-5-by-Pamela-Ann.pdf
    • http://cefasfese.4pu.com/3735738730738738/Chaos-Abounds-Soldiers-of-Chaos-1-by-A-A-Askevold.pdf
    • http://cefasfese.4pu.com/4738732738733739/Deception-and-Chaos-Chaos-1-by-S-M-Soto.pdf
    • http://cefasfese.4pu.com/1731736738735737734/Humanitarian-Logistics-by-Rolando-Tomasini.pdf
    • http://cefasfese.4pu.com/4737733739738735/Chaos-Walking-The-Complete-Trilogy-Chaos-Walking-1-3-by-Patrick-Ness.pdf
    • http://cefasfese.4pu.com/6732739737733736/Chasing-Perfection-Complete-Series-Chasing-Perfection-1-5-by-M-S-Parker.pdf
    • http://cefasfese.4pu.com/7732732730731736/Customary-International-Humanitarian-Law-by-Louise-Doswald-Beck.pdf
    • http://cefasfese.4pu.com/6734730736738733/Peoples-of-the-Sea-A-Reconstruction-of-Ancient-History-A-Continuation-of-the-Ages-in-Chaos-Series-Ages-in-Chaos-series-2-by-Immanuel-Velikovsky.pdf
    • http://cefasfese.4pu.com/3735735738736/Chaos-Walking-A-Trilogy-Chaos-Walking-1-3-by-Patrick-Ness.pdf
    • http://cefasfese.4pu.com/1730739738734739/Reece-Winner-For-The-Win-the-making-of-a-teen-humanitarian-by-Kevin-Armes.pdf
    • http://cefasfese.4pu.com/1730734732733736738/The-Least-of-All-Possible-Evils-Humanitarian-Violence-from-Arendt-to-Gaza-by-Eyal-Weizman.pdf
    • http://cefasfese.4pu.com/8736730733730736/Between-Samaritans-and-States-The-Political-Ethics-of-Humanitarian-Ingos-by-Jennifer-Rubenstein.pdf