Malicious PDF — malware analysis report

Static analysis result for SHA-256 30d2d40798df064b…

MALICIOUS

PDF

14.9 KB Created: 2019-11-08 01:15:26 +00:00 Authoring application: mPDF 5.7
MD5: e048996e0dc731b6d2f1b0044958f4b1 SHA-1: 23d8cbd4185fb0e8c27bd83858b27772033d971a SHA-256: 30d2d40798df064b150fb40df14cf631d7491ab5c4a85d30c23a66f1de2c6aff
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. It contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM', pointing to external PDF documents. While the specific intent of these links is unclear without further analysis of the linked content, the sheer volume and the heuristic firing suggest a malicious attempt to manipulate search engine results or distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1739736735735731/Blue-Moon-Promise-Under-Texas-Stars-1-by-Colleen-Coble.pdf
    • http://cefasfese.4pu.com/3734737739738734/Montana-Moon-Over-Water-Promise-Texas-by-Debbie-Macomber.pdf
    • http://cefasfese.4pu.com/6735739734737738/Once-in-a-Blue-Moon-Bluebonnet-Texas-2-by-Amie-Stuart.pdf
    • http://cefasfese.4pu.com/6735735732733/Midnight-Sea-Aloha-Reef-4-by-Colleen-Coble.pdf
    • http://cefasfese.4pu.com/2730738731738/Into-the-Deep-Rock-Harbor-3-by-Colleen-Coble.pdf
    • http://cefasfese.4pu.com/1731739735730730739/Tidewater-Inn-Hope-Beach-1-by-Colleen-Coble.pdf
    • http://cefasfese.4pu.com/2733734739732733/The-Lightkeeper-s-Bride-Mercy-Falls-2-by-Colleen-Coble.pdf
    • http://cefasfese.4pu.com/2730737737730/Distant-Echoes-Aloha-Reef-1-by-Colleen-Coble.pdf
    • http://cefasfese.4pu.com/4734735738737/Without-a-Trace-Rock-Harbor-Series-1-by-Colleen-Coble.pdf
    • http://cefasfese.4pu.com/3734735739733738/Twilight-at-Blueberry-Barrens-Sunset-Cove-3-by-Colleen-Coble.pdf
    • http://cefasfese.4pu.com/4739739738731739/A-Heart-s-Home-A-Journey-of-the-Heart-6-by-Colleen-Coble.pdf
    • http://cefasfese.4pu.com/1733734732735734/Lonestar-Secrets-Lonestar-2-by-Colleen-Coble.pdf
    • http://cefasfese.4pu.com/4730732739738739/Blue-Moon-Blue-Moon-and-Red-Sunset-1-by-Rowena-Sudbury.pdf
    • http://cefasfese.4pu.com/3739738735733737/Blue-Moon-House-Kitten-Blue-Moon-House-The-Prequels-Series-by-Angelica-Dawson.pdf
    • http://cefasfese.4pu.com/3733732730730735/Blue-Moon-III-Call-of-the-Alpha-Blue-Moon-3-by-A-E-Via.pdf
    • http://cefasfese.4pu.com/3738735730732738/Return-to-Promise-Heart-of-Texas-8-by-Debbie-Macomber.pdf
    • http://cefasfese.4pu.com/1734736734731733/Blue-Moon-The-Blood-Moon-Trilogy-3-by-A-D-Ryan.pdf
    • http://cefasfese.4pu.com/1737734739735735/Blue-Moon-Blue-Crystal-1-by-Pat-Spence.pdf
    • http://cefasfese.4pu.com/1731734739732737733/Blue-Bonnet-of-the-Seven-Stars-Blue-Bonnet-6-by-Lela-Horn-Richards.pdf
    • http://cefasfese.4pu.com/6731735735739737/The-Kids-Got-It-Right-How-the-Texas-All-Stars-Kicked-Down-Racial-Walls-by-Jim-Dent.pdf
    • http://cefasfese.4pu.com/