Malicious PDF — malware analysis report

Static analysis result for SHA-256 394713e815539ee8…

MALICIOUS

PDF

23.3 KB Created: 2019-11-07 12:31:45 +00:00 Authoring application: mPDF 5.7
MD5: 9d145b64e15ee18c6bff9187af94ca5d SHA-1: a46f297881d085216f8fde1e37bffbf3fadb38e9 SHA-256: 394713e815539ee8bfc4ec78e8ee38e8a083d4011019aea5ad0237ca0ff9f8cf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which strongly suggests a malicious intent to manipulate search engine results or redirect users. While most individual URLs appear benign, the sheer volume and the heuristic firing indicate a coordinated effort. The ML classifier also flagged this PDF with high confidence. No scripts were extracted, and the document body was heavily obfuscated, making it difficult to determine a more specific attack pattern beyond link farming.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9784

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7732735739739737/Past-Mortems-Life-and-Death-Behind-Mortuary-Doors-by-Carla-Valentine.pdf
    • http://cefasfese.4pu.com/3736733734734738/Past-Life-Regression-A-Manual-for-Hypnotherapists-to-Conduct-Effective-Past-Life-Regression-Sessions-by-Kemila-Zsange.pdf
    • http://cefasfese.4pu.com/7731738738735735/Past-Life-Regression-Remember-Past-Lives-and-Reincarnation-with-Hypnosis-via-Beach-Hypnosis-and-Meditation-by-Gelina-Ray.pdf
    • http://cefasfese.4pu.com/1730738739735733732/Dr-J-My-Life-Above-the-Rim-and-Behind-Closed-Doors-by-Julius-Erving.pdf
    • http://cefasfese.4pu.com/1730737738734732736/Death-Message-from-the-Past-by-Gustave-A-Boehn.pdf
    • http://cefasfese.4pu.com/4736730730732738/Soaring-Past-Death-by-Morticia-Knight.pdf
    • http://cefasfese.4pu.com/2732730731736732/Behind-Closed-Doors-Behind-Closed-Doors-1-Inside-Out-0-1-by-Lisa-Renee-Jones.pdf
    • http://cefasfese.4pu.com/4732733730735731/Angel-of-Death-Row-My-Life-as-a-Death-Penalty-Defense-Lawyer-by-Andrea-D-Lyon.pdf
    • http://cefasfese.4pu.com/4738738737731737/Murder-at-the-Mortuary-by-Lee-Strauss.pdf
    • http://cefasfese.4pu.com/1738734731739730/The-Men-with-the-Pink-Triangle-The-True-Life-and-Death-Story-of-Homosexuals-in-the-Nazi-Death-Camps-by-Heinz-Heger.pdf
    • http://cefasfese.4pu.com/1739730734730739/Wisdom-for-the-New-Millennium-Creating-the-Ultimate-Relationship-Healing-with-Consciousness-Love-Ego-and-the-Purpose-of-Life-Death-and-Beyond-Death-Jesus-and-Buddha-by-Sri-Sri-Ravi-Shankar.pdf
    • http://cefasfese.4pu.com/4733735736735731/Fry-Bacon-Add-Onions-The-Valentine-Family-amp-Friends-Cookbook-by-Kathleen-Valentine.pdf
    • http://cefasfese.4pu.com/1731736733733736738/The-Unsigned-Valentine-And-Other-Events-in-the-Life-of-Emma-Meade-by-Johanna-Hurwitz.pdf
    • http://cefasfese.4pu.com/7733738738738738/Be-My-Valentine-My-Funny-Valentine-My-Hero-by-Debbie-Macomber.pdf
    • http://cefasfese.4pu.com/6739736731734736/Valentine-Pontifex-Lord-Valentine-3-by-Robert-Silverberg.pdf
    • http://cefasfese.4pu.com/7733738738739734/New-York-Valentine-Annie-Valentine-5-by-Carmen-Reid.pdf
    • http://cefasfese.4pu.com/1730737730733734/Vegan-Virgin-Valentine-V-Valentine-1-by-Carolyn-Mackler.pdf
    • http://cefasfese.4pu.com/8736735734733/The-House-of-Doors-House-of-Doors-1-by-Brian-Lumley.pdf
    • http://cefasfese.4pu.com/7737738731732730/An-Introduction-to-the-mortuary-customs-of-the-North-American-Indians-by-Harry-Cr-cy-Yarrow.pdf
    • http://cefasfese.4pu.com/4733733737737736/A-Breath-of-Life-Life-amp-Death-Saga-Book-2-by-D-Love.pdf
    • http://cefasfese.4pu.com/4732733730735731/Angel-of-Death-Row-My-Life-as-a-Death-Penalty-Def