Malicious PDF — malware analysis report

Static analysis result for SHA-256 39ad7a78e8609ca0…

MALICIOUS

PDF

20.2 KB Created: 2019-05-03 05:30:46 +01:00 Authoring application: mPDF 5.7
MD5: f96b478878d909d2e243cd11d21dc3e3 SHA-1: 9e83c630656d7c886b8f6681c5291daff060de85 SHA-256: 39ad7a78e8609ca00f71db746af5f06ece9f9a4006376d1f1cde7c0af002aecb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, identified as a 'PDF_SEO_LINK_FARM' heuristic. These links, such as http://cefasfese.4pu.com/2738733730731735/Crazy-Horny-Lady-Crazy-Sexy-Love-Stories-Book-1-by-Lindsay-Valentine.pdf, likely serve to direct traffic or host further malicious content, although the specific URLs themselves were classified as benign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2738733730731735/Crazy-Horny-Lady-Crazy-Sexy-Love-Stories-Book-1-by-Lindsay-Valentine.pdf
    • http://cefasfese.4pu.com/1739738732734731/Crazy-Sexy-Ghoulish-A-Halloween-Romance-Crazy-Sexy-Ghoulish-1-by-G-G-Andrew.pdf
    • http://cefasfese.4pu.com/3735734737732735/Crazy-Sexy-Love-Dirty-Dicks-1-by-K-L-Grayson.pdf
    • http://cefasfese.4pu.com/2732735735735736/Kissing-Her-Crazy-Crazy-Love-2-by-Kira-Archer.pdf
    • http://cefasfese.4pu.com/1731731734731737733/The-Cuckold-Surrender-Hotwife-Femdom-Interracial-Cuckold-Erotica-with-a-sexy-wife-who-s-crazy-for-BBC-and-will-do-anything-for-a-sexy-black-African-dominant-to-be-her-stud-by-Ronnie-Kinski.pdf
    • http://cefasfese.4pu.com/4730736730736735/The-Book-of-Love-Improvisations-on-a-Crazy-Little-Thing-by-Roger-Rosenblatt.pdf
    • http://cefasfese.4pu.com/1732739732737735/A-Crazy-Homecoming-Crazy-Texas-1-by-Cate-Baylor.pdf
    • http://cefasfese.4pu.com/4739731730737735/Drive-Me-Crazy-Holland-Springs-1-by-Marquita-Valentine.pdf
    • http://cefasfese.4pu.com/1738733731733734/Crazy-Sexy-Diet-Eat-Your-Veggies-Ignite-Your-Spark-and-Live-Like-You-Mean-It-by-Kris-Carr.pdf
    • http://cefasfese.4pu.com/3733732731735739/Crazy-Kinky-Dirty-Clowns-Crazy-Kinky-Dirty-Love-4-by-K-A-Merikan.pdf
    • http://cefasfese.4pu.com/3733732731735735/Crazy-Kinky-Dirty-Skinhead-Crazy-Kinky-Dirty-Love-1-by-K-A-Merikan.pdf
    • http://cefasfese.4pu.com/3733731738732739/Crazy-Little-Town-Called-love-The-To-Hell-And-Back-Club-Series-Book-Two-by-Jill-Hannah-Anderson.pdf
    • http://cefasfese.4pu.com/4737730735731737/A-Crazy-Little-Thing-Called-Love-Serendipitous-Love-1-by-Christina-C-Jones.pdf
    • http://cefasfese.4pu.com/1739739738731739/Chickens-May-Not-Cross-the-Road-and-Other-Crazy-But-True-Laws-and-Other-Crazy-But-True-Laws-by-Kathi-Linz.pdf
    • http://cefasfese.4pu.com/4736735738731738/Love-Me-Crazy-by-M-N-Forgy.pdf
    • http://cefasfese.4pu.com/3731736735733732/Crazy-Maybe-Crazy-1-by-A-D-Justice.pdf
    • http://cefasfese.4pu.com/2736736737/Some-Sort-of-Love-Happy-Crazy-Love-3-by-Melanie-Harlow.pdf
    • http://cefasfese.4pu.com/4733732730734737/Crazy-Love-by-Rachael-Tamayo.pdf
    • http://cefasfese.4pu.com/2733731733738739/Crazy-in-Love-by-Chris-Manby.pdf
    • http://cefasfese.4pu.com/6733731734737732/Love-Is-Crazy-by-Abby-Brooks.pdf
    • http://cefasfese.4pu.com/1731731734731737733/The-Cuckold-Surrender-Hotwife-Femdom-Interracial-Cuckold-Erotica-with-a-sexy-wife-who-s-crazy-for-BBC-and-will-do-anything-for-a-sexy-black-Afr