Malicious PDF — malware analysis report

Static analysis result for SHA-256 3be9c21aa3023f7c…

MALICIOUS

PDF

23.0 KB Created: 2019-11-08 00:25:03 +00:00 Authoring application: mPDF 5.7
MD5: ef05c37b003f86cff437f40d3f9108b2 SHA-1: bb5e9ebfc90398f06664f754a3c27de8e6e25476 SHA-256: 3be9c21aa3023f7cee58a8dad3cca369ca3e39fe97622c7a2278e5d082841065
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a significant number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to a domain that appears to be hosting a large collection of PDF files, suggesting a link farm or content distribution network. While the document body is unreadable, the presence of numerous links indicates a likely attempt to manipulate search engine results or distribute content from a controlled domain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9776

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9733733735737736/Bart-of-Darkness-The-Book-of-Bart---Verse-2-by-Ryan-Hill.pdf
    • http://cefasfese.4pu.com/2737736730733732/Papal-Bull-An-Ex-Catholic-Calls-Out-the-Catholic-Church-by-Joe-Wenke.pdf
    • http://cefasfese.4pu.com/3732732731734736/Is-Notre-Dame-Still-a-Catholic-University-a-Catholic-Reflection-on-Faith-and-Freedom-Before-and-Beyond-the-Vagina-Monologues-and-Queer-Films-by-Zacharias-P-Thundy.pdf
    • http://cefasfese.4pu.com/6733736732730730/Carmelite-Studies-Centenary-of-Saint-Teresa-by-Catholic-University-Symposium-1982-Catholic-University-of-America-.pdf
    • http://cefasfese.4pu.com/6736730733735732/The-Culture-of-Catholic-Schools-A-Study-of-Catholic-Schools-1972-1993-by-Marcellin-Flynn.pdf
    • http://cefasfese.4pu.com/9734738731738737/My-Treasury-of-Chaplets-by-Patricia-S-Quintiliani.pdf
    • http://cefasfese.4pu.com/9734738734734731/Chaplets-from-Coquet-Side-by-Joseph-1821-1896-Crawhall.pdf
    • http://cefasfese.4pu.com/1731733736736732/Courageous-Gilbert-the-Groundhog-2016-Mom-s-Choice-Awards-Gold-Medal-Pinnacle-Medal-Readers-Favorite-5-Star-Review-and-Readers-Favorite-International-Gold-Medal-Winner-by-Regina-E-McCarthy.pdf
    • http://cefasfese.4pu.com/6736734736731737/My-Favorite-Thing-Is-Monsters-Vol-2-My-Favorite-Thing-Is-Monsters-2-by-Emil-Ferris.pdf
    • http://cefasfese.4pu.com/4739739736/My-Favorite-Thing-Is-Monsters-Vol-1-My-Favorite-Thing-Is-Monsters-1-by-Emil-Ferris.pdf
    • http://cefasfese.4pu.com/6730734737730731/Dreamcatcher-by-Bart-Powell.pdf
    • http://cefasfese.4pu.com/7730736735731732/The-New-Testament-by-Bart-D-Ehrman.pdf
    • http://cefasfese.4pu.com/3733730731736734/Leave-Myself-Behind-by-Bart-Yates.pdf
    • http://cefasfese.4pu.com/4733736731734734/The-Innkeeper-by-Bart-Varelmann.pdf
    • http://cefasfese.4pu.com/1732731735736731/The-Door-Is-Open-by-Bart-Campbell.pdf
    • http://cefasfese.4pu.com/1731739735733738/Zombie-Books-by-Bart-Gnarly.pdf
    • http://cefasfese.4pu.com/6736736732738738/Inside-the-Vatican-by-Bart-McDowell.pdf
    • http://cefasfese.4pu.com/3736739730735732/Fierce-Family-by-Bart-R-Leib.pdf
    • http://cefasfese.4pu.com/9734738733738738/The-Torn-Trilogy-Chaplets-5-The-Torn-Trilogy-12-Chaplet-Edition-by-Josephine-Thompson.pdf
    • http://cefasfese.4pu.com/9734738733738735/The-Torn-Trilogy-Chaplet-10-The-Torn-Trilogy-12-Chaplets-Edition-by-Sara-Niles-Pen-Name-.pdf
    • http://cefasfese.4pu.com/6736730733735732/The-Culture-of-Catholic-Schools-A-Study-of-