Malicious PDF — malware analysis report

Static analysis result for SHA-256 46bc1c8b707f0c76…

MALICIOUS

PDF

16.2 KB Created: 2019-06-13 13:13:09 +01:00 Authoring application: mPDF 5.7
MD5: 024da6a4c575008ff414122633c6fbb2 SHA-1: a9040e706ca5fe55281fcd1ba78bf0b5e2d60059 SHA-256: 46bc1c8b707f0c76fa26496c586c5e2ab65054b79a3b24e3802f3945b98f475d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a link farm with over 20 external URLs, predominantly pointing to book titles. This heuristic firing indicates a tactic to artificially inflate search engine rankings or distribute content through a large number of linked pages. While the specific URLs themselves are marked as benign, the sheer volume and structure suggest a malicious intent to manipulate traffic or distribute content indirectly. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6735736736737/Ivy-and-Bean-What-s-the-Big-Idea-Ivy-and-Bean-7-by-Annie-Barrows.pdf
    • http://cefasfese.4pu.com/6733739730735/Ivy-and-Bean-Doomed-to-Dance-Ivy-and-Bean-6-by-Annie-Barrows.pdf
    • http://cefasfese.4pu.com/6731735733738/Ivy-and-Bean-Bound-to-be-Bad-Ivy-and-Bean-5-by-Annie-Barrows.pdf
    • http://cefasfese.4pu.com/6730734730731739/Ivy-and-Bean-s-Treasure-Box-by-Annie-Barrows.pdf
    • http://cefasfese.4pu.com/1731734730739738733/Bean-Floats-a-Boat-Bean-in-the-Garden-2-by-Ann-Bevans.pdf
    • http://cefasfese.4pu.com/1730738730733737734/Nelly-Bean-and-the-Kids-Eating-Garbage-Can-Monster-The-Adventures-of-Nate-Boy-and-Nelly-Bean-Book-1-by-Casia-Schreyer.pdf
    • http://cefasfese.4pu.com/1731734730739738737/Maggie-Bean-in-Love-Maggie-Bean-3-by-Tricia-Rayburn.pdf
    • http://cefasfese.4pu.com/1734732733731735/The-Melting-of-Maggie-Bean-Maggie-Bean-1-by-Tricia-Rayburn.pdf
    • http://cefasfese.4pu.com/4733732736737730/Bean-s-Gallipoli-by-C-E-W-Bean.pdf
    • http://cefasfese.4pu.com/3731730737730736/Bean-by-Bean-A-Cookbook-More-Than-175-Recipes-for-Fresh-Beans-Dried-Beans-Cool-Beans-Hot-Beans-Savory-Beans-Even-Sweet-Beans-by-Crescent-Dragonwagon.pdf
    • http://cefasfese.4pu.com/4733735737730732/Jilly-Bean-Jilly-Bean-1-by-Celia-Vogel.pdf
    • http://cefasfese.4pu.com/1738732731738736/The-Huntress-by-Amy-Bean.pdf
    • http://cefasfese.4pu.com/2737739738734735/The-Magic-Half-by-Annie-Barrows.pdf
    • http://cefasfese.4pu.com/4733730738738733/The-Watch-by-Krista-Bean.pdf
    • http://cefasfese.4pu.com/5731736733737730/The-Big-Meeting-by-David-Bean.pdf
    • http://cefasfese.4pu.com/1731731737739735731/Bean-Counter-by-T-A-Clark.pdf
    • http://cefasfese.4pu.com/1731734731730733735/Bella-Bean-by-Rebecca-Kai-Dotlich.pdf
    • http://cefasfese.4pu.com/5739730733737/Building-Our-House-by-Jonathan-Bean.pdf
    • http://cefasfese.4pu.com/1731734731730733733/This-Is-My-Home-This-Is-My-School-by-Jonathan-Bean.pdf
    • http://cefasfese.4pu.com/1731734731730731738/The-Jelly-Bean-by-F-Scott-Fitzgerald.pdf
    • http://cefasfese.4pu.com/3731730737730736/Bean-by-Bean-A-Cookboo