Malicious PDF — malware analysis report

Static analysis result for SHA-256 5faa8a4101f1f72a…

MALICIOUS

PDF

20.9 KB Created: 2019-06-04 12:45:18 +01:00 Authoring application: mPDF 5.7
MD5: a89e682d8a81109ecf1fcc0515be07a7 SHA-1: 9d22f3e5a180858aa7ef1e8023283d8b1fa770d4 SHA-256: 5faa8a4101f1f72a2466a98cfadf5b726f297b364fb700879313f7093f6bd33e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. The document body is heavily obfuscated, preventing a detailed analysis of its specific content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9462

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731738734734731739/Gertie-Sews-Vintage-Casual-A-Modern-Guide-to-Sportswear-Styles-of-the-1940s-and-1950s-by-Gretchen-Hirsch.pdf
    • http://cefasfese.4pu.com/1731733732738734737/Gertie-s-New-Book-for-Better-Sewing-A-Modern-Guide-to-Couture-Style-Sewing-Using-Basic-Vintage-Techniques-by-Gretchen-Hirsch.pdf
    • http://cefasfese.4pu.com/2732731734739731/Modern-Vintage-Style-Using-vintage-pieces-in-the-contemporary-home-by-Emily-Chalmers.pdf
    • http://cefasfese.4pu.com/9737739738730730/Die-Geheimnisvolle-Aff-re-bei-Styles-The-Mysterious-Affair-at-Styles-German-edition-by-Agatha-Christie.pdf
    • http://cefasfese.4pu.com/6734739736735730/Die-Geheimsinnige-Verhouding-Met-Styles-The-Mysterious-Affair-at-Styles-Afrikaans-Edition-by-Agatha-Christie.pdf
    • http://cefasfese.4pu.com/4731736738736733/Modern-Girl-s-Guide-to-Vacation-Flings-Modern-Girl-s-Guide-1-by-Gina-Drayer.pdf
    • http://cefasfese.4pu.com/3734730730736738/Star-Wars-Vintage-Action-Figures-A-Guide-for-Collectors-by-John-Kellerman.pdf
    • http://cefasfese.4pu.com/3739734734739733/Casual-Encounter-Vol-1-Casual-Encounter-1-by-M-S-Parker.pdf
    • http://cefasfese.4pu.com/1735731738738730/Discovering-Vintage-Boston-A-Guide-to-the-City-s-Timeless-Shops-Bars-Restaurants-amp-More-by-Maria-Olia.pdf
    • http://cefasfese.4pu.com/1731738734734731737/Grilling-with-chef-George-Hirsch-by-George-Hirsch.pdf
    • http://cefasfese.4pu.com/1731733732738734739/Gretchen-Birch-Boxed-Set-Gretchen-Birch-1-4-by-Deb-Baker.pdf
    • http://cefasfese.4pu.com/4734731730738736/Very-Casual-by-Michael-DeForge.pdf
    • http://cefasfese.4pu.com/1732730734734738/Far-from-Casual-by-Caroline-King.pdf
    • http://cefasfese.4pu.com/2738731732733/The-Dream-Endures-California-Enters-the-1940s-by-Kevin-Starr.pdf
    • http://cefasfese.4pu.com/6737732733733735/The-Modern-Builder-s-Guide-by-Minard-Lafever.pdf
    • http://cefasfese.4pu.com/4730731731732736/Murder-Grins-and-Bears-It-Gertie-Johnson-2-by-Deb-Baker.pdf
    • http://cefasfese.4pu.com/5736732731737738/Grandma-Gertie-s-Haunted-Handbag-by-Malorie-Blackman.pdf
    • http://cefasfese.4pu.com/2739732738735731/Murder-Grins-and-Bears-It-Gertie-Johnson-2-by-Deb-Baker.pdf
    • http://cefasfese.4pu.com/1738730735734732/Casual-Women-A-Short-Story-by-C-Michaels.pdf
    • http://cefasfese.4pu.com/1730738734736731738/SowHow-A-Modern-Guide-to-Grow-Your-Own-Veg-by-Paul-Matson.pdf