Malicious PDF — malware analysis report

Static analysis result for SHA-256 6459f3c3b7ed7f00…

MALICIOUS

PDF

29.7 KB Created: 2019-09-27 13:24:33 +01:00 Authoring application: mPDF 5.7
MD5: f24c04149127ec5c05014e00e374d8da SHA-1: 7a8d98d5207403fd066646d1ef7e18b26e38b7bc SHA-256: 6459f3c3b7ed7f00c006d66a29ce483dabfcf5c47e359a5df961b901cae2436d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDFs, identified as a link farm. The ML classifier also flagged the document as malicious. While no scripts were extracted, the structure and embedded URLs suggest a campaign to drive traffic to potentially malicious content or to distribute further payloads disguised as book downloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9670

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2737734736/How-to-Have-a-Good-Day-Harness-the-Power-of-Behavioral-Science-to-Transform-Your-Working-Life-by-Caroline-Webb.pdf
    • http://cefasfese.4pu.com/6731739735732730/Working-with-Meditation-Practical-Ways-to-Heal-and-Transform-Your-Life-by-Madonna-Gauding.pdf
    • http://cefasfese.4pu.com/2732732738730735/Woman-Power-Transform-Your-Man-Your-Marriage-Your-Life-by-Laura-Schlessinger.pdf
    • http://cefasfese.4pu.com/1730736730736739738/Hypno-Health-How-to-Transform-Your-Life-Through-the-Power-of-Self-Hypnosis-by-Robert-Farago.pdf
    • http://cefasfese.4pu.com/2737734739735739/Enlightenment-to-Go-Shantideva-and-the-Power-of-Compassion-to-Transform-Your-Life-by-David-Michie.pdf
    • http://cefasfese.4pu.com/2732732738738734/Thank-God-for-Evolution-How-the-Marriage-of-Science-and-Religion-Will-Transform-Your-Life-and-Our-World-by-Michael-Dowd.pdf
    • http://cefasfese.4pu.com/1731736731730736737/The-Power-of-Impossible-Thinking-Transform-the-Business-of-Your-Life-and-the-Life-of-Your-Business-With-CDROM-by-Yoram-Jerry-Wind.pdf
    • http://cefasfese.4pu.com/4739733731731731/Journey-Into-Power-How-to-Sculpt-Your-Ideal-Body-Free-Your-True-Self-and-Transform-Your-Life-with-Yoga-by-Baron-Baptiste.pdf
    • http://cefasfese.4pu.com/3733733730733731/The-Power-of-Fifty-Bits-The-New-Science-of-Turning-Good-Intentions-into-Positive-Results-by-Bob-Nease.pdf
    • http://cefasfese.4pu.com/1731735732730730739/The-Science-of-Getting-Rich-How-to-Think-How-to-Act-and-What-to-Do-to-Harness-Your-Creative-Potential-by-Wallace-D-Wattles.pdf
    • http://cefasfese.4pu.com/1739730732737739/The-Next-Wave-The-Quest-to-Harness-the-Power-of-the-Oceans-by-Elizabeth-Rusch.pdf
    • http://cefasfese.4pu.com/1731736733735730731/Born-to-Be-Good-The-Science-of-a-Meaningful-Life-by-Dacher-Keltner.pdf
    • http://cefasfese.4pu.com/1730731733738731731/The-Irresistible-Introvert-Harness-the-Power-of-Quiet-Charisma-in-a-Loud-World-by-Michaela-Chung.pdf
    • http://cefasfese.4pu.com/7736730732738/Mind-Power-Into-the-21st-Century-Techniques-to-Harness-the-Astounding-Powers-of-Thought-by-John-Kehoe.pdf
    • http://cefasfese.4pu.com/4733738736735734/Healing-Companions-Ordinary-Dogs-and-Their-Extraordinary-Power-to-Transform-Lives-by-Jane-Miller.pdf
    • http://cefasfese.4pu.com/8734735735738737/Sacred-Stories-A-Celebration-Of-The-Power-Of-Story-To-Transform-And-Heal-by-Charles-Hare-Simpkinson.pdf
    • http://cefasfese.4pu.com/2735737739737730/Power-Faces-of-Evil-3-by-Debra-Webb.pdf
    • http://cefasfese.4pu.com/1738734737730730/Change-Friendly-Leadership-How-to-Transform-Good-Intentions-Into-Great-Performance-by-Rodger-Dean-Duncan.pdf
    • http://cefasfese.4pu.com/6731735733734731/Matthew-Scriven-s-Little-Book-of-Online-Marketing-Secrets-Harness-the-Power-of-the-Internet-to-Boost-Your-Profits-by-Matthew-Scriven.pdf
    • http://cefasfese.4pu.com/3734735734732735/Overcoming-Depression-One-Step-at-a-Time-The-New-Behavioral-Activation-Approach-to-Getting-Your-Life-Back-by-Michael-E-Addis.pdf