Malicious PDF — malware analysis report

Static analysis result for SHA-256 65791ea2a5d92dd0…

MALICIOUS

PDF

17.1 KB Created: 2019-08-02 07:37:44 +01:00 Authoring application: mPDF 5.7
MD5: f34ecab1fa35d84dd1e4a4d2956b1ce6 SHA-1: d3a91ab028c21ee36cc9194abdd12907622207da SHA-256: 65791ea2a5d92dd00684313193029f8a225969b14f71a21d51eec603e73f368d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently classified as benign, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content. No scripts were extracted, limiting further analysis of the file's direct actions.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731731737739739733/Daenyathos-Soul-Drinkers-7-by-Ben-Counter.pdf
    • http://cefasfese.4pu.com/1731731737739734734/Hellforged-Soul-Drinkers-5-by-Ben-Counter.pdf
    • http://cefasfese.4pu.com/1731731737739732733/Soul-Drinker-Soul-Drinkers-1-by-Ben-Counter.pdf
    • http://cefasfese.4pu.com/1731731737739735730/Crimson-Tears-Soul-Drinkers-3-by-Ben-Counter.pdf
    • http://cefasfese.4pu.com/3731739731734736/The-Cat-and-the-Coffee-Drinkers-by-Max-Steele.pdf
    • http://cefasfese.4pu.com/1730731731734730/Drinkers-of-the-Wind-by-Carl-Raswan.pdf
    • http://cefasfese.4pu.com/3734735734732731/Soul-Whispers-II-Secret-Alchemy-of-the-Elements-in-Soul-Coaching-Soul-Whispers-2-by-Denise-Linn.pdf
    • http://cefasfese.4pu.com/5731731737737730/Young-Soul-Rebels-A-Personal-History-of-Northern-Soul-by-Stuart-Cosgrove.pdf
    • http://cefasfese.4pu.com/6732739736736730/Unchain-Your-Soul-Through-Mago-s-Dream-Communing-with-the-Earth-s-Soul-by-Ilchi-Lee.pdf
    • http://cefasfese.4pu.com/9735737731738734/Soul-Mastery-Accessing-the-Gifts-of-Your-Soul-by-Susann-Taylor-Shier.pdf
    • http://cefasfese.4pu.com/2734733733732734/Soul-of-the-Forgotten-Love-Heart-amp-Soul-10-by-Angela-Verdenius.pdf
    • http://cefasfese.4pu.com/1736733730731734/Soul-of-a-Witch-Love-Heart-amp-Soul-8-by-Angela-Verdenius.pdf
    • http://cefasfese.4pu.com/6734738734737733/Chocolate-amp-Diamonds-for-the-Woman-s-Soul-Timeless-Treasures-to-Warm-the-Heart-and-Sooth-the-Soul-by-Carla-Wynn-Hall.pdf
    • http://cefasfese.4pu.com/2732738737738732/Soul-s-Perfection-Journey-of-the-Soul-2-by-Sylvia-Browne.pdf
    • http://cefasfese.4pu.com/1738732732733730/Eyes-of-the-Soul-Soul-Seers-2-by-Rene-Folsom.pdf
    • http://cefasfese.4pu.com/5730730739734730/Soul-Betrayal-Soul-Trilogy-2-by-Leanore-Elliott.pdf
    • http://cefasfese.4pu.com/1738737739734730/Truths-of-the-Soul-Soul-Seers-3-by-Rene-Folsom.pdf
    • http://cefasfese.4pu.com/3731739730733732/Soul-Sucker-Soul-Justice-1-by-Kate-Pearce.pdf
    • http://cefasfese.4pu.com/4730733737733/My-Soul-to-Lose-Soul-Screamers-0-5-by-Rachel-Vincent.pdf
    • http://cefasfese.4pu.com/3733737737733730/The-Guardian-Of-My-Soul-Soul-s-Desire-1-by-Emily-A-Lawrence.pdf