Malicious PDF — malware analysis report

Static analysis result for SHA-256 679963f443893cad…

MALICIOUS

PDF

17.4 KB Created: 2019-04-30 09:36:18 +01:00 Authoring application: mPDF 5.7
MD5: e3d997fc71f904ee1cbc52feb81a30a8 SHA-1: 763f3fd819818cce52516d84a699cbf65ca04742 SHA-256: 679963f443893cad1acb9186f4774d00f50c5d2312037d8d53a7c0b0d138efee
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the 'PDF_SEO_LINK_FARM' heuristic, which are presented as book titles. These links likely lead to malicious websites or phishing pages. While no scripts were explicitly extracted, the nature of the embedded links suggests a potential for JavaScript execution within the PDF to facilitate the redirection or further malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1734738733730730/Drew-Fable-Forever-One-Week-Girlfriend-3-5-by-Monica-Murphy.pdf
    • http://cefasfese.4pu.com/8736738732/You-Promised-Me-Forever-Forever-Yours-1-by-Monica-Murphy.pdf
    • http://cefasfese.4pu.com/4732736734733736/Nothing-Without-You-Forever-Yours-1-5-Big-Sky-3-4-by-Monica-Murphy.pdf
    • http://cefasfese.4pu.com/5735738737733/Forever-Friends-3-by-Monica-Murphy.pdf
    • http://cefasfese.4pu.com/3738732734731731/Never-Tear-Us-Apart-Never-1-by-Monica-Murphy.pdf
    • http://cefasfese.4pu.com/2734738733/Never-Tear-Us-Apart-Never-1-by-Monica-Murphy.pdf
    • http://cefasfese.4pu.com/7730738731734/One-Night-Friends-0-5-by-Monica-Murphy.pdf
    • http://cefasfese.4pu.com/3739732731731732/Her-Destiny-Reverie-2-by-Monica-Murphy.pdf
    • http://cefasfese.4pu.com/2735733737733730/Her-Defiant-Heart-Damaged-Hearts-1-by-Monica-Murphy.pdf
    • http://cefasfese.4pu.com/4735731739731734/Crave-Billionaire-Bachelors-Club-1-by-Monica-Murphy.pdf
    • http://cefasfese.4pu.com/1733739732/Taming-Lily-The-Fowler-Sisters-3-by-Monica-Murphy.pdf
    • http://cefasfese.4pu.com/3734735739730737/Stealing-Rose-The-Fowler-Sisters-2-by-Monica-Murphy.pdf
    • http://cefasfese.4pu.com/1730732738735731738/The-Disco-Files-1973-78-New-York-s-Underground-Week-by-Week-by-Vince-Aletti.pdf
    • http://cefasfese.4pu.com/4736732731739730/The-List-A-Week-by-Week-Reckoning-of-Trump-s-First-Year-by-Amy-Siskind.pdf
    • http://cefasfese.4pu.com/9735732733736737/Spelling-Demons-Week-by-Week-by-Elizabeth-Hagner.pdf
    • http://cefasfese.4pu.com/1730738737738735731/Dutch-and-Gina-The-President-s-Girlfriend-The-President-s-Girlfriend-1-by-Mallory-Monroe.pdf
    • http://cefasfese.4pu.com/8733733738739730/Your-Pregnancy-Week-by-Week-by-Glade-B-Curtis.pdf
    • http://cefasfese.4pu.com/6738733731737736/One-Year-to-an-Organized-Life-From-Your-Closets-to-Your-Finances-the-Week-by-Week-Guide-to-Getting-Completely-Organized-for-Good-by-Regina-Leeds.pdf
    • http://cefasfese.4pu.com/2733736735739736/Monica-Speaks-Genuine-Pearls-of-Wisdom-from-America-s-Most-Famous-White-House-Intern-by-Monica-Lewinsky.pdf
    • http://cefasfese.4pu.com/7737734734731730/Andrew-Drew-and-Drew-by-Barney-Saltzberg.pdf