Malicious PDF — malware analysis report

Static analysis result for SHA-256 69793764972072fa…

MALICIOUS

PDF

13.7 KB Created: 2019-05-24 13:47:34 +01:00 Authoring application: mPDF 5.7
MD5: 9d229b5a5fe55af04f0594289bb7e7e7 SHA-1: 821f7797b5ad95af42c04410423bdd487dcde0a5 SHA-256: 69793764972072faeb6a8a5ffaed30090eb3e90e15d878e48a3959bef2cc981e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, indicative of a link farm or SEO spam campaign. While the URLs themselves are marked as benign, the sheer volume and the heuristic firing of PDF_SEO_LINK_FARM suggest a malicious intent to manipulate search engine results or redirect users to potentially harmful content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2734738739735733/The-Underworld-Rhyn-Eternal-4-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/3730736738736734/Gabriel-s-Hope-Rhyn-Eternal-1-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/2732730730736734/Darkyn-s-Mate-Rhyn-Eternal-3-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/1731735737733737/Katie-s-Hellion-Rhyn-Trilogy-1-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/3737736732732732/The-Rhyn-Trilogy-Rhyn-Trilogy-1-3-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/3737736732735738/Katie-s-Hellion-amp-Katie-s-Hope-Rhyn-Trilogy-1-2-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/1733735736738732/Star-Kissed-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/1738733739730735/The-Warlord-s-Secret-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/1738733738738734/A-Demon-s-Desire-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/1738733737734730/Mind-Caf-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/2735739735730733/Cursed-Voodoo-Nights-1-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/2737732731733738/Summer-Night-The-Witchling-1-5-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/8731737737736/Soldier-Mine-Sons-of-War-2-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/2735739730736732/Revealed-Starwalkers-Serial-4-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/7736733738734/Damian-s-Oracle-War-of-Gods-1-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/1738733738738730/Damian-s-Immortal-War-of-Gods-3-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/3731730733733734/Charred-Tears-Heart-of-Fire-2-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/1738733739730739/Kiera-s-Moon-The-Anshan-Saga-1-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/4735734731739730/Trial-by-Blood-Trial-Series-3-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/1738738737736739/Trial-by-Moon-Trial-Series-1-by-Lizzy-Ford.pdf