Malicious PDF — malware analysis report

Static analysis result for SHA-256 6d10b5b7447d9322…

MALICIOUS

PDF

17.9 KB Created: 2019-05-03 23:20:57 +01:00 Authoring application: mPDF 5.7
MD5: d9b18e97c0b7e70abb0298dc767ed780 SHA-1: 5f220cc2c0c59bcdafe5988487f8de1e7f79a112 SHA-256: 6d10b5b7447d9322437064da6a2690d9b0af9601459252c4be7eceb063fd12f5
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be SEO spam or a redirection scheme to distribute content from numerous external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9735735738732730/The-Mother-Road-by-Jennifer-AlLee.pdf
    • http://cefasfese.4pu.com/9735736730733737/Curtain-Call-Charm-and-Deceit-3-by-Jennifer-AlLee.pdf
    • http://cefasfese.4pu.com/9735735738732731/A-Wild-Goose-Chase-Christmas-Quilts-of-Love-2-by-Jennifer-AlLee.pdf
    • http://cefasfese.4pu.com/4735733731736735/The-Mitchell-Family-Series-Box-Set-Mitchell-Family-1-4-5-by-Jennifer-Foor.pdf
    • http://cefasfese.4pu.com/4735737735731730/Losing-Him-Mitchell-Family-8-by-Jennifer-Foor.pdf
    • http://cefasfese.4pu.com/1732739732732730/Letting-Go-Mitchell-Family-1-by-Jennifer-Foor.pdf
    • http://cefasfese.4pu.com/8739735739732/Raging-Love-Mitchell-Family-3-by-Jennifer-Foor.pdf
    • http://cefasfese.4pu.com/2731739738730737/Blinding-Trust-Mitchell-Family-7-by-Jennifer-Foor.pdf
    • http://cefasfese.4pu.com/1730737739734732734/Joshua-The-Mitchell-Healy-Family-10-by-Jennifer-Foor.pdf
    • http://cefasfese.4pu.com/3737739739730734/One-Mother-s-Journey-Creating-My-Family-Through-in-Vitro-Fertilization-by-Jennifer-Prudenti.pdf
    • http://cefasfese.4pu.com/4731735737737730/My-Grandfather-Would-Have-Shot-Me-A-Black-Woman-Discovers-Her-Family-s-Nazi-Past-by-Jennifer-Teege.pdf
    • http://cefasfese.4pu.com/1735731731730737/The-House-by-Marjorie-Hill-Allee.pdf
    • http://cefasfese.4pu.com/9735736730733730/Chasing-His-Vampire-by-Tiffany-Allee.pdf
    • http://cefasfese.4pu.com/9735736730733738/Love-in-a-Black-Lagoon-Critter-Getter-3-by-Allee-Mae.pdf
    • http://cefasfese.4pu.com/9735735739735733/Claiming-Their-Royal-Mate-Part-One-by-Tiffany-Allee.pdf
    • http://cefasfese.4pu.com/9735736731732736/Allee-Effects-in-Ecology-and-Conservation-by-Franck-Courchamp.pdf
    • http://cefasfese.4pu.com/4738736739734735/Merry-Mitchell-Affair-The-Mitchell-Healy-Family-3-5-by-Jennifer-Foor.pdf
    • http://cefasfese.4pu.com/9735735738732735/Succubus-Lost-From-the-Files-of-the-Otherworlder-Enforcement-Agency-2-by-Tiffany-Allee.pdf
    • http://cefasfese.4pu.com/3732736739736730/Finding-Love-and-Bigfoot-the-Critter-Getter-Series-Book-2-by-Allee-Mae.pdf
    • http://cefasfese.4pu.com/1731736739730733732/Cinderella-s-Family-A-Feminist-View-of-Family-and-Matriarchy--From-Primate-to-22nd-Century-Family-by-B-Meinhardt.pdf