Malicious PDF — malware analysis report

Static analysis result for SHA-256 76890c1f3a364f44…

MALICIOUS

PDF

16.5 KB Created: 2019-06-10 05:01:45 +01:00 Authoring application: mPDF 5.7
MD5: 2bb7ba3e58695e4a31fc6be80980bf7e SHA-1: 6e813da41a89e7fa06da618c780128816ee23145 SHA-256: 76890c1f3a364f443ac47b475423b353811d5da7c52c65325fceb607aadfa833
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently classified as benign, the sheer volume and the heuristic firing of PDF_SEO_LINK_FARM suggest a malicious intent, likely to manipulate search engine results or redirect users to potentially harmful content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5737733735738/The-Art-of-Losing-Yourself-by-Katie-Ganshert.pdf
    • http://cefasfese.4pu.com/2730734732733/Wishing-on-Willows-by-Katie-Ganshert.pdf
    • http://cefasfese.4pu.com/5730734736732736/She-Asked-for-It-She-Asked-for-It-1-by-Willow-Winters.pdf
    • http://cefasfese.4pu.com/3737736732735738/Katie-s-Hellion-amp-Katie-s-Hope-Rhyn-Trilogy-1-2-by-Lizzy-Ford.pdf
    • http://cefasfese.4pu.com/2737739731736/If-I-Asked-You-Would-You-Stay-by-Eve-Bunting.pdf
    • http://cefasfese.4pu.com/7731732730735737/Asked-For-by-Colleen-L-Donnelly.pdf
    • http://cefasfese.4pu.com/4730730738732/Nobody-Asked-Me-But-by-Karl-Wiggins.pdf
    • http://cefasfese.4pu.com/2732733738732739/Questions-I-Asked-My-Mother-by-Di-Brandt.pdf
    • http://cefasfese.4pu.com/4738730732733730/The-Life-I-Never-Asked-For-by-Kira-Adams.pdf
    • http://cefasfese.4pu.com/4732737733738733/You-Asked-for-Perfect-by-Laura-Silverman.pdf
    • http://cefasfese.4pu.com/3735737739737736/We-Never-Asked-for-Wings-by-Vanessa-Diffenbaugh.pdf
    • http://cefasfese.4pu.com/3731732731/My-Grandmother-Asked-Me-to-Tell-You-She-s-Sorry-by-Fredrik-Backman.pdf
    • http://cefasfese.4pu.com/6738739737730733/Hope-for-Laodicea-I-Have-Asked-God-by-Valerie-A-Beauchene.pdf
    • http://cefasfese.4pu.com/1731738731739732731/MTV-458-Success-Secrets---458-Most-Asked-Questions-on-MTV---What-You-Need-to-Know-by-Kevin-Jackson.pdf
    • http://cefasfese.4pu.com/4739731730736739/Are-All-Women-Leg-Spinners-asked-the-Stephanian-by-Anurag-Mathur.pdf
    • http://cefasfese.4pu.com/5732739731737739/Not-That-You-Asked-Rants-Exploits-and-Obsessions-by-Steve-Almond.pdf
    • http://cefasfese.4pu.com/1730739736732734730/Katie-and-the-Mustang-Book-3-Hoofbeats-Katie-and-the-Mustang-3-by-Kathleen-Duey.pdf
    • http://cefasfese.4pu.com/8731739739733/I-Never-Asked-You-to-Save-Me-Wakefield-Romance-3-by-Theresa-Marguerite-Hewitt.pdf
    • http://cefasfese.4pu.com/3738735734739739/What-Was-Asked-of-Us-An-Oral-History-of-the-Iraq-War-by-the-Soldiers-Who-Fought-It-by-Trish-Wood.pdf
    • http://cefasfese.4pu.com/2734739736733730/Buried-Memories-Katie-Beers-Story-by-Katie-Beers.pdf