Malicious PDF — malware analysis report

Static analysis result for SHA-256 78aa5ec8deaa8ffe…

MALICIOUS

PDF

19.1 KB Created: 2019-05-01 05:26:18 +01:00 Authoring application: mPDF 5.7
MD5: 68974bcd15a94e7161311cd35738bf63 SHA-1: b986018843b3dabb7d0b8a98e27ccaf5a347b302 SHA-256: 78aa5ec8deaa8ffef10ca98dad66c69ade5878037054b0988af34675c9aa10ef
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm. While the ML classifier flagged this as malicious, the specific URLs extracted appear to be benign book titles. The primary attack pattern is likely SEO manipulation or a lure to potentially malicious content hosted on these domains. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1737737730733734/An-Heir-to-Spare-The-Brotherhood-Series-2-by-Lisa-Cooke.pdf
    • http://cefasfese.4pu.com/4730738733731738/The-Heir-and-the-Spare-Negligent-Chaperone-1-by-Maya-Rodale.pdf
    • http://cefasfese.4pu.com/4735731737739734/Manifesting-Your-Spirit-Way-Of-The-Warrior-Series-by-Graham-Cooke.pdf
    • http://cefasfese.4pu.com/6738736734730732/Wrightful-Heir-Wright-Series-Book-1-by-Arielle-Alia.pdf
    • http://cefasfese.4pu.com/8736737730733732/Lost-to-the-Night-The-Brotherhood-Series-1-by-Adele-Clee.pdf
    • http://cefasfese.4pu.com/7733739734732739/A-Present-for-a-Papist-Or-the-History-of-the-Life-of-Pope-Joan-taken-Mainly-from-A-Cooke-s-Pope-Joane-by-Alexander-Cooke.pdf
    • http://cefasfese.4pu.com/3732736737730730/The-Wizard-Heir-The-Heir-Chronicles-2-by-Cinda-Williams-Chima.pdf
    • http://cefasfese.4pu.com/3734731732732/The-Warrior-Heir-The-Heir-Chronicles-1-by-Cinda-Williams-Chima.pdf
    • http://cefasfese.4pu.com/3739731734732736/Addison-Cooke-and-the-Treasure-of-the-Incas-Addison-Cooke-1-by-Jonathan-W-Stokes.pdf
    • http://cefasfese.4pu.com/3738733730732738/Addison-Cooke-and-the-Tomb-of-Khan-Addison-Cooke-2-by-Jonathan-W-Stokes.pdf
    • http://cefasfese.4pu.com/1732732730734735/Immortal-Champion-Immortal-Brotherhood-3-by-Lisa-Hendrix.pdf
    • http://cefasfese.4pu.com/1732732730734739/Immortal-Defender-Immortal-Brotherhood-4-by-Lisa-Hendrix.pdf
    • http://cefasfese.4pu.com/8736733732738/The-Heir-Chronicles-Books-I-III-The-Heir-Chronicles-1-3-by-Cinda-Williams-Chima.pdf
    • http://cefasfese.4pu.com/3734730731734730/Who-Are-You-Again---Series-II-Do-You-Believe-by-Lisa-Goldin-Theunissen-.pdf
    • http://cefasfese.4pu.com/9738736731738738/The-Spellman-Series-Box-Set-1---4-The-Spellmans-1-4-by-Lisa-Lutz.pdf
    • http://cefasfese.4pu.com/1731735731733733735/The-Woyzeck-Spare-by-Sebastian-Rex.pdf
    • http://cefasfese.4pu.com/9732734732739/Articles-on-Enid-Blyton-Series-Including-The-Famous-Five-Series-the-Secret-Seven-Malory-Towers-the-Faraway-Tree-St-Clare-s-Series-the-Five-Find-Outers-the-Adventure-Series-the-Wishing-Chair-Series-the-Circus-Series-by-Hephaestus-Books.pdf
    • http://cefasfese.4pu.com/5731738736730730/Sweet-Glory-Civil-War-Series-1-by-Lisa-Y-Potocar.pdf
    • http://cefasfese.4pu.com/3732731732731737/Twice-upon-a-Time-The-Celtic-Legends-Series-1-by-Lisa-Ann-Verge.pdf
    • http://cefasfese.4pu.com/6734734738732731/The-Illumination-The-Awakening-Series-Book-4-by-Lisa-M-Lilly.pdf