Malicious PDF — malware analysis report

Static analysis result for SHA-256 7a9f5882289bdbed…

MALICIOUS

PDF

15.9 KB Created: 2019-05-04 10:32:15 +01:00 Authoring application: mPDF 5.7
MD5: a7ac08f92537d91090c353bc732bb06d SHA-1: 775d006a2ec0935cbea295716d20b8015754051e SHA-256: 7a9f5882289bdbeda49edc72d473eb3117f10c5f3010bdbb89e31aab91c641b7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file was flagged by a machine learning classifier and exhibits a critical heuristic for containing a large number of external links, suggesting a link farm or SEO abuse. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic indicate a malicious intent, likely to redirect users to malicious content or for search engine manipulation. The embedded URLs are reconstructed from the document body.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9800

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8732738735733735/Summary-amp-Study-Guide-Live-By-Night-by-Dennis-Lehane-by-BookRags.pdf
    • http://cefasfese.4pu.com/8732738734731730/Dennis-Lehane-Collection-Sacred-Gone-Baby-Gone-Prayers-for-Rain-by-Dennis-Lehane.pdf
    • http://cefasfese.4pu.com/1738736739737734/The-Given-Day-by-Dennis-Lehane.pdf
    • http://cefasfese.4pu.com/4731735739731738/Since-We-Fell-by-Dennis-Lehane.pdf
    • http://cefasfese.4pu.com/3737735737739/The-Given-Day-Coughlin-1-by-Dennis-Lehane.pdf
    • http://cefasfese.4pu.com/4736735736730738/Mystic-River-by-Dennis-Lehane.pdf
    • http://cefasfese.4pu.com/6731732730731738/Boston-Noir-by-Dennis-Lehane.pdf
    • http://cefasfese.4pu.com/4736737731734739/Shutter-Island-by-Dennis-Lehane.pdf
    • http://cefasfese.4pu.com/3735731739738735/Mystic-River-by-Dennis-Lehane.pdf
    • http://cefasfese.4pu.com/4733731737731/Sacred-Kenzie-amp-Gennaro-3-by-Dennis-Lehane.pdf
    • http://cefasfese.4pu.com/3734732735730736/Gone-baby-gone-Kenzie-and-Gennaro-4-by-Dennis-Lehane.pdf
    • http://cefasfese.4pu.com/2735730738734731/A-Drink-Before-the-War-Kenzie-amp-Gennaro-1-by-Dennis-Lehane.pdf
    • http://cefasfese.4pu.com/2732732733731738/Darkness-Take-My-Hand-Kenzie-amp-Gennaro-2-by-Dennis-Lehane.pdf
    • http://cefasfese.4pu.com/1734730736738732/Live-from-New-York-An-Oral-History-of-Saturday-Night-Live-by-James-Andrew-Miller.pdf
    • http://cefasfese.4pu.com/3735737737738733/Saturday-Night-A-Backstage-History-of-Saturday-Night-Live-by-Doug-Hill.pdf
    • http://cefasfese.4pu.com/3739732730735730/Once-Upon-a-Winter-s-Night-Faery-1-by-Dennis-L-McKiernan.pdf
    • http://cefasfese.4pu.com/2732738736739/Song-for-a-Summer-Night-by-Mark-Dennis.pdf
    • http://cefasfese.4pu.com/3735736739737737/Saturday-Night-Live-The-Book-by-Alison-Castle.pdf
    • http://cefasfese.4pu.com/5734739735739736/Live-Longer-Live-Younger-The-10-Step-Programme-to-Healthy-Ageing-by-Rajendra-Sharma.pdf
    • http://cefasfese.4pu.com/1731737739731730733/Plan-to-Live-Forever-Get-Better-with-Age-Live-a-Life-You-Love-and-Leave-a-Lasting-Legacy-by-Jonathon-C-Leise.pdf
    • http://cefasfese.4pu.com/2732732733731738/Darkness-Take-My-Hand