Malicious PDF — malware analysis report

Static analysis result for SHA-256 7b09b2817fb6f9fb…

MALICIOUS

PDF

18.7 KB Created: 2019-05-03 05:32:29 +01:00 Authoring application: mPDF 5.7
MD5: dba8867d8c59b8d7e24be6a04e865722 SHA-1: 467e068ccf82903b7ae1be532718d39f0dd49c76 SHA-256: 7b09b2817fb6f9fbe2db3569d54d7efdae60615f004bf3c6e50d9cac2fd36e19
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. While the specific content of the PDF is obfuscated, the heuristic 'PDF_SEO_LINK_FARM' indicates a pattern of generating numerous external links, likely to distribute malicious content or engage in SEO manipulation. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8730735736730735/Secrets-of-the-Afro-Comb-by-K-N-Chimbiri.pdf
    • http://cefasfese.4pu.com/4738730738733735/I-Don-t-Want-to-Comb-My-Hair-by-Tony-Ross.pdf
    • http://cefasfese.4pu.com/8730735736730738/The-Joy-of-Cooking-Comb-Bound-Edition-by-Irma-S-Rombauer.pdf
    • http://cefasfese.4pu.com/1734739735733735/Comb-Ridge-and-Its-People-The-Ethnohistory-of-a-Rock-by-Robert-S-McPherson.pdf
    • http://cefasfese.4pu.com/8730735736730736/Goodnight-Moon-Board-Book-Comb-and-Brush-Set-by-Margaret-Wise-Brown.pdf
    • http://cefasfese.4pu.com/8730739731732733/Afro-Orientalism-by-Bill-V-Mullen.pdf
    • http://cefasfese.4pu.com/7730735737734730/Laid-Back-Camp-Vol-1-by-Afro.pdf
    • http://cefasfese.4pu.com/1730735733735739736/Capoeira-The-History-of-an-Afro-Brazilian-Martial-Art-by-Matthias-Rohrig-Assuncao.pdf
    • http://cefasfese.4pu.com/1738735732730734/The-River-That-Gave-Gifts-An-Afro-American-Story-by-Margo-Humphrey.pdf
    • http://cefasfese.4pu.com/1730735733735739733/Capoeira-The-History-of-an-Afro-Brazilian-Martial-Art-by-Matthias-Rohrig-Assunccao.pdf
    • http://cefasfese.4pu.com/4733737735732738/Flash-of-the-Spirit-African-amp-Afro-American-Art-amp-Philosophy-by-Robert-Farris-Thompson.pdf
    • http://cefasfese.4pu.com/6736735733739732/Ubuntu-Peacebuilding-An-Afro-Christian-Perspective-African-Perspectives-of-Reconciliation-Book-1-by-Fidele-Lumeya.pdf
    • http://cefasfese.4pu.com/7732735739733730/Afro-Latin-s-in-Movement-Critical-Approaches-to-Blackness-and-Transnationalism-in-the-Americas-by-Petra-R-Rivera-Rideau.pdf
    • http://cefasfese.4pu.com/1730738739738735733/Warwolves-of-the-Iron-Cross-Black-Wolf-White-Reich-An-Afro-German-Family-in-Nazi-Germany-Wehrwolf-Book-6-by-V-K-Clark.pdf
    • http://cefasfese.4pu.com/1738733736731732/Stepbrother-Secrets-The-Monroe-Family-Secrets-Book-1-by-Lauren-Branford.pdf
    • http://cefasfese.4pu.com/1738732732734731/Deadly-Secrets-The-Secrets-Saga-2-by-Angee-Taylor.pdf
    • http://cefasfese.4pu.com/1738731739734737/Hidden-Secrets-The-Secrets-Saga-1-by-Angee-Taylor.pdf
    • http://cefasfese.4pu.com/3735733730732736/Secrets-and-High-Spirits-Secrets-4-by-Lou-Harper.pdf
    • http://cefasfese.4pu.com/4732731736738733/The-Secrets-of-the-Montebellis-Secrets-1-by-Cheryl-Colwell.pdf
    • http://cefasfese.4pu.com/7737737731731738/Alluring-Secrets-Secrets-2-by-Lynne-Connolly.pdf