Malicious PDF — malware analysis report

Static analysis result for SHA-256 7c8d6db2d7d29161…

MALICIOUS

PDF

22.0 KB Created: 2019-06-04 10:27:52 +01:00 Authoring application: mPDF 5.7
MD5: 01e4deb8d1e43238cf8eb7fa69abb145 SHA-1: abdc6855756a40da862b31745615df68e385d880 SHA-256: 7c8d6db2d7d29161431d0acde8af9b0e7520fead2b9dee4a37ff108bb0a0bb11
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, forming a link farm. The primary heuristic identified this as a PDF_SEO_LINK_FARM, indicating a malicious intent to redirect users to external content. While the document body is heavily obfuscated, the presence of numerous links suggests a social engineering or redirection-based attack. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3733734739732731/The-Lord-Peter-Wimsey-Mysteries-Whose-Body-Clouds-of-Witness-and-Unnatural-Death-by-Dorothy-L-Sayers.pdf
    • http://cefasfese.4pu.com/3738735736733733/Your-Body-Believes-Every-Word-You-Say-The-Language-of-the-Body-Mind-Connection-by-Barbara-Hoberman-Levine.pdf
    • http://cefasfese.4pu.com/3736736736735739/Five-Good-Minutes-in-Your-Body-100-Mindful-Practices-to-Help-You-Accept-Yourself-and-Feel-at-Home-in-Your-Body-by-Jeffrey-Brantley.pdf
    • http://cefasfese.4pu.com/4731735730734735/The-Body-Has-a-Mind-of-Its-Own-How-Body-Maps-in-Your-Brain-Help-You-Do-Almost-Everything-Better-by-Sandra-Blakeslee.pdf
    • http://cefasfese.4pu.com/1737733735733736/My-Body-Mine-My-Body-Trilogy-3-by-Blakely-Bennett.pdf
    • http://cefasfese.4pu.com/4733732731736732/3-Men-And-A-Body-Body-Movers-3-by-Stephanie-Bond.pdf
    • http://cefasfese.4pu.com/1735739730735735/My-Body-His-My-Body-Trilogy-1-by-Blakely-Bennett.pdf
    • http://cefasfese.4pu.com/4737731737733736/Home-Dairy-with-Ashley-English-All-You-Need-to-Know-to-Make-Cheese-Yogurt-Butter-amp-More-by-Ashley-English.pdf
    • http://cefasfese.4pu.com/8732737731735735/Body-Mind-and-Sport-The-Mind-Body-Guide-to-Lifelong-Health-Fitness-and-Your-Personal-Best-by-John-Douillard.pdf
    • http://cefasfese.4pu.com/8732737735734/Clouds-by-Aristophanes.pdf
    • http://cefasfese.4pu.com/5739738734733737/Fat-Loss-Strategy-Little-Dirty-Secrets-and-Weird-Tricks-to-Massive-Fat-Loss-and-Sexy-Drooling-Body-Lose-the-Fat-Take-Control-of-Your-Body-Look-Like-Descendant-of-the-Roman-Gods-by-Jeff-Sandorf.pdf
    • http://cefasfese.4pu.com/5731737737730738/The-Clouds-in-Memphis-by-C-J-Hribal.pdf
    • http://cefasfese.4pu.com/3739736732735738/Just-Under-the-Clouds-by-Melissa-Sarno.pdf
    • http://cefasfese.4pu.com/1730735739731732/Clouds-End-by-Sean-Stewart.pdf
    • http://cefasfese.4pu.com/5730735736737731/The-Clouds-Above-by-Jordan-Crane.pdf
    • http://cefasfese.4pu.com/4735738732735732/Beyond-the-Clouds-by-Amanda-Lee-Psket.pdf
    • http://cefasfese.4pu.com/4733739737734/The-Invention-of-Clouds-by-Richard-Hamblyn.pdf
    • http://cefasfese.4pu.com/8732734739731/Ketchup-Clouds-by-Annabel-Pitcher.pdf
    • http://cefasfese.4pu.com/9733737737732731/Hidden-in-the-Clouds-by-Kathleen-Odenthal.pdf
    • http://cefasfese.4pu.com/2735734731731739/The-Princess-in-the-Clouds-by-Steve-Valiquette.pdf
    • http://cefasfese.4pu.com/4731735730734735/The-Bod