Malicious PDF — malware analysis report

Static analysis result for SHA-256 807c6ad392223f63…

MALICIOUS

PDF

25.0 KB Created: 2019-05-02 06:50:11 +01:00 Authoring application: mPDF 5.7
MD5: 20a3a0bdc7f202faa828797f3e8fc1d0 SHA-1: 6941d9c35bb363d9dd12df3a60cf6feb3c504f95 SHA-256: 807c6ad392223f6364ae92dd1e389eab36fda095eb3c6450b8505035e9ea247c
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various book titles. While the URLs themselves are currently marked as benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely to redirect users to malicious content or download further payloads. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9727

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731734739732736735/Kodiak-Point-Anthology-1-3-Shapeshifter-Paranormal-Romance-by-Eve-Langlais.pdf
    • http://cefasfese.4pu.com/9738738739739731/BBW-SHIFTER-ROMANCE-PARANORMAL-SHAPESHIFTER-ROMANCE-Wolf-Shifter-The-Protector-Paranormal-Alpha-Male-Suspense-Romance-Werewolf-Fantasy-Romance-Short-Stories-by-Jenny-Wildner.pdf
    • http://cefasfese.4pu.com/9738738739734738/BBW-DRAGON-SHIFTER-ROMANCE-WOLF-SHIFTER-ROMANCE-Wife-Me-Dragon-Paranormal-Alpha-Male-Shapeshifter-Romance-Werewolf-Devil-Vampire-Shifter-Romance-Short-Stories-by-Jenny-Wildner.pdf
    • http://cefasfese.4pu.com/1737737736739737/Shapeshifter-Romance-Saved-by-the-Tiger-SEAL-Paranormal-BBW-Shifter-Army-Navy-Seal-Protector-Romance-Fantasy-Urban-Military-Adventure-Older-Man-Short-Stories-by-J-K-Hudson.pdf
    • http://cefasfese.4pu.com/4733733739737730/Mystical-Xmas-Paranormal-Romance-Anthology-Box-Set-1-by-P-T-Macias.pdf
    • http://cefasfese.4pu.com/9730731730737732/Hunted-in-Wolfen-Wood-A-BBW-Paranormal-Shape-Shifter-Romance-Wolfen-Wood-Paranormal-Romance-Series-Book-2-by-Megan-Tisdale.pdf
    • http://cefasfese.4pu.com/3737737730737737/Croc-s-Return-Bitten-Point-1-by-Eve-Langlais.pdf
    • http://cefasfese.4pu.com/4738734732733730/ROMANCE-SHIFTER-ROMANCE-Knocked-Up-By-The-Navy-Shifter-Navy-Seal-Pregnancy-Alpha-Male-Romance-Paranormal-Fantasy-Protector-Short-Stories-by-Silvia-Pierce.pdf
    • http://cefasfese.4pu.com/1731734739733731732/Kodiak-A-Picture-Book-about-the-Amazing-Kodiak-Bear-by-E-T-Aardentee.pdf
    • http://cefasfese.4pu.com/1731734739733732736/From-Humboldt-to-Kodiak-Recollections-of-a-Frontier-Childhood-and-the-Founding-of-the-First-American-School-and-the-Baptist-Mission-at-Kodiak-Alaska-by-Frederic-Roscoe.pdf
    • http://cefasfese.4pu.com/4735738737738734/Paranormal-Anthology-with-a-Twist-by-Cynthia-Shepp.pdf
    • http://cefasfese.4pu.com/3733732735730739/Paranormal-Holiday-Anthology-Trio-by-Nalini-Singh.pdf
    • http://cefasfese.4pu.com/4735739738732737/Paranormal-Romance-by-Yaritza-Garcia.pdf
    • http://cefasfese.4pu.com/4736734733737732/Space-Junque-A-Paranormal-Romance-by-L-K-Rigel.pdf
    • http://cefasfese.4pu.com/4732737735738737/Soldier-Bears-Box-Set-BBW-Paranormal-Romance-by-Terry-Bolryder.pdf
    • http://cefasfese.4pu.com/1738738738730734/In-Each-Other-s-Embrace-Erotic-Paranormal-Romance-by-Sandra-Ross.pdf
    • http://cefasfese.4pu.com/1731737739737736730/Werebears-Of-The-Everglades-A-Paranormal-Romance-Collection-by-Meg-Ripley.pdf
    • http://cefasfese.4pu.com/2734730733731730/The-Mammoth-Book-Of-Paranormal-Romance-2-by-Trisha-Telep.pdf
    • http://cefasfese.4pu.com/1731731739730732737/Deadly-Sins-Box-Set-Paranormal-Romance-Collection-by-Andris-Bear.pdf
    • http://cefasfese.4pu.com/6734734739732735/Wolf-Cabin-Werewolf-Paranormal-Romance-by-Annelise-Arden.pdf