Malicious PDF — malware analysis report

Static analysis result for SHA-256 810d8f15dbac86d0…

MALICIOUS

PDF

18.8 KB Created: 2019-11-21 12:47:23 +00:00 Authoring application: mPDF 5.7
MD5: af1a523dba44731710c967f27817b4b0 SHA-1: ef6a6cc592979da71cb704e06c69737af99ed6ff SHA-256: 810d8f15dbac86d016ed50c9398836850370f2e5ec18224b4ec9bb1683b7c3ce
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the primary function appears to be directing users to a vast collection of external PDF files, likely for SEO manipulation or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9754

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2730730738732733/Steel-Horse-Cowboy-The-Dirty-Denim-Series-by-Sidda-Lee-Rain.pdf
    • http://cefasfese.4pu.com/2730730735730733/Quick-on-the-Trigger-The-Dirty-Denim-Series-by-Sidda-Lee-Rain.pdf
    • http://cefasfese.4pu.com/2736737737737731/Talk-Dirty-to-Me-Cowboy-A-Deputy-Laney-Briggs-Novella-by-Jodi-Linton.pdf
    • http://cefasfese.4pu.com/1735737737737739/The-Horse-Lover-A-Cowboy-s-Quest-to-Save-the-Wild-Mustangs-by-H-Alan-Day.pdf
    • http://cefasfese.4pu.com/4732731737730737/Cowboy-The-Harmony-Series-1-by-Staci-Stallings.pdf
    • http://cefasfese.4pu.com/3737736733734735/Hail-Mary-Jim-Knighthorse-series-3-by-J-R-Rain.pdf
    • http://cefasfese.4pu.com/1737737735732735/Taken-on-the-Ranch-Complete-Cowboy-Erotica-Series-by-Kenzie-Haven.pdf
    • http://cefasfese.4pu.com/1737732734730735/Drifter-s-Heart-Cowboy-Fever-Series-6-by-Karen-Wiesner.pdf
    • http://cefasfese.4pu.com/5739734732737736/The-Last-Iron-Horse-The-Kingdom-of-Walden-Series-2-by-Kristan-Cannon.pdf
    • http://cefasfese.4pu.com/2739732739739734/Articles-on-Foundation-Universe-Books-Including-I-Robot-Foundation-s-Edge-the-Caves-of-Steel-Prelude-to-Foundation-Foundation-and-Earth-Foundation-Series-Isaac-Asimov-s-Robot-Series-Isaac-Asimov-s-Galactic-Empire-Series-by-Hephaestus-Books.pdf
    • http://cefasfese.4pu.com/2733736730730731/The-Toronto-Series-Bundle-Includes-the-novels-Dirty-Sweet-Everybody-Knows-this-is-Nowhere-and-Swap-by-John-McFetridge.pdf
    • http://cefasfese.4pu.com/1731735731734730732/Forty-Days-and-Forty-Nights-Rain-Rain-Rain-by-Joan-Gross.pdf
    • http://cefasfese.4pu.com/8739735738734734/Dirty-In-seiner-Gewalt-Dirty-Rich-amp-Thug-1-by-Sarah-Saxx.pdf
    • http://cefasfese.4pu.com/5731732739/Dirty-Filthy-Rich-Boys-Dirty-Duet-0-5-by-Laurelin-Paige.pdf
    • http://cefasfese.4pu.com/3733732736/Dirty-Love-Dirty-Girl-Duet-2-by-Meghan-March.pdf
    • http://cefasfese.4pu.com/7734733734732733/Good-Girls-Like-It-Dirty-Dirty-Debts-2-by-Carmen-Falcone.pdf
    • http://cefasfese.4pu.com/3734730730731731/Denim-And-Diamonds-by-Debbie-Macomber.pdf
    • http://cefasfese.4pu.com/2734736739737731/Denim-and-Lace-by-Patricia-Rice.pdf
    • http://cefasfese.4pu.com/1731730735735734737/Denim-A-Material-World-4-by-K-C-Wells.pdf
    • http://cefasfese.4pu.com/3736730/Dirty-Deeds-Dirty-Angels-2-by-Karina-Halle.pdf