Malicious PDF — malware analysis report

Static analysis result for SHA-256 817d61d46a08d3f9…

MALICIOUS

PDF

20.6 KB Created: 2019-05-01 05:09:24 +01:00 Authoring application: mPDF 5.7
MD5: 216a66671cc2a82336c3fec841a5187c SHA-1: 28c7d3f2ff231529a8c1f69e1542a579dac9c8eb SHA-256: 817d61d46a08d3f910b77ddba057737b6be1c7bcced242f89029e12866c96a4b
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves appear to point to benign book titles, the sheer volume and the heuristic's classification suggest a malicious intent, possibly for SEO poisoning or to direct users to a malicious site. The ML classifier also flagged the document as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3733733736737735/Peanut-Butter-and-Jelly-A-Narwhal-and-Jelly-Book-3-by-Ben-Clanton.pdf
    • http://cefasfese.4pu.com/2733736738739/Narwhal-Unicorn-of-the-Sea-A-Narwhal-and-Jelly-Book-1-by-Ben-Clanton.pdf
    • http://cefasfese.4pu.com/4732736736730731/Jelly-s-Blues-The-Life-Music-And-Redemption-Of-Jelly-Roll-Morton-by-Howard-Reich.pdf
    • http://cefasfese.4pu.com/4739736737738736/Jelly-s-Blues-The-Life-Music-and-Redemption-of-Jelly-Roll-Morton-by-Howard-Reich.pdf
    • http://cefasfese.4pu.com/3735737733737735/Jelly-Beans-in-Life-Book-1-by-Sig-Schmalhofer.pdf
    • http://cefasfese.4pu.com/1734739736732/Jelly-Roll-by-Kevin-Young.pdf
    • http://cefasfese.4pu.com/1735730739735734/How-Many-Jelly-Beans-by-Andrea-Menotti.pdf
    • http://cefasfese.4pu.com/1731734731730731738/The-Jelly-Bean-by-F-Scott-Fitzgerald.pdf
    • http://cefasfese.4pu.com/1731733736738732737/Red-Rockets-and-Rainbow-Jelly-by-Sue-Heap.pdf
    • http://cefasfese.4pu.com/4731731739738732/Jam-and-Jelly-by-Holly-and-Nellie-by-Gloria-Whelan.pdf
    • http://cefasfese.4pu.com/1738731734736732/Jelly-Belly-by-Robert-Kimmel-Smith.pdf
    • http://cefasfese.4pu.com/6737734731731/The-Voluptuous-Delights-of-Peanut-Butter-and-Jam-by-Lauren-Liebenberg.pdf
    • http://cefasfese.4pu.com/2730732733733738/Just-Jelly-Beans-and-Jealousy-The-Reed-Brothers-2-5-by-Tammy-Falkner.pdf
    • http://cefasfese.4pu.com/5737733737731730/Fancy-Nancy-Peanut-Butter-and-Jellyfish-by-Jane-O-39-Connor.pdf
    • http://cefasfese.4pu.com/4734735732731733/My-Estonia-Passport-Forgery-Meat-Jelly-Eaters-And-Other-Stories-Minu-13-by-Justin-Petrone.pdf
    • http://cefasfese.4pu.com/2735732738731733/The-Last-Book-in-the-World-The-Travels-of-Jonathan-Butter-the-Greatest-Character-the-World-Has-Ever-Seen-by-Jonathan-Butter.pdf
    • http://cefasfese.4pu.com/5736738736737731/Zeldapedia---The-Legend-of-Zelda-The-Wind-Waker-Locations-Angular-Isles-Aryll-s-Lookout-Beedle-s-Shop-Ship-Bird-s-Peak-Rock-Boating-Course-Bomb-Island-Bomb-Shop-C-C-Cold-Island-Cabana-Cafe-Bar-Chu-Jelly-Juice-Shop-Cliff-Plateau-Isles-Cres-by-Source-Wikia.pdf
    • http://cefasfese.4pu.com/3735733738737/The-Butter-Battle-Book-by-Dr-Seuss.pdf
    • http://cefasfese.4pu.com/1730734731732736731/From-Grass-to-Butter-Start-to-Finish-Book-by-Ali-Mitgutsch.pdf
    • http://cefasfese.4pu.com/1730731736737738739/Secret-Eye-The-Journal-of-Ella-Gertrude-Clanton-Thomas-1848-1889-by-Ella-Gertrude-Thomas-Clanton.pdf