Malicious PDF — malware analysis report

Static analysis result for SHA-256 817f83a7d877d5d3…

MALICIOUS

PDF

19.1 KB Created: 2019-05-03 05:31:47 +01:00 Authoring application: mPDF 5.7
MD5: 3a1a81cc5e33f0d2be8981b4b26991be SHA-1: f04de5c67546cf2662a34e76d8d4dd0b0e437353 SHA-256: 817f83a7d877d5d3a2850ac46016a9be78d6c58f471cdf88a8fe6e85aa56b814
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to a domain that appears to be hosting a link farm. The heuristic 'PDF_SEO_LINK_FARM' indicates this is a technique to generate traffic or potentially distribute malicious content. While the URLs themselves are marked as benign, the sheer volume and suspicious domain suggest a malicious intent, likely to drive traffic to potentially compromised or malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3730734736738734/Lisa-and-David-Jordi-Little-Ralphie-and-the-Creature-by-Theodore-Isaac-Rubin.pdf
    • http://cefasfese.4pu.com/4730739730730734/Lisa-and-David-by-Theodore-Isaac-Rubin.pdf
    • http://cefasfese.4pu.com/3734736735736734/The-Angry-Book-by-Theodore-Isaac-Rubin.pdf
    • http://cefasfese.4pu.com/1739734730739736/The-Greater-Darkness-by-David-Rubin.pdf
    • http://cefasfese.4pu.com/1731733736731736732/Rubin-s-Pathology-Clinicopathologic-Foundations-of-Medicine-by-Raphael-Rubin.pdf
    • http://cefasfese.4pu.com/8731735738735736/The-Best-of-Jordi-Bernet-s-Clara-by-Jordi-Bernet.pdf
    • http://cefasfese.4pu.com/5731733735730731/Memory-in-Oral-Traditions-The-Cognitive-Psychology-of-Epic-Ballads-and-Counting-Out-Rhymes-by-David-C-Rubin.pdf
    • http://cefasfese.4pu.com/5739736735736733/Colonel-Theodore-Roosevelt-by-David-A-Adler.pdf
    • http://cefasfese.4pu.com/1731734733734739732/Isaac-Hecker-An-American-Catholic-by-David-J-O-39-Brien.pdf
    • http://cefasfese.4pu.com/1730733737739735738/Theodore-de-Banville-Constructing-Poetic-Value-in-Nineteenth-Century-France-by-David-Evans.pdf
    • http://cefasfese.4pu.com/3731733730736738/Discovering-Isaac-The-Beloved-Potter-of-Niederbipp-Remembering-Isaac-2-by-Ben-Behunin.pdf
    • http://cefasfese.4pu.com/3731732736732734/Becoming-Isaac-The-Next-Potter-of-Niederbipp-Remembering-Isaac-3-by-Ben-Behunin.pdf
    • http://cefasfese.4pu.com/2730734733732736/Deviations-A-Gayle-Rubin-Reader-by-Gayle-S-Rubin.pdf
    • http://cefasfese.4pu.com/9731738735736731/Natura-Morta-by-Jordi-Valls.pdf
    • http://cefasfese.4pu.com/7732731737733738/Le-Huiti-me-Livre-de-V-sale-by-Jordi-Llobregat.pdf
    • http://cefasfese.4pu.com/1731731737737739732/Sue-os-de-acero-y-ne-n-by-Jordi-Wild.pdf
    • http://cefasfese.4pu.com/5739736734737733/Edmund-Morris-s-Theodore-Roosevelt-Trilogy-Bundle-The-Rise-of-Theodore-Roosevelt-Theodore-Rex-and-Colonel-Roosevelt-by-Edmund-Morris.pdf
    • http://cefasfese.4pu.com/1733739730733733/David-Starr-Space-Ranger-Lucky-Starr-1-by-Isaac-Asimov.pdf
    • http://cefasfese.4pu.com/1731736735732732737/H-llenjagd-Ein-Isaac-Bell-Roman-Reihenfolge-der-Isaac-Bell-Abenteuer-1-by-Clive-Cussler.pdf
    • http://cefasfese.4pu.com/4735736736733732/Isaac-Asimov-Presents-the-Golden-Years-of-Science-Fiction-Third-Series-by-Isaac-Asimov.pdf