Malicious PDF — malware analysis report

Static analysis result for SHA-256 850c7c5119600262…

MALICIOUS

PDF

17.8 KB Created: 2019-05-01 12:03:38 +01:00 Authoring application: mPDF 5.7
MD5: 7d434c56e439f66009f61f61c6e04c76 SHA-1: c34d042bb82c5987749663c0a3cd2e87a9604a74 SHA-256: 850c7c5119600262db097a2721dc530ce69f784df3d8ae87ccdeb58473f96d58
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves appear to point to benign book titles, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9807

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6731730736737730/A-Liar-amp-a-Cheat-by-Monette.pdf
    • http://cefasfese.4pu.com/3739733731732735/Liar-Liar-The-Theory-Practice-and-Destructive-Properties-of-Deception-Liar-Liar-1-by-Gary-Paulsen.pdf
    • http://cefasfese.4pu.com/1739735732733734/Crush-The-Theory-Practice-and-Destructive-Properties-of-Love-Liar-Liar-3-by-Gary-Paulsen.pdf
    • http://cefasfese.4pu.com/3730730738734731/Liar-Liar-Cat-DeLuca-Mysteries-1-by-K-J-Larsen.pdf
    • http://cefasfese.4pu.com/1737734735/Liar-Liar-Helen-Grace-4-by-M-J-Arlidge.pdf
    • http://cefasfese.4pu.com/3733733737733732/Liar-Liar-by-Alan-McMonagle.pdf
    • http://cefasfese.4pu.com/8738730737739730/Liar-Liar-2-by-Lia-Fairchild.pdf
    • http://cefasfese.4pu.com/1730737731731738/The-Liar-Society-The-Liar-Society-1-by-Lisa-Roecker.pdf
    • http://cefasfese.4pu.com/3733733738736734/The-Cowboy-The-CHEAT-His-EX-WIFE-And-Her-Vibrator-by-C-C-Coburn.pdf
    • http://cefasfese.4pu.com/4736739731730739/The-Cheat-Code-for-God-Mode-by-Andy-de-Fonseca.pdf
    • http://cefasfese.4pu.com/7739737730737734/One-App-One-Hour-Cheat-Sheet-A-No-BS-Guide-to-Making-Your-First-App-by-Mon-Baroi.pdf
    • http://cefasfese.4pu.com/7739736738739/Cheat-the-Grave-Signs-of-the-Zodiac-5-by-Vicki-Pettersson.pdf
    • http://cefasfese.4pu.com/1733738736733737/The-Sweet-Cheat-Gone-In-Search-of-Lost-Time-6-by-Marcel-Proust.pdf
    • http://cefasfese.4pu.com/3730732735734736/Domestic-Sluttery-Cheat-Your-Way-to-the-Good-Life-by-Sian-Meades.pdf
    • http://cefasfese.4pu.com/4732732733734735/To-Catch-a-Cheat-The-Great-Greene-Heist-2-by-Varian-Johnson.pdf
    • http://cefasfese.4pu.com/2738732730735735/Pretending-to-Love-How-to-Cheat-Your-Way-to-Relationship-Bliss-by-Ashton-Cartwright.pdf
    • http://cefasfese.4pu.com/9735739738736739/Mental-Floss-Cocktail-Party-Cheat-Sheets-by-Mangesh-Hattikudur.pdf
    • http://cefasfese.4pu.com/1730734735733735737/The-Four-Pack-Revolution-How-You-Can-Aim-Lower-Cheat-on-Your-Diet-and-Still-Lose-Weight-and-Keep-It-Off-by-Chael-Sonnen.pdf
    • http://cefasfese.4pu.com/6731730736739734/After-the-Dragon-by-Sarah-Monette.pdf
    • http://cefasfese.4pu.com/1737736735736738/Predator-by-Paul-Monette.pdf