Malicious PDF — malware analysis report

Static analysis result for SHA-256 8a5084ea5c9439ab…

MALICIOUS

PDF

25.2 KB Created: 2019-05-03 06:08:22 +01:00 Authoring application: mPDF 5.7
MD5: 1dccaa6605ae5859f38c35ee0c109c0c SHA-1: afef12ebafc5638bbf583054b18c448ab3976646 SHA-256: 8a5084ea5c9439abe74159f0601412acce67edee023b06afc26e90e60ae4e4bf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. While the specific content of the linked PDFs is benign, the sheer volume and the nature of the links suggest a malicious intent, possibly for SEO spam or to distribute further malicious content. The ML_NYX_PDF_MALICIOUS heuristic also flagged the file with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9742

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2731739735733737/The-Shadow-War-A-Dark-Paranormal-Fantasy-The-Demon-Born-Trilogy-Book-3-by-L-C-Hibbett.pdf
    • http://cefasfese.4pu.com/1731737730734730730/Shadow-Born-Shadow-Born-Trilogy-1-by-Jamie-Sedgwick.pdf
    • http://cefasfese.4pu.com/9739738734731737/Guardians-of-Magic-A-Reverse-Harem-Paranormal-Fantasy-Romance-Guardians-of-the-Fae-Book-1-by-Elizabeth-Hartwell.pdf
    • http://cefasfese.4pu.com/5738734733736733/Rage-of-a-Demon-King-Shadow-of-a-Dark-Queen-Rise-of-a-Merchant-Prince-The-Serpentwar-Saga-1-3-by-Raymond-E-Feist.pdf
    • http://cefasfese.4pu.com/2731733739732737/Fantasy-Begins-Book-1-of-the-Dungeon-Hive-Trilogy-by-Roy-Lim.pdf
    • http://cefasfese.4pu.com/7736735732734732/The-Demon-Inside-The-Zone-War-Trilogy-Book-1-by-Terry-Cloutier.pdf
    • http://cefasfese.4pu.com/9738738739739731/BBW-SHIFTER-ROMANCE-PARANORMAL-SHAPESHIFTER-ROMANCE-Wolf-Shifter-The-Protector-Paranormal-Alpha-Male-Suspense-Romance-Werewolf-Fantasy-Romance-Short-Stories-by-Jenny-Wildner.pdf
    • http://cefasfese.4pu.com/1730739739731732730/Mother-of-the-King-powerful-historical-fantasy-romance-The-Igraine-Trilogy-Book-3-by-Lavinia-Collins.pdf
    • http://cefasfese.4pu.com/2731734730733733/Escape-From-Samsara-A-Dark-Comedy-Fantasy-Adventure-Prophecy-Allocation-Book-1-by-Nicky-Blue.pdf
    • http://cefasfese.4pu.com/3739735734735736/My-Demon-Determined-My-Demon-Trilogy-2-by-Alicia-Dawn.pdf
    • http://cefasfese.4pu.com/2731735739738739/A-Chance-Beginning-Book-One-of-the-Shadow-s-Fire-Trilogy-by-Christopher-Patterson.pdf
    • http://cefasfese.4pu.com/2734739739739733/Obfuscate---A-Paranormal-Urban-Fantasy-World-of-Blood-2-by-Killion-Slade.pdf
    • http://cefasfese.4pu.com/1731732735732736730/Eternally-Enchanted-A-Collection-of-Paranormal-and-Fantasy-Romances-by-Nicole-Morgan.pdf
    • http://cefasfese.4pu.com/1738731737730738/21-Shades-of-Night-A-Collection-of-Best-Selling-Paranormal-Romance-and-Urban-Fantasy-by-Katie-de-Long.pdf
    • http://cefasfese.4pu.com/1731730736737731730/Matched-with-the-Demon-Demon-Marked-Book-1-by-Ripley-Proserpina.pdf
    • http://cefasfese.4pu.com/4732731732730731/Dark-Duets-All-New-Tales-of-Horror-and-Dark-Fantasy-by-Christopher-Golden.pdf
    • http://cefasfese.4pu.com/5730735734739731/Xoe-Meyers-Trilogy-Books-1-3-Xoe-Accidental-Ashes-and-Broken-Beasts-Xoe-Meyers-Young-Adult-Fantasy-Horror-Series-Book-0-by-Sara-C-Roethle.pdf
    • http://cefasfese.4pu.com/2730738739737738/Demon-from-the-Dark-Immortals-After-Dark-10-by-Kresley-Cole.pdf
    • http://cefasfese.4pu.com/2735731734739735/Demon-from-the-Dark-Immortals-After-Dark-10-by-Kresley-Cole.pdf
    • http://cefasfese.4pu.com/5730735738732/Born-in-Flames-Born-in-Flames-Trilogy-1-by-Candace-Knoebel.pdf
    • http://cefasfese.4pu.com/2731733739732737/Fantasy-Begins-Book-1-of-the-D