Malicious PDF — malware analysis report

Static analysis result for SHA-256 8a726906c1595917…

MALICIOUS

PDF

16.3 KB Created: 2019-05-02 05:06:33 +01:00 Authoring application: mPDF 5.7
MD5: 0f19abbf605c303d64e0406857ba4c28 SHA-1: 7fc2430c8d51a198ef2e002c6ef00d37b72b6b3c SHA-256: 8a726906c1595917d6562da921e2c07d49a98c4f88120be8db45b1168636f159
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified as a link farm. The primary heuristic indicates a critical finding related to this link farm, with the dominant host being 'cefasfese.4pu.com'. While the document body is heavily corrupted, the presence of numerous links suggests a malicious intent, possibly for SEO manipulation or to direct users to further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1738731739734737/Hidden-Secrets-The-Secrets-Saga-1-by-Angee-Taylor.pdf
    • http://cefasfese.4pu.com/1738732732734731/Deadly-Secrets-The-Secrets-Saga-2-by-Angee-Taylor.pdf
    • http://cefasfese.4pu.com/2730731736730732/Journey-The-Beginning-A-Prequel-to-the-Secrets-Saga-by-Angee-Taylor.pdf
    • http://cefasfese.4pu.com/1731735738733733735/Hidden-by-Barbara-Taylor-Bradford.pdf
    • http://cefasfese.4pu.com/4739731736732730/Happily-Ever-After-Hidden-Falls-Trilogy-1-by-Taylor-Hart.pdf
    • http://cefasfese.4pu.com/3739730738732732/Hidden-Secrets-by-Cait-London.pdf
    • http://cefasfese.4pu.com/3735732739737733/Seventh-Mark---Part-1-Hidden-Secrets-1-1-by-W-J-May.pdf
    • http://cefasfese.4pu.com/3731738734730733/Hidden-Secrets-Attract-Everything-You-Want-by-Carl-Nagel.pdf
    • http://cefasfese.4pu.com/2731730739736736/Hidden-Bone-Secrets-1-by-Kendra-Elliot.pdf
    • http://cefasfese.4pu.com/5737730739737/Hidden-Bone-Secrets-1-by-Kendra-Elliot.pdf
    • http://cefasfese.4pu.com/6735735730736/Dumbing-Us-Down-The-Hidden-Curriculum-of-Compulsory-Schooling-by-John-Taylor-Gatto.pdf
    • http://cefasfese.4pu.com/2730730737738737/Constantine-s-Secret-The-Secrets-of-Hidden-Bay-2-by-Urcelia-Teixeira.pdf
    • http://cefasfese.4pu.com/6737734733737733/Hidden-Credit-Repair-Secrets-by-Mark-Clayborne.pdf
    • http://cefasfese.4pu.com/2731738737733730/Blood-Secrets-by-Karen-E-Taylor.pdf
    • http://cefasfese.4pu.com/3736737731734733/Hidden-Inheritance-Family-Secrets-Memory-and-Faith-by-Heidi-B-Neumark.pdf
    • http://cefasfese.4pu.com/2732739736736737/The-Book-of-Secrets-Unlocking-the-Hidden-Dimensions-of-Your-Life-by-Deepak-Chopra.pdf
    • http://cefasfese.4pu.com/6735731736736737/The-ABC-s-of-Real-Estate-Investing-The-Secrets-of-Finding-Hidden-Profits-Most-Investors-Miss-by-Ken-McElroy.pdf
    • http://cefasfese.4pu.com/5734737733731/Tesoro-Secrets-of-the-Hidden-Treasure-The-Tesoro-Series-1-by-Andrea-Hintz.pdf
    • http://cefasfese.4pu.com/4736732735736737/Secrets-of-Cavendon-Cavendon-Hall-4-by-Barbara-Taylor-Bradford.pdf
    • http://cefasfese.4pu.com/4738730735736733/Hidden-Deceit-The-Hidden-Series-8-by-Nicole-Colville.pdf
    • http://cefasfese.4pu.com/2730730737738737/Constantine-s-Secret-The-Secrets-of-Hidden-Bay-2-by-Urcelia-Teixeira.pd