Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b5dbdd56c705bf0…

MALICIOUS

PDF

18.0 KB Created: 2019-05-02 17:28:13 +01:00 Authoring application: mPDF 5.7
MD5: e37104cfdd0471bb427fd03ee6885308 SHA-1: 0f3e39748c52ed13dfb8c49be03f39ef607ea757 SHA-256: 8b5dbdd56c705bf02036ef84a150b09194fcff2934b944ff505691cd2ec2d71c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF was flagged by a critical heuristic for containing a large number of external links, suggesting a link farm or SEO manipulation tactic. The ML classifier also strongly indicated maliciousness. While no scripts were extracted, the sheer volume of embedded links, primarily to PDF files hosted on 'cefasfese.4pu.com', points towards a distribution or redirection mechanism rather than legitimate document content. The document body was unreadable, preventing further analysis of its direct user-facing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6730731736738731/The-Marquise-Hill-Story-by-Sherry-Hill.pdf
    • http://cefasfese.4pu.com/1730732738737/Red-Hill-Red-Hill-1-by-Jamie-McGuire.pdf
    • http://cefasfese.4pu.com/1730734731738739730/Think-and-Grow-Rich-by-Napoleon-Hill-with-Linked-Table-of-Contents-by-Napoleon-Hill.pdf
    • http://cefasfese.4pu.com/7737734730734737/Think-amp-Grow-Rich---Lectures-by-Napoleon-Hill-MP3-by-Napoleon-Hill.pdf
    • http://cefasfese.4pu.com/9731733738731/Harry-Hill-s-TV-Burp-Book-by-Harry-Hill.pdf
    • http://cefasfese.4pu.com/9737732736737730/The-Witches-of-Cleopatra-Hill-Box-Set-Volume-1-The-Witches-of-Cleopatra-Hill-1-3-by-Christine-Pope.pdf
    • http://cefasfese.4pu.com/9739730739738732/Hill-s-Wilmington-New-Hanover-County-N-C-City-Directory-1961-Including-Audubon-Devon-Park-Edgewood-Foxtown-Garden-City-Hanover-Heights-Highwood-Park-Idlewild-Long-Leaf-Hills-Oak-Court-Oak-Crest-Piney-Woods-and-Winter-Park-by-Hill-Directory-Company.pdf
    • http://cefasfese.4pu.com/1732733738735739/Black-Hill-Farm-Black-Hill-Farm-1-by-Tim-O-39-Rourke.pdf
    • http://cefasfese.4pu.com/7735737738734732/The-McGraw-Hill-36-Hour-Course-Product-Development-the-McGraw-Hill-36-Hour-Course-Product-Development-by-Andrea-Belz.pdf
    • http://cefasfese.4pu.com/1731734739732734734/Kodiak-by-Joe-Hill.pdf
    • http://cefasfese.4pu.com/3730731733734736/NOS4R2-by-Joe-Hill.pdf
    • http://cefasfese.4pu.com/2734733735735732/NOS4R2-by-Joe-Hill.pdf
    • http://cefasfese.4pu.com/4730737734732/Locke-amp-Key-by-Joe-Hill.pdf
    • http://cefasfese.4pu.com/4736731730736734/Someone-Knows-My-Name-by-Lawrence-Hill.pdf
    • http://cefasfese.4pu.com/2734736730731737/NOS4R2-by-Joe-Hill.pdf
    • http://cefasfese.4pu.com/7732735734733/NOS4R2-by-Joe-Hill.pdf
    • http://cefasfese.4pu.com/3730738734736738/FAG-by-Jonathan-Hill.pdf
    • http://cefasfese.4pu.com/4738732738731731/The-Nix-by-Nathan-Hill.pdf
    • http://cefasfese.4pu.com/4738731735/The-Fireman-by-Joe-Hill.pdf
    • http://cefasfese.4pu.com/6730738731734/NOS4A2-by-Joe-Hill.pdf
    • http://cefasfese.4pu.com/9739730739738732/Hill-s-Wilmington-New-Hanover-C