Malicious PDF — malware analysis report

Static analysis result for SHA-256 8d8f4a7e2a32bfe1…

MALICIOUS

PDF

15.8 KB Created: 2019-05-02 17:35:03 +01:00 Authoring application: mPDF 5.7
MD5: 0d967de9c3f27b892d944a0d99c815d6 SHA-1: b6449a2797758a7ee987a5c4f0c8e1891d89ece0 SHA-256: 8d8f4a7e2a32bfe1b8a9f7c46f10e2639c6b7fb3c3f7bcebb27c89bc219b7d4e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: User Execution: Malicious File

The PDF contains a large number of embedded URLs, identified as a link farm. While the specific content of the links appears benign, the sheer volume and structure suggest a malicious intent, likely for SEO manipulation or to serve as a distribution point for other malware. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9800

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6733732732739736/Rose-Point-Her-Instruments-2-by-M-C-A-Hogarth.pdf
    • http://cefasfese.4pu.com/6731736735734730/The-Arcane-Eye-of-Hogarth-by-Burne-Hogarth.pdf
    • http://cefasfese.4pu.com/5739733731735735/The-Mortal-Instruments-Mortal-Instruments-1-3-by-Cassandra-Clare.pdf
    • http://cefasfese.4pu.com/1737732732739736/Reckless-Point-Cross-Point-Village-1-by-Cora-Brent.pdf
    • http://cefasfese.4pu.com/2733734730734732/Counter-Point-Heath-s-Point-Suspense-1-by-Marji-Laine.pdf
    • http://cefasfese.4pu.com/2731734732735733/The-Worth-of-a-Shell-by-M-C-A-Hogarth.pdf
    • http://cefasfese.4pu.com/5737736737739/Point-of-No-Return-Turning-Point-1-by-N-R-Walker.pdf
    • http://cefasfese.4pu.com/3739733738730734/Point-of-No-Return-Turning-Point-1-by-N-R-Walker.pdf
    • http://cefasfese.4pu.com/2735733739730739/Mr-Hogarth-s-Will-by-Catherine-Helen-Spence.pdf
    • http://cefasfese.4pu.com/2732736735730733/Educating-Intuition-by-Robin-M-Hogarth.pdf
    • http://cefasfese.4pu.com/5731733739734734/The-Other-Hogarth-Aesthetics-of-Difference-by-Bernadette-Fort.pdf
    • http://cefasfese.4pu.com/6737736737731731/Le-portrait-sans-peine-by-Burne-Hogarth.pdf
    • http://cefasfese.4pu.com/2730739739735738/Drawing-Dynamic-Hands-by-Burne-Hogarth.pdf
    • http://cefasfese.4pu.com/1730735738733731/Cantor-for-Pearls-Twin-Kingdoms-Romances-2-by-M-C-A-Hogarth.pdf
    • http://cefasfese.4pu.com/5735735738738738/Wrecked-Under-the-Green-Point-Light-The-Background-to-the-Green-and-Mouille-Point-Lights-and-Stories-of-Six-Shipwrecks-in-the-Area-by-John-T-Dimond.pdf
    • http://cefasfese.4pu.com/1730735737732738735/Insights-in-Decision-Making-A-Tribute-to-Hillel-J-Einhorn-by-Robin-M-Hogarth.pdf
    • http://cefasfese.4pu.com/2734732733730/The-Origins-of-Comics-From-William-Hogarth-to-Winsor-McCay-by-Thierry-Smolderen.pdf
    • http://cefasfese.4pu.com/1732736737731730/Extinction-Point-Extinction-Point-1-by-Paul-Antony-Jones.pdf
    • http://cefasfese.4pu.com/1731733736737/Snowfall-on-Haven-Point-Haven-Point-5-by-RaeAnne-Thayne.pdf
    • http://cefasfese.4pu.com/5732732735730737/The-People-Instruments-by-Amy-King.pdf
    • http://cefasfese.4pu.com/2730739739735738/Drawing-Dynamic-Hands-by-Burne-