Malicious PDF — malware analysis report

Static analysis result for SHA-256 90f270fec644ea11…

MALICIOUS

PDF

18.2 KB Created: 2019-05-02 04:38:54 +01:00 Authoring application: mPDF 5.7
MD5: b7d056232ed92e0686e9007a610500a2 SHA-1: 2da73d315e941dbe52c188bdde7b1ec3881f75bc SHA-256: 90f270fec644ea11a4f61bd566b0bdcd30379ef54124873fd2e2c3254d5d4321
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various book titles. While the individual URLs are marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to distribute further payloads. The ML_NYX_PDF_MALICIOUS classifier also flagged this PDF with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2733736737737733/The-Minotaur-by-Barbara-Vine.pdf
    • http://cefasfese.4pu.com/2733736735731733/No-Night-is-Too-Long-by-Barbara-Vine.pdf
    • http://cefasfese.4pu.com/6731736732738738/The-Birthday-Present-by-Barbara-Vine.pdf
    • http://cefasfese.4pu.com/1736735733734/A-Dark-Adapted-Eye-by-Barbara-Vine.pdf
    • http://cefasfese.4pu.com/7738734733735/The-Chimney-Sweeper-s-Boy-by-Barbara-Vine.pdf
    • http://cefasfese.4pu.com/1735733737734734/The-Blood-Doctor-by-Barbara-Vine.pdf
    • http://cefasfese.4pu.com/2734730734732736/The-Brimstone-Wedding-by-Barbara-Vine.pdf
    • http://cefasfese.4pu.com/2730739732730731/Copper-Beech-Grove-A-Different-Kind-of-Love-by-Barbara-Pintoro.pdf
    • http://cefasfese.4pu.com/2735739736739735/Blood-Vine-Blood-Vine-1-by-Amber-Belldene.pdf
    • http://cefasfese.4pu.com/8732739739730736/A-Kind-of-Romance-A-Kind-of-Stories-2-by-Lane-Hayes.pdf
    • http://cefasfese.4pu.com/3733739736733730/A-Kind-of-Honesty-A-Kind-of-Stories-3-by-Lane-Hayes.pdf
    • http://cefasfese.4pu.com/1739732734732731/A-Kind-of-Truth-A-Kind-of-Stories-1-by-Lane-Hayes.pdf
    • http://cefasfese.4pu.com/1730730734736732739/Albtraum---Tod-eines-Kindes-by-K-J-Weiss.pdf
    • http://cefasfese.4pu.com/1730732739732738731/Die-Erziehung-des-Kindes-Ein-Aufsatz-und-zwei-Vortr-ge-1906-und-1907-aus-GA-34-und-55-by-Cornelius-Bohlen.pdf
    • http://cefasfese.4pu.com/1731731732730732733/Empfindsam-erziehen-Tipps-f-r-die-ersten-10-Lebensjahre-des-hochsensiblen-Kindes-by-Julie-Leuze.pdf
    • http://cefasfese.4pu.com/1731736730739736735/LILA-FLOH-IN-LAVENDEL-Das-R-tsel-eines-stummen-Kindes-by-Inka-Mareila.pdf
    • http://cefasfese.4pu.com/1731738736730734731/Kinder-Der-Angst-Studie-Zum-Anthropologischen-Phanomen-Der-Angst-Im-Historischen-Wandel-Der-Erlebniswelt-Des-Kindes-by-Ferdinand-Bitz.pdf
    • http://cefasfese.4pu.com/9736734732733731/Erorterung-Und-Erlauterung-Der-Frage-OB-Es-Ein-Gewi-Zeichen-Wenn-Eines-Todten-Kindes-Lunge-Im-Wasser-Untersinket-Da-Solches-in-Mutter-Leibe-Gestorben-Sey-by-Johann-Schreyer.pdf
    • http://cefasfese.4pu.com/3739732736735738/Lurk-by-Adam-Vine.pdf
    • http://cefasfese.4pu.com/9738734734732/Jam-on-the-Vine-by-LaShonda-Katrice-Barnett.pdf