Malicious PDF — malware analysis report

Static analysis result for SHA-256 97a41f0491d7feb9…

MALICIOUS

PDF

18.7 KB Created: 2019-11-07 10:26:23 +00:00 Authoring application: mPDF 5.7
MD5: a2889df6dd50782bafa86a3f1baf10d3 SHA-1: 997a7614a588198434a80241baca95a5fd3bef77 SHA-256: 97a41f0491d7feb9019e3b85af48f67a813f997aa254d0578647bef8ce56586d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While most of these URLs point to benign-looking book titles, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO poisoning or to redirect users to harmful sites. No scripts were extracted, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9364

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6738739737730734/Called-by-Name---In-The-Shadow-of-The-Almighty-The-Wonders-of-Practical-Christianity---A-Teaching-Series---Vol-4-by-Valerie-A-Beauchene.pdf
    • http://cefasfese.4pu.com/6738739737731731/The-Oasis-by-Valerie-A-Beauchene.pdf
    • http://cefasfese.4pu.com/6738739737735730/The-Auction-by-Valerie-A-Beauchene.pdf
    • http://cefasfese.4pu.com/6738739737731730/Call-Me-Esther-by-Valerie-A-Beauchene.pdf
    • http://cefasfese.4pu.com/6738739737730733/Hope-for-Laodicea-I-Have-Asked-God-by-Valerie-A-Beauchene.pdf
    • http://cefasfese.4pu.com/6738739737735735/The-Making-of-a-Twenty-First-Century-Hero-by-Valerie-A-Beauchene.pdf
    • http://cefasfese.4pu.com/6738739737731733/Of-Sinking-Ships-and-Broken-Walls-by-Valerie-A-Beauchene.pdf
    • http://cefasfese.4pu.com/6738739737730735/As-Lively-Stones-A-Solid-Foundation-by-Valerie-A-Beauchene.pdf
    • http://cefasfese.4pu.com/6738739737730739/Rise-and-Shine-A-Trilogy-on-Revival-for-the-Christian-by-Valerie-A-Beauchene.pdf
    • http://cefasfese.4pu.com/6738739737731735/I-Have-Found-the-Book-The-Power-of-a-Tender-Heart-by-Valerie-A-Beauchene.pdf
    • http://cefasfese.4pu.com/6738739737732735/Of-Sinking-Ships-and-Broken-Walls-The-Repairer-of-the-Breach-by-Valerie-A-Beauchene.pdf
    • http://cefasfese.4pu.com/4739732737733735/The-Shadow-Walkers-Ghost-Series-Books-1-3-Lost-in-Shadow-Desired-by-Shadow-Iced-in-Shadow-by-Cynthia-Luhrs.pdf
    • http://cefasfese.4pu.com/1731738738736735731/Living-Gnosis-A-Practical-Guide-to-Gnostic-Christianity-by-Tau-Malachi.pdf
    • http://cefasfese.4pu.com/6736737730739734/Practical-Method-of-Teaching-the-French-Language-by-Gatien-De-Lestrade.pdf
    • http://cefasfese.4pu.com/6733731736738731/Orthodox-Christianity-Volume-II-Doctrine-and-Teaching-of-the-Orthodox-Church-by-Metropolitan-Hilarion-Alfeyev.pdf
    • http://cefasfese.4pu.com/2732737736731734/Rain-Shadow-by-Valerie-Sherrard.pdf
    • http://cefasfese.4pu.com/3735733731738/Shadow-Puppets-The-Shadow-Series-3-by-Orson-Scott-Card.pdf
    • http://cefasfese.4pu.com/3734737735738/Shadow-of-the-Hegemon-The-Shadow-Series-2-by-Orson-Scott-Card.pdf
    • http://cefasfese.4pu.com/3737732739733737/Ender-s-Shadow-Shadow-Series-1-by-Orson-Scott-Card.pdf
    • http://cefasfese.4pu.com/2730736739732730/Called-Back-Legoria-Series-2-by-A-M-Winters.pdf
    • http://cefasfese.4pu.com/6738739737731735/I-Have-Found-the-Book-The-Power-of-a-Tender-Heart-b