Malicious PDF — malware analysis report

Static analysis result for SHA-256 9daa7cc2bba9513c…

MALICIOUS

PDF

17.5 KB Created: 2019-11-07 10:43:45 +00:00 Authoring application: mPDF 5.7
MD5: d5b6d1d89e5da43694e0234719d44577 SHA-1: 7ba41b7b9ea9a1298b37a78507e6f7bbafed69db SHA-256: 9daa7cc2bba9513c775a0932d518d584059187a393164c4adeaebd76e5681ab1
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified as a link farm. The primary heuristic indicates a critical finding related to SEO link farming, suggesting the document's purpose is to direct users to a large number of external PDF files. While the document body is heavily obfuscated, the presence of numerous links points towards a malicious intent, likely for SEO poisoning or traffic generation. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7730731736733733/Jingle-Bells-A-Chubby-Board-Book-by-Normand-Chartier.pdf
    • http://cefasfese.4pu.com/7730731735739739/Over-the-River-amp-Thro-the-Woods-by-Normand-Chartier.pdf
    • http://cefasfese.4pu.com/1735731737732731/Jingle-Bells-by-Michael-Hague.pdf
    • http://cefasfese.4pu.com/7732731730733/Junie-B-First-Grader-Jingle-Bells-Batman-Smells-P-S-So-Does-May-Junie-B-Jones-25-by-Barbara-Park.pdf
    • http://cefasfese.4pu.com/4730730730737732/Jingle-All-The-Way-Interactive-Storybook-And-Story-Buddy-Jingle-Pup-by-Tom-Shay-Zapien.pdf
    • http://cefasfese.4pu.com/3731731733731730/The-Owl-and-the-Pussycat-Board-Book-by-Edward-Lear.pdf
    • http://cefasfese.4pu.com/1730730736739739737/The-Wheels-on-the-Bus-board-book-by-Larry-Nolte.pdf
    • http://cefasfese.4pu.com/2736738732738731/Never-Board-A-Green-Bus-Flight-Knights-Book-3-by-C-D-Bryan.pdf
    • http://cefasfese.4pu.com/1736732733739732/Hush-Little-Alien-Board-Book-by-Daniel-Kirk.pdf
    • http://cefasfese.4pu.com/6730733730733730/The-Night-Before-Christmas-Board-Book-by-Clement-C-Moore.pdf
    • http://cefasfese.4pu.com/1735731732730739/Blue-Bells-of-Scotland-Blue-Bells-Trilogy-1-by-Laura-Vosika.pdf
    • http://cefasfese.4pu.com/7739730733735731/The-Official-Olympiads-Book-of-Reasoning-Class-5-by-MTG-editorial-board.pdf
    • http://cefasfese.4pu.com/1739736733738736/Hop-On-Board-A-Series-of-Ghastly-Things-Book-1-by-Nicholas-A-Price.pdf
    • http://cefasfese.4pu.com/1730737738738737731/Goodnight-Moon-Board-Book-Bunny-by-Margaret-Wise-Brown.pdf
    • http://cefasfese.4pu.com/8737734739730739/Dora-s-Sweet-Adventure-A-Scratch-amp-Sniff-Board-Book-by-Brooke-Lindner.pdf
    • http://cefasfese.4pu.com/8730735736730736/Goodnight-Moon-Board-Book-Comb-and-Brush-Set-by-Margaret-Wise-Brown.pdf
    • http://cefasfese.4pu.com/1732733733730732/On-the-Plus-Side-Chubby-Girl-Chronicles-1-by-Tabatha-Vargo.pdf
    • http://cefasfese.4pu.com/1730738733733736736/Dying-for-Dinner-Rolls-Chubby-Chicks-Club-1-by-Lois-Lavrisa.pdf
    • http://cefasfese.4pu.com/1731736738736732736/Report-of-the-Defense-Science-Board-Task-Force-on-Discriminate-Use-of-Force-by-Defence-Science-Board.pdf
    • http://cefasfese.4pu.com/6733730731735736/Afterdeath-by-Benoit-Chartier.pdf