Malicious PDF — malware analysis report

Static analysis result for SHA-256 a2f98c23eb6e975d…

MALICIOUS

PDF

23.5 KB Created: 2019-11-07 20:44:56 +00:00 Authoring application: mPDF 5.7
MD5: fec02b06603e318464b2c74d102b6f21 SHA-1: 8ebe99360619e81c7eff3a3054b2ebfde98a4118 SHA-256: a2f98c23eb6e975d55f7efa1b552f10e1ff3e1aec21f716b03172f11ad024516
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to book titles but are likely part of a link farm or SEO poisoning scheme. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document. While no scripts were extracted, the embedded links are the primary indicators of malicious intent, suggesting a lure to external malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9776

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3733736735731732/3000-Degrees-The-True-Story-of-a-Deadly-Fire-and-the-Men-Who-Fought-It-by-Sean-Flynn.pdf
    • http://cefasfese.4pu.com/9735738739735735/Through-the-Fire-Based-on-a-True-Story-About-a-Young-Girl-That-Was-Maliciously-Burned-in-a-House-Fire-by-Theresa-A-Vandermeer.pdf
    • http://cefasfese.4pu.com/1737732737739/Deadly-Force-The-True-Story-of-How-a-Badge-Can-Become-a-License-to-Kill-by-Lawrence-O-39-Donnell.pdf
    • http://cefasfese.4pu.com/2734730735732736/The-Cadet-Murder-Case-A-True-Story-of-Teen-Love-and-Deadly-Revenge-by-A-W-Gray.pdf
    • http://cefasfese.4pu.com/7733730736735/The-Beast-in-the-Garden-The-True-Story-of-a-Predator-s-Deadly-Return-to-Suburban-America-by-David-Baron.pdf
    • http://cefasfese.4pu.com/4738731738730734/Fighting-the-Devil-A-True-Story-of-Consuming-Passion-Deadly-Poison-and-Murder-by-Jeannie-Walker.pdf
    • http://cefasfese.4pu.com/1737737731733734/Fighting-the-Devil-A-True-Story-of-Consuming-Passion-Deadly-Poison-and-Murder-by-Jeannie-Walker.pdf
    • http://cefasfese.4pu.com/1736734733730/Fire-Lover-A-True-Story-by-Joseph-Wambaugh.pdf
    • http://cefasfese.4pu.com/1731738736734730/God-Inside-the-Fire-An-Amazing-True-Story-by-Greg-Stelley.pdf
    • http://cefasfese.4pu.com/2733738733739739/By-Permission-of-Heaven-The-True-Story-of-the-Great-Fire-of-London-by-Adrian-Tinniswood.pdf
    • http://cefasfese.4pu.com/8738730733736733/Angels-in-the-Fire-The-Dramatic-True-Story-of-an-Impossible-Rescue-by-Dann-Stadler.pdf
    • http://cefasfese.4pu.com/1733731731735733/Deadly-Harvest-Flynn-Brothers-2-by-Heather-Graham.pdf
    • http://cefasfese.4pu.com/3730733737739735/Deadly-Gift-Flynn-Brothers-3-by-Heather-Graham.pdf
    • http://cefasfese.4pu.com/1733731735731738/Deadly-Night-Flynn-Brothers-1-by-Heather-Graham.pdf
    • http://cefasfese.4pu.com/6736732739739737/Fire-in-the-Desert-The-True-Story-of-the-Craig-Titus-Kelly-Ryan-Murder-Mystery-by-Glenn-Puit.pdf
    • http://cefasfese.4pu.com/1730738736730737732/Revealed-by-Fire-A-True-Story-of-a-Soldier-Told-in-His-Letters-at-a-Time-Unparalleled-in-American-History---The-Korean-War-1950-1953-by-Bill-Ahnen.pdf
    • http://cefasfese.4pu.com/1731733731731733738/Degrees-of-Betrayal-Ryun-s-Story-by-Jeff-Nesbit.pdf
    • http://cefasfese.4pu.com/3736734732735735/Six-Degrees-of-Agony-By-Degrees-3-by-Taylor-V-Donovan.pdf
    • http://cefasfese.4pu.com/2735735738730736/Six-Degrees-of-Lust-By-Degrees-1-by-Taylor-V-Donovan.pdf
    • http://cefasfese.4pu.com/1736738739736735/Showdown-The-Inside-Story-of-How-Obama-Fought-Back-Against-Boehner-Cantor-and-the-Tea-Party-by-David-Corn.pdf