Malicious PDF — malware analysis report

Static analysis result for SHA-256 a5bae20cfeb57a5e…

MALICIOUS

PDF

25.7 KB Created: 2019-06-04 17:45:21 +01:00 Authoring application: mPDF 5.7
MD5: c0ad9c820fed88c242607693593c8e15 SHA-1: 73cde22202cf4bb93238785c05fe452eff3fe460 SHA-256: a5bae20cfeb57a5e4f665c3423a8ce8f750cb2493c840cf9a9612c16d7c7879b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs point to what appear to be legitimate book titles, the sheer volume and the ML classifier's high confidence score suggest a malicious intent. The primary attack pattern involves redirecting users to a vast external link farm, likely for SEO manipulation or to serve further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730732734732737/Raving-Fans-A-Revolutionary-Approach-to-Customer-Service-by-Kenneth-H-Blanchard.pdf
    • http://cefasfese.4pu.com/2734735731730736/Customer-Service-by-Felicity-Brandon.pdf
    • http://cefasfese.4pu.com/6733730731732738/Customer-Service-by-Beno-t-Duteurtre.pdf
    • http://cefasfese.4pu.com/1730731736739739731/Big-Bucks-by-Kenneth-H-Blanchard.pdf
    • http://cefasfese.4pu.com/7739731737737736/The-Servant-Leader-by-Kenneth-H-Blanchard.pdf
    • http://cefasfese.4pu.com/1730738734732734735/Care-Packages-for-Your-Customers-An-Idea-a-Week-to-Enhance-Customer-Service-by-Barbara-Glanz.pdf
    • http://cefasfese.4pu.com/2732736732737/Smile-Sell-More-with-Amazing-Customer-Service-The-Essential-60-Minute-Crash-Course-by-Kirt-Manecke.pdf
    • http://cefasfese.4pu.com/1730737730734739732/Gung-Ho-Wie-Sie-jedes-Team-in-H-chstform-bringen-by-Kenneth-H-Blanchard.pdf
    • http://cefasfese.4pu.com/5738732739731730/The-Leadership-Pill-The-Missing-Ingredient-in-Motivating-People-Today-by-Kenneth-H-Blanchard.pdf
    • http://cefasfese.4pu.com/3738731730737735/Lead-Like-Jesus-Lessons-from-the-Greatest-Leadership-Role-Model-of-All-Time-by-Kenneth-H-Blanchard.pdf
    • http://cefasfese.4pu.com/4739738730737734/The-Customer-Rules-The-39-Essential-Rules-for-Delivering-Sensational-Service-by-Lee-Cockerell.pdf
    • http://cefasfese.4pu.com/1730736737738738734/The-Natural-Mind-A-Revolutionary-Approach-to-the-Drug-Problem-by-Andrew-Weil.pdf
    • http://cefasfese.4pu.com/8730739733733730/Self-Leadership-and-the-One-Minute-Manager-Increasing-Effectiveness-Through-Situational-Self-Leadership-by-Kenneth-H-Blanchard.pdf
    • http://cefasfese.4pu.com/6732734730734738/Refire-Don-t-Retire-Make-the-Rest-of-Your-Life-the-Best-of-Your-Life-by-Kenneth-H-Blanchard.pdf
    • http://cefasfese.4pu.com/7739737730734736/Integral-Recovery-A-Revolutionary-Approach-to-the-Treatment-of-Alcoholism-and-Addiction-by-John-Dupuy.pdf
    • http://cefasfese.4pu.com/4739733731736730/Customer-LLC-The-Small-Business-Guide-to-Customer-Engagement-amp-Marketing-by-Hillary-Berman.pdf
    • http://cefasfese.4pu.com/5734731732736736/The-Eternal-E-Customer-How-Emotionally-Intelligent-Interfaces-Can-Create-Long-Lasting-Customer-Relationships-by-Bryan-Bergeron.pdf
    • http://cefasfese.4pu.com/3739739738737738/Screamfree-Parenting-The-Revolutionary-Approach-to-Raising-Your-Kids-by-Keeping-Your-Cool-by-Hal-Edward-Runkel.pdf
    • http://cefasfese.4pu.com/3733736732732736/Spies-Patriots-and-Traitors-American-Intelligence-in-the-Revolutionary-War-by-Kenneth-A-Daigler.pdf
    • http://cefasfese.4pu.com/3732735738734732/Tales-from-the-Kurtherian-Universe-Fans-Write-For-The-Fans-1-by-S-E-Weir.pdf
    • http://cefasfese.4pu.com/5738732739731730/The-Leadership-Pill-The-Missing-Ingredient-in-Motivating-People-Today-by-Kenneth-H-Blanchard