Malicious PDF — malware analysis report

Static analysis result for SHA-256 a62454f84805d477…

MALICIOUS

PDF

23.4 KB Created: 2019-05-03 05:26:03 +01:00 Authoring application: mPDF 5.7
MD5: a6ec76d90e0172f1d6db849ce73dff65 SHA-1: 49765b565704168f11320cb288503e67b71b861b SHA-256: a62454f84805d477f82c31cbea805855d0dfe50470d92df5ff4433f9ed7afb3a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was flagged by a machine learning classifier as malicious and contains a large number of external links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links, predominantly found in the document body, point to various book titles hosted on the '4pu.com' domain. While the individual URLs are marked as benign, the sheer volume and the heuristic firing suggest a link farm or SEO poisoning tactic, likely intended to lure users to malicious content or phishing pages. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9254

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1739734733733730/Ghosthunters-On-the-Trail-of-Mediums-Dowsers-Spirit-Seekers-and-Other-Investigators-of-America-s-Paranormal-World-by-John-B-Kachuba.pdf
    • http://cefasfese.4pu.com/2736730731739733/Ghosthunters-and-the-Muddy-Monster-of-Doom-Ghosthunters-4-by-Cornelia-Funke.pdf
    • http://cefasfese.4pu.com/7737731735731731/Ghosthunters-and-the-Incredibly-Revolting-Ghost-Ghosthunters-1-by-Cornelia-Funke.pdf
    • http://cefasfese.4pu.com/5736737734734738/The-Book-on-Mediums-Guide-for-Mediums-and-Invocators-by-Allan-Kardec.pdf
    • http://cefasfese.4pu.com/7738730736731735/2016-Europe-s-Best-Psychics-and-Mediums-Meilleurs-Voyants-Et-Mediums-de-France-Et-D-Europe-by-Jean-Maximillien-De-La-Croix-de-Lafayette.pdf
    • http://cefasfese.4pu.com/7738730736732730/2015-EUROPE-S-BEST-PSYCHICS-AND-MEDIUMS-Vol-2-Meilleurs-M-diums-et-Voyants-en-France-et-Europe-by-Jean-Maximillien-De-La-Croix-de-Lafayette.pdf
    • http://cefasfese.4pu.com/8730735731733733/Trail-of-the-Spirit-The-Mysteries-of-Medicine-Power-Revealed-by-George-Blondin.pdf
    • http://cefasfese.4pu.com/9738735732737/Trail-of-32-The-True-Story-of-a-Youthful-Spirit-That-Knew-Not-of-Defeat-by-Paul-Rega.pdf
    • http://cefasfese.4pu.com/1739731735732733/The-Seekers-The-Story-of-Man-s-Continuing-Quest-to-Understand-His-World-by-Daniel-J-Boorstin.pdf
    • http://cefasfese.4pu.com/8737735738736/The-Seekers-Kent-Family-Chronicles-3-by-John-Jakes.pdf
    • http://cefasfese.4pu.com/4737735731737737/Pathfinder-Blazing-a-New-Wilderness-Trail-in-Modern-America-by-Ron-Strickland.pdf
    • http://cefasfese.4pu.com/4735731733735730/The-Fort-Henry-Saga-Complete-in-One-Volume-Betty-Zane-The-Spirit-of-the-Border-The-Last-Trail-by-Zane-Grey.pdf
    • http://cefasfese.4pu.com/5730733732734731/Paranormal-America-Ghost-Encounters-UFO-Sightings-Bigfoot-Hunts-and-Other-Curiosities-in-Religion-and-Culture-by-Christopher-Bader.pdf
    • http://cefasfese.4pu.com/1731738735737737/The-Footloose-American-Following-the-Hunter-S-Thompson-Trail-Across-South-America-by-Brian-Kevin.pdf
    • http://cefasfese.4pu.com/8736736739735/Westward-to-Home-My-America-Joshua-s-Oregon-Trail-Diary-1-by-Patricia-Hermes.pdf
    • http://cefasfese.4pu.com/6734736731732736/The-World-of-the-Unexplained-An-Illustrated-Guide-to-the-Paranormal-by-Janet-Bord.pdf
    • http://cefasfese.4pu.com/2734739739739733/Obfuscate---A-Paranormal-Urban-Fantasy-World-of-Blood-2-by-Killion-Slade.pdf
    • http://cefasfese.4pu.com/9735737738736/Presidential-Trail-by-John-Lock.pdf
    • http://cefasfese.4pu.com/2736734731731735/The-Trail-of-the-Lonesome-Pine-by-John-Fox-Jr-.pdf
    • http://cefasfese.4pu.com/1734735739735732/John-s-Ghost-A-Coming-of-Age-Paranormal-Romantic-Flash-Fiction-by-E-Viona.pdf
    • http://cefasfese.4pu.com/7738730736732730/2015-EUROPE-S-BEST-PSYCHICS-AND-MEDIUMS-Vol-2-Meilleurs-M-diums-et-Voyants-en-France-et-Europe-by-Jean-Maximillien-De-La-Croix-de-Lafaye