Malicious PDF — malware analysis report

Static analysis result for SHA-256 acc0d797916fb356…

MALICIOUS

PDF

17.0 KB Created: 2019-11-21 12:47:27 +00:00 Authoring application: mPDF 5.7
MD5: 00f2631c2540bff097d822ecc23d4b0d SHA-1: 0041f23313a65f35d6e94709f43acb27f46ebc37 SHA-256: acc0d797916fb356e1461fff49c7cfff6ed3f33938d1e45c959b9a6892f56a0a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. While most individual URLs are marked as benign, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' indicate a malicious intent, likely for SEO manipulation or to distribute further malicious content. No scripts were extracted, and the document body was heavily obfuscated, limiting deeper analysis.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6731738739731734/Fierce-Fragile-Hearts-by-Sara-Barnard.pdf
    • http://cefasfese.4pu.com/2736733737/Beautiful-Broken-Things-by-Sara-Barnard.pdf
    • http://cefasfese.4pu.com/1732733737733737/A-Heart-Broken-An-Everlasting-Heart-2-by-Sara-Barnard.pdf
    • http://cefasfese.4pu.com/8731731736731736/A-Heart-at-Home-An-Everlasting-Heart-3-by-Sara-Barnard.pdf
    • http://cefasfese.4pu.com/1734731736733733/Good-Bye-Chunky-Rice-by-Craig-Thompson.pdf
    • http://cefasfese.4pu.com/5737730736737736/Valley-of-the-Sugars-of-Salt-by-Anna-Tambour.pdf
    • http://cefasfese.4pu.com/8731731734730734/Christiaan-Barnard-One-Life-by-Christiaan-Barnard.pdf
    • http://cefasfese.4pu.com/1731734732730737732/Comparative-Study-of-Conditions-Affecting-the-Determination-of-Reducing-Sugars-by-Fehling-Solution-by-Francisco-Arguelles-Quisumbing.pdf
    • http://cefasfese.4pu.com/1731734732730736739/Comparative-Study-of-Conditions-Affecting-the-Determination-of-Reducing-Sugars-by-Fehling-Solution-by-Francisco-Arguelles-1893--Quisumbing.pdf
    • http://cefasfese.4pu.com/5738731732733732/Sara-s-Game-Sara-Winthrop-1-by-Ernie-Lindsey.pdf
    • http://cefasfese.4pu.com/1731731733730739733/Sara-and-the-Crying-Clown-Sara-4-by-Anna-Sellberg.pdf
    • http://cefasfese.4pu.com/3738739739731736/Sara-s-Game-Sara-Winthrop-1-by-Ernie-Lindsey.pdf
    • http://cefasfese.4pu.com/1730739737737731737/Dr-Bernstein-s-Diabetes-Solution-The-Complete-Guide-to-Achieving-Normal-Blood-Sugars-by-Richard-K-Bernstein.pdf
    • http://cefasfese.4pu.com/1731731733730739732/Watch-Out-Sara-Sara-5-by-Anna-Sellberg.pdf
    • http://cefasfese.4pu.com/2739736730733732/The-Map-and-The-Stone-by-Sarah-Barnard.pdf
    • http://cefasfese.4pu.com/3735737730730731/Behind-a-Mask--Or--A-Woman-s-Power-by-A-M-Barnard.pdf
    • http://cefasfese.4pu.com/8731731736738731/A-Murder-in-Mayfair-by-Robert-Barnard.pdf
    • http://cefasfese.4pu.com/8731731736730737/A-Little-Local-Murder-by-Robert-Barnard.pdf
    • http://cefasfese.4pu.com/8731731736730735/Tequila-and-Tea-Bags-by-Laura-Barnard.pdf
    • http://cefasfese.4pu.com/8731731736737735/Barnard-s-Star-by-Tamar-Yoseloff.pdf
    • http://cefasfese.4pu.com/1731734732730736739/Comparative-Study-of-Conditions-Affecting-the-Determination-of-Reducing-Sugars-by-Fehlin