Malicious PDF — malware analysis report

Static analysis result for SHA-256 be3ea6ff17e1b4a8…

MALICIOUS

PDF

15.2 KB Created: 2020-01-01 23:19:55 +00:00 Authoring application: mPDF 5.7
MD5: 1b537b44eb61b1ff84b9683c58492d43 SHA-1: 240c99f85931e29103888cc6e5039acb3e6ea044 SHA-256: be3ea6ff17e1b4a877831955ac80ec9c7b9aa8d1f96934625e96dc82b8d823da
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs appear to point to book titles and are marked as benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO spam or to distribute malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5732737737730736/Juliette-Drouet-La-Prisonniere-Sur-Parole-by-Henri-Troyat.pdf
    • http://cefasfese.4pu.com/7733736732739731/Chekhov-by-Henri-Troyat.pdf
    • http://cefasfese.4pu.com/5735731735732732/Sylvie-Viou-2-by-Henri-Troyat.pdf
    • http://cefasfese.4pu.com/8737730739730/Catherine-the-Great-by-Henri-Troyat.pdf
    • http://cefasfese.4pu.com/7733736732738737/Terrible-Tsarinas-Five-Russian-Women-in-Power-by-Henri-Troyat.pdf
    • http://cefasfese.4pu.com/8735739732738738/Un-job-de-r-ve-sign-Juliette-sign-Juliette-2-by-Sophie-Dieuaide.pdf
    • http://cefasfese.4pu.com/7733736739733736/La-Cour-de-Catherine-de-M-dicis-de-Charles-IX-de-Henri-III-et-de-Henri-IV-Tome-2-by-Marie-Armande-Jeanne-Gacon-Dufour.pdf
    • http://cefasfese.4pu.com/5732737736739739/Prisonni-re-de-l-Inceste-by-Annwn-Deith.pdf
    • http://cefasfese.4pu.com/5732737735739736/Galkiddek-T01-La-Prisonni-re-by-Frank-Giroud.pdf
    • http://cefasfese.4pu.com/5732737737738730/Une-Bien-Etrange-Prisonni-re-Emma-t-3-by-Agn-s-Massion.pdf
    • http://cefasfese.4pu.com/5730739734737730/Exile-in-Richmond-The-Confederate-Journal-of-Henri-Garidel-by-Henri-Garidel.pdf
    • http://cefasfese.4pu.com/6737738738734739/Henri-Michaux-Peindre-Composer-crire-by-Henri-Michaux.pdf
    • http://cefasfese.4pu.com/4738734738731730/On-Parole-by-Akira-Yoshimura.pdf
    • http://cefasfese.4pu.com/6734735733735737/Christmas-On-Parole-by-Stacy-Dawn.pdf
    • http://cefasfese.4pu.com/6734735733730730/Parole-in-disordine-by-Alena-Graedon.pdf
    • http://cefasfese.4pu.com/6734735733736732/Love-s-Parole-by-Irene-Northan.pdf
    • http://cefasfese.4pu.com/4730734731738733/Yeti-s-Parole-Officer-by-K-T-Bryski.pdf
    • http://cefasfese.4pu.com/6734735733736731/le-parole-segrete-del-cuore-by-Jennifer-Weiner.pdf
    • http://cefasfese.4pu.com/4734730733736736/HARD-JUSTICE-No-Parole-by-Alvin-Slater.pdf
    • http://cefasfese.4pu.com/6738736736736734/Parole-Dure-E-Chiare-by-Mario-Appelius.pdf
    • http://cefasfese.4pu.com/5732737737738730/Une-Bien-Etrange-Prisonni-re-Emma-t-3-by-Agn