Malicious PDF — malware analysis report

Static analysis result for SHA-256 be5fd271620459cc…

MALICIOUS

PDF

25.2 KB Created: 2019-05-02 06:17:33 +01:00 Authoring application: mPDF 5.7
MD5: be190022b0be219391034136309e69b6 SHA-1: eaca985686fe0f719733d5399a71b4c62a80a63c SHA-256: be5fd271620459cc2c54e51c75a94786fe3ccb8eca3d805cbafca258949e0f3a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs were individually classified as benign, the sheer volume and the ML_NYX_PDF_MALICIOUS firing indicate a malicious intent. The primary purpose appears to be directing users to a link farm, potentially for SEO manipulation or to serve as a gateway to further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1739737733734735/The-Social-Life-of-Poetry-Appalachia-Race-and-Radical-Modernism-by-Chris-Green.pdf
    • http://cefasfese.4pu.com/9731737737736/The-Social-Life-of-DNA-Race-Reparations-and-Reconciliation-After-the-Genome-by-Alondra-Nelson.pdf
    • http://cefasfese.4pu.com/2738737738734730/The-Southern-Poetry-Anthology-Volume-III-Contemporary-Appalachia-by-William-Wright.pdf
    • http://cefasfese.4pu.com/7736737731738731/Postmodernity-USA-The-Crisis-of-Social-Modernism-in-Postwar-America-by-Anthony-B-Woodiwiss.pdf
    • http://cefasfese.4pu.com/2738737739738738/Hell-and-Ohio-Stories-of-Southern-Appalachia-by-Chris-Holbrook.pdf
    • http://cefasfese.4pu.com/2734737731736734/Radical-Judaism-Rethinking-God-and-Tradition-by-Arthur-Green.pdf
    • http://cefasfese.4pu.com/3734731738733730/Green-Rage-Radical-Environmentalism-and-the-Unmaking-of-Civilization-by-Christopher-Manes.pdf
    • http://cefasfese.4pu.com/4739736735737/Race-Decoded-The-Genomic-Fight-for-Social-Justice-by-Catherine-Bliss.pdf
    • http://cefasfese.4pu.com/4735732739736737/White-Women-Race-Matters-The-Social-Construction-of-Whiteness-by-Ruth-Frankenberg.pdf
    • http://cefasfese.4pu.com/1730736730737736734/Facing-the-Other-Interdisciplinary-Studies-on-Race-Gender-and-Social-Justice-in-Ireland-by-Borb-la-Farag-.pdf
    • http://cefasfese.4pu.com/4731735735731733/The-Invention-of-the-White-Race-Volume-I-Racial-Oppression-and-Social-Control-by-Theodore-W-Allen.pdf
    • http://cefasfese.4pu.com/4735738739735736/A-Poetics-of-Global-Solidarity-Modern-American-Poetry-and-Social-Movements-by-Clemens-Spahr.pdf
    • http://cefasfese.4pu.com/1739737734734733/Coal-Towns-Life-Work-and-Culture-in-Company-Towns-of-Southern-Appalachia-1880-1960-by-Crandall-A-Shifflett.pdf
    • http://cefasfese.4pu.com/3734734735733733/Above-the-Dreamless-Dead-World-War-I-in-Poetry-and-Comics-by-Chris-Duffy.pdf
    • http://cefasfese.4pu.com/7733736731738731/There-s-a-Pain-in-my-Brain-Funny-Medical-Poetry-for-Adults-by-Chris-Honsberger.pdf
    • http://cefasfese.4pu.com/5735734738731738/The-Radical-Edge-Stoke-Your-Business-Amp-Your-Life-and-Change-the-World-by-Steve-Farber.pdf
    • http://cefasfese.4pu.com/8730733738733/The-Path-of-Razors-Vampire-Babylon-5-by-Chris-Marie-Green.pdf
    • http://cefasfese.4pu.com/1730731736737737737/Felix-Holt-the-Radical-by-George-Eliot-Complete-Set-Volume-1-2-and-3-in-Three-Volume-Social-Novel-Illustrated-By-Frank-T-Merrill-1848-1936-by-George-Eliot.pdf
    • http://cefasfese.4pu.com/4739737730736730/Only-The-Good-Die-Young-Jensen-Murphy-Ghost-for-Hire-1-by-Chris-Marie-Green.pdf
    • http://cefasfese.4pu.com/5732735739735733/Life-of-Riley-Tails-of-a-Treasured-Life-by-Chris-Rosinski.pdf
    • http://cefasfese.4pu.com/773673