Malicious PDF — malware analysis report

Static analysis result for SHA-256 bf46dd60f71ca510…

MALICIOUS

PDF

19.8 KB Created: 2019-05-01 16:19:09 +01:00 Authoring application: mPDF 5.7
MD5: 07c9ce4acb1a2982edc7af04782d280c SHA-1: bc48885b185f77348c5b752be17839829dfde3cd SHA-256: bf46dd60f71ca510b88fba10b0b231491c4cc94845e46290bc69e9e19f5f4432
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF was flagged by a machine learning classifier and contains a large number of external links, indicating a potential SEO spam or redirection attack. The document body is heavily corrupted, but the embedded URLs are visible and appear to be part of a link farm. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9780

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6734734738732731/The-Illumination-The-Awakening-Series-Book-4-by-Lisa-M-Lilly.pdf
    • http://cefasfese.4pu.com/2732735732737736/Boy-In-A-Band-Morgan-Mallory-Series-Book-1-by-Lisa-Loomis.pdf
    • http://cefasfese.4pu.com/6734734738737737/The-Book-of-Illumination-by-Maureen-Foley.pdf
    • http://cefasfese.4pu.com/4730739733733735/Mona-Lisa-Awakening-Mon-re-1-by-Sunny.pdf
    • http://cefasfese.4pu.com/2736731735731730/Mona-Lisa-Awakening-Mon-re-Children-of-the-Moon-1-by-Sunny.pdf
    • http://cefasfese.4pu.com/3737735733732730/50-Things-To-Know-To-Stick-With-A-Workout-Motivational-Tips-To-Start-The-New-You-Today-50-Things-to-Know-Healthy-Living-Series-Book-4-by-Lisa-M-Rusczyk.pdf
    • http://cefasfese.4pu.com/4737734734731732/Demons-A-Hunter-s-Novel-Book-1-by-Felicite-Lilly.pdf
    • http://cefasfese.4pu.com/6734734737730731/Chronicles-The-Library-of-Illumination-The-Library-of-Illumination-1-5-by-C-A-Pack.pdf
    • http://cefasfese.4pu.com/7735735733738733/James-Lee-Burke-Series-Reading-Order-amp-Checklist-Series-List-in-Order---Dave-Robicheaux-Series-Hackberry-Holland-Series-amp-All-Other-Books-Listabook-Series-Order-Book-29-by-Listabook.pdf
    • http://cefasfese.4pu.com/4730738733730734/The-Awakening-The-Outsider-Series-3-by-Lorhainne-Eckhart.pdf
    • http://cefasfese.4pu.com/2739739733739730/Awakening-The-Chrysalis-Series-1-by-Elene-Sallinger.pdf
    • http://cefasfese.4pu.com/1730736739738737732/Enchanted-Awakening-The-Enchantment-Series-by-Alanna-Wilson.pdf
    • http://cefasfese.4pu.com/3733735732739736/Yellow-Eyes-The-Awakening-Book-One-by-Skiagraphy.pdf
    • http://cefasfese.4pu.com/5739734739736738/Crystal-Casters-Awakening-Book-1-by-Jenn-Nixon.pdf
    • http://cefasfese.4pu.com/7730738739739739/Chameleon-The-Awakening-Book-1-of-The-Forest-People-by-Maggie-Faire.pdf
    • http://cefasfese.4pu.com/3739737734735/The-Book-Whisperer-Awakening-the-Inner-Reader-in-Every-Child-by-Donalyn-Miller.pdf
    • http://cefasfese.4pu.com/7734736735735737/THE-AWAKENING---A-Solitary-Soul-Feminist-Classics-Series-One-Women-s-Story-from-the-Turn-Of-The-Century-American-South-by-Kate-Chopin.pdf
    • http://cefasfese.4pu.com/3734730731734730/Who-Are-You-Again---Series-II-Do-You-Believe-by-Lisa-Goldin-Theunissen-.pdf
    • http://cefasfese.4pu.com/1732735739738738/Runic-Awakening-The-Runic-Series-1-by-Clayton-Taylor-Wood.pdf
    • http://cefasfese.4pu.com/2730737733736734/The-Guardians-Series-8-Book-Series-by-Meljean-Brook.pdf
    • http://cefasfese.4pu.com/7735735733738733/James-Lee-Burke-Series-Reading-Order-amp-Checklist-Series-List-in-Order-