Malicious PDF — malware analysis report

Static analysis result for SHA-256 c36c7f45d91662be…

MALICIOUS

PDF

15.6 KB Created: 2019-05-02 07:42:41 +01:00 Authoring application: mPDF 5.7 First seen: 2021-06-28
MD5: 4e40f356fc9f945c11c25f9ce13b5ebd SHA-1: 2ad7a09910a4ffc7c8ededeaaa478d69d66365a0 SHA-256: c36c7f45d91662bea560ba25308507dba6ebcc7d43f489f2bc7f53767723dead
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. While the URLs themselves are classified as benign, the sheer volume and the heuristic firing of PDF_SEO_LINK_FARM indicate a malicious attempt to manipulate search engine results or direct users to potentially harmful content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5730732733730733/You-ll-Think-of-Me-by-Robin-Lee-Hatcher.pdf In PDF document text
    • http://cefasfese.4pu.com/2730738733734/Beyond-the-Shadows-by-Robin-Lee-Hatcher.pdfIn PDF document text
    • http://cefasfese.4pu.com/1732734738739/Whispers-From-Yesterday-by-Robin-Lee-Hatcher.pdfIn PDF document text
    • http://cefasfese.4pu.com/4731736733739733/Four-Weddings-and-a-Kiss-by-Robin-Lee-Hatcher.pdfIn PDF document text
    • http://cefasfese.4pu.com/1731736731730/Betrayal-Where-The-Heart-Lives-2-by-Robin-Lee-Hatcher.pdfIn PDF document text
    • http://cefasfese.4pu.com/1731734734733/Love-Letter-to-the-Editor-by-Robin-Lee-Hatcher.pdfIn PDF document text
    • http://cefasfese.4pu.com/1732735738731/In-His-Arms-Coming-to-America-3-by-Robin-Lee-Hatcher.pdfIn PDF document text
    • http://cefasfese.4pu.com/2730735739734/Fit-to-Be-Tied-Sisters-of-Bethlehem-Springs-2-by-Robin-Lee-Hatcher.pdfIn PDF document text
    • http://cefasfese.4pu.com/1735732738738739/Sweet-Dreams-Drive-Hart-s-Crossing-4-by-Robin-Lee-Hatcher.pdfIn PDF document text
    • http://cefasfese.4pu.com/3734734738735736/Kiss-the-Bride-Three-Summer-Love-Stories-by-Robin-Lee-Hatcher.pdfIn PDF document text
    • http://cefasfese.4pu.com/1734730735737738/A-Vote-of-Confidence-Sisters-of-Bethlehem-Springs-1-by-Robin-Lee-Hatcher.pdfIn PDF document text
    • http://cefasfese.4pu.com/2738738737739739/Avatar-The-Last-Airbender-The-Promise-Part-1-The-Promise-1-by-Gene-Luen-Yang.pdfIn PDF document text
    • http://cefasfese.4pu.com/6734735737730/Avatar-The-Last-Airbender-The-Promise-Part-2-The-Promise-2-by-Gene-Luen-Yang.pdfIn PDF document text
    • http://cefasfese.4pu.com/1730733738738/Avatar-The-Last-Airbender-The-Promise-Part-1-The-Promise-1-by-Gene-Luen-Yang.pdfIn PDF document text
    • http://cefasfese.4pu.com/1730736730730738739/-I-promise-when-the-sun-comes-up-I-promise-I-ll-be-true-So-singt-Tom-Waits-Ich-will-auch-S-nger-werden-by-Michael-Stauffer.pdfIn PDF document text
    • http://cefasfese.4pu.com/1732734738/Broken-Promise-Promise-Falls-1-by-Linwood-Barclay.pdfIn PDF document text
    • http://cefasfese.4pu.com/5732734736732737/Trilogie-Promise-Tome-1---Promise-by-Ally-Condie.pdfIn PDF document text
    • http://cefasfese.4pu.com/1734735730733739/Promise-To-Love-The-Promise-1-by-Melissa-Silvey.pdfIn PDF document text
    • http://cefasfese.4pu.com/3738733734732/Promise-Me-Light-Promise-Me-2-by-Paige-Weaver.pdfIn PDF document text
    • http://cefasfese.4pu.com/2737731733736737/Broken-Promise-Promise-Me-2-by-Tara-Fox-Hall.pdfIn PDF document text