Malicious PDF — malware analysis report

Static analysis result for SHA-256 c43b260f26621d4d…

MALICIOUS

PDF

15.3 KB Created: 2019-11-09 19:19:49 +00:00 Authoring application: mPDF 5.7
MD5: 0335500ed5ae1fdb4f00a4d8c6ca65d2 SHA-1: f19259034b84b3c1ff279d4639139592dcc58a82 SHA-256: c43b260f26621d4d1d5e527a75fc4d4e81d77434990e5fdb520a2b26fda65f3c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a machine learning classifier and contains a large number of external links, indicating a potential link farm. While most extracted URLs were benign, the sheer volume and the heuristic firing suggest a malicious intent, possibly to direct users to harmful sites or for SEO manipulation. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4731734734731733/Stormy-Montana-Sky-Montana-Sky-3-by-Debra-Holland.pdf
    • http://cefasfese.4pu.com/2735730734736732/Healing-Montana-Sky-Montana-Sky-5-by-Debra-Holland.pdf
    • http://cefasfese.4pu.com/4731734734730733/Montana-Sky-Christmas-Montana-Sky-3-1-by-Debra-Holland.pdf
    • http://cefasfese.4pu.com/4731734734731732/Starry-Montana-Sky-Montana-Sky-2-by-Debra-Holland.pdf
    • http://cefasfese.4pu.com/4731734734731730/Sweetwater-Springs-Scrooge-Montana-Sky-4-2-by-Debra-Holland.pdf
    • http://cefasfese.4pu.com/2733730730736733/His-Blushing-Bride-Montana-Born-Brides-2-Love-in-Montana-4-by-Dani-Collins.pdf
    • http://cefasfese.4pu.com/4738731734737735/Montana-Christmas-Made-in-Montana-4-by-Jackie-Merritt.pdf
    • http://cefasfese.4pu.com/5731736738734733/Proceedings-of-the-Third-International-Workshop-on-Nude-Mice-Montana-State-University-Bozeman-Montana-September-6-9-1979-by-Norman-D-Reed.pdf
    • http://cefasfese.4pu.com/4737735738/Montana-Secret-Santa-Love-at-the-Chocolate-Shop-3-by-Debra-Salonen.pdf
    • http://cefasfese.4pu.com/3734737734737731/Montana-Sky-by-Nora-Roberts.pdf
    • http://cefasfese.4pu.com/4738738733738739/Montana-Sky-by-Nora-Roberts.pdf
    • http://cefasfese.4pu.com/3736732730738737/Ranger-Elemental-Paladins-4-by-Montana-Ash.pdf
    • http://cefasfese.4pu.com/2730739734731733/Montana-1948-by-Larry-Watson.pdf
    • http://cefasfese.4pu.com/3739730739738738/Montana-Rogue-by-Jessica-Douglass.pdf
    • http://cefasfese.4pu.com/1739735731739730/Mammals-of-Montana-by-Kerry-R-Foresman.pdf
    • http://cefasfese.4pu.com/1739735732735732/Wings-Over-Montana-by-Donald-M-Jones.pdf
    • http://cefasfese.4pu.com/3734739733739730/Montana-Cherries-The-Wildes-of-Birch-Bay-1-by-Kim-Law.pdf
    • http://cefasfese.4pu.com/4731734738736736/The-Montana-Bride-by-Jeannie-Watt.pdf
    • http://cefasfese.4pu.com/9730733737739732/Audibles-My-Life-in-Football-by-Joe-Montana.pdf
    • http://cefasfese.4pu.com/1731733735739737731/My-Home-s-in-Montana-by-Kareen-Bratt.pdf
    • http://cefasfese.4pu.com/4737735738/Montana-Secret-Santa-Love-at-the-Chocolate-Shop-3-by-Debra