Malicious PDF — malware analysis report

Static analysis result for SHA-256 c5a3cc3c775d5e66…

MALICIOUS

PDF

23.1 KB Created: 2019-05-02 07:42:59 +01:00 Authoring application: mPDF 5.7
MD5: 9a94fe3b29beb1786d54f78555048f8d SHA-1: a3f84325fba794dd08da5712ac101b6efae4b05f SHA-256: c5a3cc3c775d5e66558133b9abe1a68d505f9cd085e539b1a81f1e8b69bea59f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The primary heuristic indicates this is a PDF SEO link farm, suggesting a malicious intent to drive traffic to external content. While the specific URLs point to book titles, the sheer volume and the heuristic firing suggest a deceptive practice rather than legitimate content distribution. No scripts were extracted, and the document body was largely unreadable, limiting further analysis.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9776

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3734734738739739/Princeless-Vol-3-The-Pirate-Princess-by-Jeremy-Whitley.pdf
    • http://cefasfese.4pu.com/3734731737734730/Princeless-Raven-the-Pirate-Princess-Book-1-Captain-Raven-and-the-All-Girl-Pirate-Crew-by-Jeremy-Whitley.pdf
    • http://cefasfese.4pu.com/4736732737735732/PrinceLess-2-by-Jeremy-Whitley.pdf
    • http://cefasfese.4pu.com/3731733737735737/Princeless-Vol-2-Get-Over-Yourself-by-Jeremy-Whitley.pdf
    • http://cefasfese.4pu.com/7734739734737737/The-Unstoppable-Wasp-6-by-Jeremy-Whitley.pdf
    • http://cefasfese.4pu.com/7734739734738730/The-Unstoppable-Wasp-7-by-Jeremy-Whitley.pdf
    • http://cefasfese.4pu.com/7734739734732732/The-Unstoppable-Wasp-1-by-Jeremy-Whitley.pdf
    • http://cefasfese.4pu.com/7734739734732739/The-Unstoppable-Wasp-Vol-2-Agents-of-G-I-R-L-by-Jeremy-Whitley.pdf
    • http://cefasfese.4pu.com/7734739734738737/The-Unstoppable-Wasp-G-I-R-L-Power-by-Jeremy-Whitley.pdf
    • http://cefasfese.4pu.com/7734739736736731/The-Unstoppable-Wasp-2017-Issues-8-Book-Series-by-Jeremy-Whitley.pdf
    • http://cefasfese.4pu.com/8731737735734/Cursed-Pirate-Girl-The-Collected-Edition-Volume-One-by-Jeremy-A-Bastian.pdf
    • http://cefasfese.4pu.com/2731732732730730/Adventure-Dawns-Miya-Black-Pirate-Princess-1-by-Ben-White.pdf
    • http://cefasfese.4pu.com/6730735736736/The-Complete-Princess-Trilogy-Princess-Princess-Sultana-s-Daughters-and-Princess-Sultana-s-Circle-by-Jean-Sasson.pdf
    • http://cefasfese.4pu.com/4731732733737733/The-Pirate-Guidelines-A-Book-for-Those-Who-Desire-to-Keep-to-the-Code-and-Live-a-Pirate-s-Life-by-Joshamee-Gibbs.pdf
    • http://cefasfese.4pu.com/1730736737/Pirate-Hunters-Treasure-Obsession-and-the-Search-for-a-Legendary-Pirate-Ship-by-Robert-Kurson.pdf
    • http://cefasfese.4pu.com/4739734731739735/Pirate-Hunters-Treasure-Obsession-and-the-Search-for-a-Legendary-Pirate-Ship-by-Robert-Kurson.pdf
    • http://cefasfese.4pu.com/3731733731730733/Jeremy-James-oder-Elefanten-sitzen-nicht-auf-Autos-Adventures-with-Jeremy-James-1-by-David-Henry-Wilson.pdf
    • http://cefasfese.4pu.com/1731733734737730730/The-Works-Of-Jeremy-Bentham-Published-Under-The-Superintendence-Of-His-Executor-John-Bowring-Volume-2-by-Jeremy-Bentham.pdf
    • http://cefasfese.4pu.com/7730739738732738/The-Whole-Works-of-the-Right-Rev-Jeremy-Taylor-Worthy-Communicant-Supplement-of-Sermons-Collection-of-Offices-by-Jeremy-Taylor.pdf
    • http://cefasfese.4pu.com/7734732730732732/The-Pirate-and-the-Feisty-Maid-Part-Two---Her-New-Lover-The-Pirate-and-the-Feisty-Maid-2-by-Cali-MacKay.pdf
    • http://cefasfese.4pu.com/7734739736736731/The-Unstoppable-Wasp-2017-Issues-8-B