Malicious PDF — malware analysis report

Static analysis result for SHA-256 c7b93f576d5b42bb…

MALICIOUS

PDF

17.9 KB Created: 2019-11-07 15:46:57 +00:00 Authoring application: mPDF 5.7
MD5: 09952336464b73dca888dd51b3501b8e SHA-1: 60a42a4c8ff4c12680d76dbff624d92d44ebd9be SHA-256: c7b93f576d5b42bb0e5ddaa06bd01c22a9928e658eeed5a0f99049c18ee3a864
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, constituting a link farm. This technique is often used to artificially inflate search engine rankings or to distribute malicious content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm with 32 external links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9807

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7737732737735734/Pilates-Perfect-The-Complete-Guide-to-Pilates-Exercise-at-Home-by-Dianne-Daniels.pdf
    • http://cefasfese.4pu.com/7737732736730731/The-Pilates-Bible-The-Most-Comprehensive-and-Accessible-Guide-to-Pilates-Ever-by-Lynne-Robinson.pdf
    • http://cefasfese.4pu.com/7737732736730732/A-Pilates-Primer-The-Combo-Millennium-Edition-Return-to-Life-Through-Contrology-and-Your-Health-by-Joseph-Pilates.pdf
    • http://cefasfese.4pu.com/9739730738735736/Hot-Body-Pilates-Das-POP-Pilates-Programm-um-schlank-zu-werden-gesund-zu-essen-und-gl-cklich-zu-leben---in-jeder-Jahreszeit-by-Cassey-Ho.pdf
    • http://cefasfese.4pu.com/7737732737730730/Jennifer-Kries-Pilates-Plus-Method-The-Unique-Combination-of-Yoga-Dance-and-Pilates-by-Jennifer-Kries.pdf
    • http://cefasfese.4pu.com/7735733738731732/Being-amp-Vibration-by-Joseph-Rael.pdf
    • http://cefasfese.4pu.com/3735733737737730/A-Blast-from-the-Past-Lars-and-Rael-2-by-J-L-Merrow.pdf
    • http://cefasfese.4pu.com/7737732737734737/Pilates-on-the-go-by-Margot-Campbell.pdf
    • http://cefasfese.4pu.com/7737732737734735/Pilates-by-Yvonne-Worth.pdf
    • http://cefasfese.4pu.com/7737732736732735/Pilates-for-Beginners-by-Kellina-Stewart.pdf
    • http://cefasfese.4pu.com/7737732736732732/Pilates-Illustrated-by-Portia-Page.pdf
    • http://cefasfese.4pu.com/7737732736733732/Everyday-Pilates-Up-Up-and-Away-by-Alycea-Ungaro.pdf
    • http://cefasfese.4pu.com/7737732735732734/Pilates-for-Dummies-by-Ellie-Herman.pdf
    • http://cefasfese.4pu.com/7737732737735730/Pilates-Basics-by-Trevor-Blount.pdf
    • http://cefasfese.4pu.com/7737732736739739/Ultimate-Pilates-by-Dreas-Reyneke.pdf
    • http://cefasfese.4pu.com/7737732735732733/Pilates-Body-in-Motion-by-Alycea-Ungaro.pdf
    • http://cefasfese.4pu.com/7737732736732734/Yoga-amp-Pilates-for-Everyone-by-Fran-oise-Barbira-Freedman.pdf
    • http://cefasfese.4pu.com/7737732736733734/Pilates-Practice-Companion-by-Alycea-Ungaro.pdf
    • http://cefasfese.4pu.com/7737732737734731/Discovering-Pure-Classical-Pilates-by-Peter-Fiasca.pdf
    • http://cefasfese.4pu.com/8734735733730731/Je-me-mets-au-Pilates-pour-les-Nuls-by-Floriane-GARCIA.pdf
    • http://cefasfese.4pu.com/7737732737730730/Jennifer-Kries-Pilates-Plus-Method-The-Unique-Combination-of-Yoga-Dance-and-Pilates-by-Jennifer-Kries