Malicious PDF — malware analysis report

Static analysis result for SHA-256 c8307ebc36de6c48…

MALICIOUS

PDF

20.3 KB Created: 2019-11-09 22:57:59 +00:00 Authoring application: mPDF 5.7
MD5: aa9f263e9d2e78683738d253f1bdb638 SHA-1: 1521282b2bc411134f27e851fdd12e38058398db SHA-256: c8307ebc36de6c4804dfdfe0658cb82bede479212f6ed09ee0c93833862444aa
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier and contains a large number of external links, indicating a link farm. The primary heuristic identified a link farm with 25 external PDF links, the first of which is http://cefasfese.4pu.com/4733736737732730/To-Be-Real-Telling-the-Truth-and-Changing-the-Face-of-Feminism-by-Rebecca-Walker.pdf. This suggests a social engineering attack aimed at directing users to potentially malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9472

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4733736737732730/To-Be-Real-Telling-the-Truth-and-Changing-the-Face-of-Feminism-by-Rebecca-Walker.pdf
    • http://cefasfese.4pu.com/3736736739733733/Feminism-FOR-REAL-Deconstructing-the-Academic-Industrial-Complex-of-Feminism-by-Krysta-Williams.pdf
    • http://cefasfese.4pu.com/3732731739735731/Telling-the-Truth-Truth-or-Dare-2-by-Lee-Brazil.pdf
    • http://cefasfese.4pu.com/4737738730734736/The-Face-of-Love-Feminism-and-the-Beauty-Question-by-Ellen-Zetzel-Lambert.pdf
    • http://cefasfese.4pu.com/6736734738736735/Changing-Face-of-Britain-by-Edward-Hyams.pdf
    • http://cefasfese.4pu.com/4732737736737730/I-m-Telling-the-Truth-but-I-m-Lying-Essays-by-Bassey-Ikpi.pdf
    • http://cefasfese.4pu.com/3731739735734730/Feminism-The-Ugly-Truth-by-Mike-Buchanan.pdf
    • http://cefasfese.4pu.com/1730737738739738739/Pinky-Promise-A-Book-about-Telling-the-Truth-by-Vanita-Braver.pdf
    • http://cefasfese.4pu.com/1730733736733736736/The-Lhasa-Atlas-The-Changing-Face-of-a-City-by-Knud-Larsen.pdf
    • http://cefasfese.4pu.com/6734733739735738/Shooting-Straight-Telling-the-Truth-About-Guns-in-America-by-Wayne-LaPierre.pdf
    • http://cefasfese.4pu.com/8732735731737/Barmy-Army-The-Changing-Face-of-Football-Violence-by-Dougie-Brimson.pdf
    • http://cefasfese.4pu.com/5738739734733/Telling-the-Truth-The-Gospel-as-Tragedy-Comedy-and-Fairy-Tale-by-Frederick-Buechner.pdf
    • http://cefasfese.4pu.com/5733735733736735/Unsettling-the-Settler-Within-Indian-Residential-Schools-Truth-Telling-and-Reconciliation-in-Canada-by-Paulette-Regan.pdf
    • http://cefasfese.4pu.com/4732739736739/A-Smile-on-the-Face-of-the-Tiger-Amos-Walker-14-by-Loren-D-Estleman.pdf
    • http://cefasfese.4pu.com/3736736737736736/A-Shattered-Visage-The-Real-Face-of-Atheism-by-Ravi-Zacharias.pdf
    • http://cefasfese.4pu.com/9737736733737/Black-White-and-Jewish-by-Rebecca-Walker.pdf
    • http://cefasfese.4pu.com/2739733731734736/Real-Gorgeous-The-Truth-about-Body-and-Beauty-by-Kaz-Cooke.pdf
    • http://cefasfese.4pu.com/1731730738731734733/The-Truth-about-Search-Engine-Optimization-by-Rebecca-Lieb.pdf
    • http://cefasfese.4pu.com/8732730734731731/A-Truth-Telling-Manual-and-the-Art-of-Worldly-Wisdom-Being-a-Collection-of-the-Aphorisms-Which-Appear-in-the-Works-of-Baltasar-Gracian-by-Baltasar-Graci-n.pdf
    • http://cefasfese.4pu.com/1731734735733730/Consuming-Stories-Kara-Walker-and-the-Imagining-of-American-Race-by-Rebecca-Peabody.pdf
    • http://cefasfese.4pu.com/1730737738739738739/Pinky-Prom