Malicious PDF — malware analysis report

Static analysis result for SHA-256 f3739a40a3ed88e3…

MALICIOUS

PDF

18.3 KB Created: 2019-05-02 07:05:25 +01:00 Authoring application: mPDF 5.7
MD5: d5a9118a47dbc54d1d2b7e8968426e82 SHA-1: dd59e4095f17a6e87765b91e8036a1752831f622 SHA-256: f3739a40a3ed88e32a3956591216bd16b59e0240f0c873439a39ef6a6d09f6bf
130 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1204.002 Malicious Link: Malicious File

The PDF contains a mass of external links, with the primary heuristic identifying it as a link farm. The 'PDF_LAUNCH' heuristic indicates an attempt to exploit a vulnerability to launch external content. The ML classifier strongly suggests malicious intent. While the specific payload is not directly evident, the structure points to a downloader or exploit delivery mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9943

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Launch action high PDF_LAUNCH
    PDF contains a /Launch action with an unresolved or extension-less target — treat as potentially dangerous
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3731738735737738/Mated-to-the-Grizzly-Bears-in-Love-1-by-P-A-Vachon.pdf
    • http://cefasfese.4pu.com/5730731733730734/Why-Grizzly-Bears-Should-Wear-Underpants-by-Matthew-Inman.pdf
    • http://cefasfese.4pu.com/1739734732730734/Trail-Fever-Spin-doctors-rented-strangers-thumb-wrestlers-toe-suckers-grizzly-bears-and-other-creatures-on-the-road-to-the-White-H-by-Michael-Lewis.pdf
    • http://cefasfese.4pu.com/9738733738736733/Chicago-Bears-Where-Have-You-Gone-Dick-Butkus-Gale-Sayers-Mike-Ditka-and-Other-Bears-Greats-by-Lew-Freedman.pdf
    • http://cefasfese.4pu.com/4737738733735734/Equally-Shared-Parenting-Rewriting-the-Rules-for-a-New-Generation-of-Parents-by-Marc-Vachon.pdf
    • http://cefasfese.4pu.com/8733732739735732/Teddy-Bears-Teddy-Bears-by-William-B-Winburn.pdf
    • http://cefasfese.4pu.com/3735733737734739/Launch-the-Hunt-Grizzly-Rim-1-by-Mia-West.pdf
    • http://cefasfese.4pu.com/3739732730736736/Nothin-But-Trouble-The-Grizzly-MC-4-by-Jenika-Snow.pdf
    • http://cefasfese.4pu.com/5731734730738732/The-Black-Grizzly-of-Whiskey-Creek-by-Sid-Marty.pdf
    • http://cefasfese.4pu.com/4735736737731733/An-Outlaw-Wedding-The-Grizzly-MC-7-by-Jenika-Snow.pdf
    • http://cefasfese.4pu.com/2731730739732735/The-Outlaw-s-Obsession-The-Grizzly-MC-1-by-Jenika-Snow.pdf
    • http://cefasfese.4pu.com/3739734730735735/Clint-Grizzly-Ridge-1-by-Lynn-Hagen.pdf
    • http://cefasfese.4pu.com/1733735730730739/Hunt-The-Grizzly-Brothers-Chronicles-1-by-Alyssa-Rose-Ivy.pdf
    • http://cefasfese.4pu.com/1733739734733736/The-Year-of-the-Grizzly-Saga-of-the-Sierras-6-by-Brock-Thoene.pdf
    • http://cefasfese.4pu.com/4733736738731736/The-Outlaw-Stakes-His-Claim-The-Grizzly-MC-5-by-Jenika-Snow.pdf
    • http://cefasfese.4pu.com/2731733738738731/Mated-by-Rachael-Tulipano.pdf
    • http://cefasfese.4pu.com/2732732737739733/Mated-to-the-Devil-by-Eve-Langlais.pdf
    • http://cefasfese.4pu.com/7738730735730732/La-Chevauchee-de-Jehanne-La-Pucelle-de-Vaucouleurs-a-Chinon-Journal-de-Marche-de-Jehanne-La-Pucelle-by-Maurice-Vachon.pdf
    • http://cefasfese.4pu.com/3734737730739739/Mated-To-The-Alpha-King-by-AnastasiaL.pdf
    • http://cefasfese.4pu.com/3734735739739739/mated-to-the-alpha-by-Dana-Mayfield.pdf
    • http://cefasfese.4pu.com/3735733737734739/Launch-the-Hunt-Grizzly-Rim-1