Malicious PDF — malware analysis report

Static analysis result for SHA-256 f59e93c3f176ccc5…

MALICIOUS

PDF

18.9 KB Created: 2019-05-02 17:27:04 +01:00 Authoring application: mPDF 5.7
MD5: f2f73d5d96f9391f4d0caf7cb7d0497a SHA-1: 913e5441c6d1328ec206777a63bb6625431215b4 SHA-256: f59e93c3f176ccc5eceb2c3ff75fc4cea84542c34d0764d769cd083f1e04aa3d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a machine learning classifier and contains a large number of embedded external links, many of which are structured with numeric slugs. This suggests a link farm or redirection tactic. While the specific URLs extracted were classified as benign, the overall structure and heuristic firings indicate a malicious intent, likely to manipulate search engine results or redirect users to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9768

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4738739735731733/Sweet-Valley-High-Collection-Double-Love-Secrets-Playing-with-Fire-Sweet-Valley-High-1-3-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/5730733733730731/Sweet-Valley-Twins-Summer-Diaries-Collection-Elizabeth-Next-Stop-Jr-High-Jessica-Next-Stop-Jr-High-Sweet-Valley-Twins-Super-Edition-13-14-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/6739736736731732/Playing-for-Keeps-Sweet-Valley-High-49-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/2730731733730736/The-Patmans-of-Sweet-Valley-Sweet-Valley-High-Magna-Editions-12-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/6739736733730732/Dangerous-Love-Sweet-Valley-High-6-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/6739736736731730/Nowhere-to-Run-Sweet-Valley-High-25-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/6739736736731733/The-New-Elizabeth-Sweet-Valley-High-63-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/6739736736730735/Say-Goodbye-Sweet-Valley-High-23-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/6739736734731732/Crash-Landing-Sweet-Valley-High-20-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/2739732731730734/Beware-the-Wolfman-Sweet-Valley-High-106-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/9736737738734737/Aftershock-Sweet-Valley-High-Super-Edition-12-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/8739731735732/Sweet-Valley-Twins-Collection-Jessica-s-No-Angel-Happy-Mother-s-Day-Lila-Jessica-Takes-Charge-Sweet-Valley-Twins-Super-Edition-11-115-116-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/8737732737738/The-Sweet-Valley-Cleanup-Team-Sweet-Valley-Kids-27-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/1730737731730730737/Friend-Against-Friend-Sweet-Valley-High-69-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/1731730734734736/Best-Friends-Sweet-Valley-Twins-1-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/8734736739738/Get-the-Teacher-Sweet-Valley-Kids-46-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/1738730735737734/Teacher-s-Pet-Sweet-Valley-Twins-2-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/4735732735735733/Three-s-a-Crowd-Sweet-Valley-Twins-7-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/4738734735738735/The-Roommate-Sweet-Valley-University-Thriller-6-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/8732739739732/Robin-in-the-Middle-Sweet-Valley-Kids-40-by-Francine-Pascal.pdf
    • http://cefasfese.4pu.com/6739736736730735/Say-Goodbye-Swe