Malicious PDF — malware analysis report

Static analysis result for SHA-256 f5a8ed626e2cb4b4…

MALICIOUS

PDF

15.6 KB Created: 2019-05-02 07:39:26 +01:00 Authoring application: mPDF 5.7
MD5: 9d6f2a8b390500e8a6af1eb1555af2cb SHA-1: f383253e741c4b129c38ce3f283ddbc21711c9d1 SHA-256: f5a8ed626e2cb4b4f83f98d2cd00478e9d5591dee14b24bc3a241cd477c517b4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded URLs pointing to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1738731739734737/Hidden-Secrets-The-Secrets-Saga-1-by-Angee-Taylor.pdf
    • http://cefasfese.4pu.com/1738732732734731/Deadly-Secrets-The-Secrets-Saga-2-by-Angee-Taylor.pdf
    • http://cefasfese.4pu.com/2736730733737730/Hidden-Secrets-by-Angee-Taylor.pdf
    • http://cefasfese.4pu.com/2730731736730732/Journey-The-Beginning-A-Prequel-to-the-Secrets-Saga-by-Angee-Taylor.pdf
    • http://cefasfese.4pu.com/3739730738732732/Hidden-Secrets-by-Cait-London.pdf
    • http://cefasfese.4pu.com/3735732739737733/Seventh-Mark---Part-1-Hidden-Secrets-1-1-by-W-J-May.pdf
    • http://cefasfese.4pu.com/5737730739737/Hidden-Bone-Secrets-1-by-Kendra-Elliot.pdf
    • http://cefasfese.4pu.com/2731730739736736/Hidden-Bone-Secrets-1-by-Kendra-Elliot.pdf
    • http://cefasfese.4pu.com/3731738734730733/Hidden-Secrets-Attract-Everything-You-Want-by-Carl-Nagel.pdf
    • http://cefasfese.4pu.com/2730730737738737/Constantine-s-Secret-The-Secrets-of-Hidden-Bay-2-by-Urcelia-Teixeira.pdf
    • http://cefasfese.4pu.com/6737734733737733/Hidden-Credit-Repair-Secrets-by-Mark-Clayborne.pdf
    • http://cefasfese.4pu.com/2731738737733730/Blood-Secrets-by-Karen-E-Taylor.pdf
    • http://cefasfese.4pu.com/2732739736736737/The-Book-of-Secrets-Unlocking-the-Hidden-Dimensions-of-Your-Life-by-Deepak-Chopra.pdf
    • http://cefasfese.4pu.com/3736737731734733/Hidden-Inheritance-Family-Secrets-Memory-and-Faith-by-Heidi-B-Neumark.pdf
    • http://cefasfese.4pu.com/1738733736731732/Stepbrother-Secrets-The-Monroe-Family-Secrets-Book-1-by-Lauren-Branford.pdf
    • http://cefasfese.4pu.com/6735731736736737/The-ABC-s-of-Real-Estate-Investing-The-Secrets-of-Finding-Hidden-Profits-Most-Investors-Miss-by-Ken-McElroy.pdf
    • http://cefasfese.4pu.com/2734733735731737/The-Secrets-of-the-Vanmars-Argetallam-Saga-2-by-Elisabeth-Wheatley.pdf
    • http://cefasfese.4pu.com/4732731736738733/The-Secrets-of-the-Montebellis-Secrets-1-by-Cheryl-Colwell.pdf
    • http://cefasfese.4pu.com/3735733730732736/Secrets-and-High-Spirits-Secrets-4-by-Lou-Harper.pdf
    • http://cefasfese.4pu.com/7737737731731738/Alluring-Secrets-Secrets-2-by-Lynne-Connolly.pdf