Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd4879404f238a22…

MALICIOUS

PDF

22.6 KB Created: 2019-05-02 05:29:55 +01:00 Authoring application: mPDF 5.7
MD5: a3da967d2a5da8558a1141a92d18c466 SHA-1: 0de76cb8027b375f27550180d5dec107a4d2c415 SHA-256: fd4879404f238a22b05349a92cec2b62e12c373f1f38f6a715537898f64a48c2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF_SEO_LINK_FARM heuristic indicates the presence of a large number of external links within the document, suggesting a link farm designed to redirect users. The ML_NYX_PDF_MALICIOUS classifier also flagged this PDF with high confidence. While no scripts were extracted, the sheer volume of links and the heuristic firing strongly suggest a malicious intent, likely to lure users to potentially harmful websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6730733731737730/Concubine-at-Birth-The-Warrior-Kings-Series-by-Cloe-Black.pdf
    • http://cefasfese.4pu.com/6730733732733738/Typical-Drama-with-Cloe-New-School-new-Life-by-Cloe-Demartino.pdf
    • http://cefasfese.4pu.com/6730733732733736/Judas-the-Apostle-The-Cloe-Lejeune-Series-Book-1-by-Van-R-Mayhall-Jr-.pdf
    • http://cefasfese.4pu.com/1730734739734738736/Holly-Black-Books-2017-Checklist-Reading-Order-of-Spiderwick-Chronicles-Curse-Workers-Series-Lucifer-Series-Magisterium-Series-and-list-of-all-Holly-Black-Books-Over-55-Books-by-Hot-Series.pdf
    • http://cefasfese.4pu.com/2736736733733739/Silent-Warrior-Dragon-Kings-0-5-by-Lindsey-Piper.pdf
    • http://cefasfese.4pu.com/1737733733739731/In-the-Service-of-the-King-Vampire-Warrior-Kings-1-by-Laura-Kaye.pdf
    • http://cefasfese.4pu.com/1732735731731733/The-Devil-s-Concubine-The-Devil-of-Ponong-series-1-by-Jill-Braden.pdf
    • http://cefasfese.4pu.com/6730733730739735/Cl-e-Lust-Perversiones-al-O-do-by-Cl-e-LUST.pdf
    • http://cefasfese.4pu.com/2739735739736737/Black-The-Birth-of-Evil-The-Circle-1-by-Ted-Dekker.pdf
    • http://cefasfese.4pu.com/4734733730730730/Black-The-Birth-of-Evil-The-Circle-The-Graphic-Novel-1-by-Ted-Dekker.pdf
    • http://cefasfese.4pu.com/6730733731737731/Howl-And-Growl-Wolf-And-Cat-Shifter-Paranormal-Romance-Howl-And-Growl-Series-Book-1-by-Cloe-Cullen.pdf
    • http://cefasfese.4pu.com/8731739733734732/The-Birth-of-Writing-The-Emergence-of-Man-Series-by-Robert-Claiborne.pdf
    • http://cefasfese.4pu.com/2735731737732734/Black-Lion-s-Bride-Warrior-2-by-Tina-St-John.pdf
    • http://cefasfese.4pu.com/9732731731738/The-Warrior-s-Way-Pre-Aztec-series-3-by-Zoe-Saadia.pdf
    • http://cefasfese.4pu.com/1730736739736736733/Cracking-the-Einstein-Code-Relativity-and-the-Birth-of-Black-Hole-Physics-by-Fulvio-Melia.pdf
    • http://cefasfese.4pu.com/8732733732737/The-Warrior-s-Game-The-Warriors-Series-3-by-Denise-Domning.pdf
    • http://cefasfese.4pu.com/4735731737739734/Manifesting-Your-Spirit-Way-Of-The-Warrior-Series-by-Graham-Cooke.pdf
    • http://cefasfese.4pu.com/1730734739734738730/HOLLY-BLACK-SERIES-READING-ORDER-MAGISTERIUM-BOOKS-MODERN-TALE-OF-FAERIE-BOOKS-SPIDERWICK-CHRONICLES-BOOKS-BEYONG-SPIDERWICK-CHRONICLES-GOOD-NEIGHBORS-BOOKS-BY-HOLLY-BLACK-by-List-Series.pdf
    • http://cefasfese.4pu.com/3735735736731730/Code-Name-War-of-Stones-A-Warrior-s-Challenge-series-Book-7-by-Natasza-Waters.pdf
    • http://cefasfese.4pu.com/9733731735737736/The-Joyful-Child-for-Birth-to-Three-Years-Michael-Olaf-s-Essential-Montessori-Series-by-Susan-Stephenson.pdf
    • http://cefasfese.4pu.com/2736736733733739/Silent-Warrior-Dragon-Kings-0-5-b