Malicious PDF — malware analysis report

Static analysis result for SHA-256 0b23dedca3d04dd4…

MALICIOUS

PDF

20.3 KB Created: 2019-06-04 12:36:16 +01:00 Authoring application: mPDF 5.7
MD5: 5a86725041a7333e738b45cbeaa58176 SHA-1: 5e09187037d17298c2a75637a7bbf1aee5fd5dcc SHA-256: 0b23dedca3d04dd4ab7997f57b640cc4b744ee335ca7ea09a07e99fb0dc515ad
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9836

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1736737739738730/The-Ilia-Stone-by-R-J-Loom.pdf
    • http://cefasfese.4pu.com/9735734733733736/Rainbow-Loom-Magic-10-Awesome-New-And-Fun-Loom-Designs-For-Any-Level-Of-Skill-by-Brooke-Wegner.pdf
    • http://cefasfese.4pu.com/4738730730/The-Alchemists-of-Loom-Loom-Saga-1-by-Elise-Kova.pdf
    • http://cefasfese.4pu.com/9733735735734735/Franciscan-Prayer-by-Ilia-Delio.pdf
    • http://cefasfese.4pu.com/9733735737732730/Bite-A-Shifters-of-Theria-Novel-by-Ilia-Bera.pdf
    • http://cefasfese.4pu.com/9733735737731737/Phparchitect-s-Guide-to-PHP-Security-by-Ilia-Alshanetsky.pdf
    • http://cefasfese.4pu.com/1735736730731733/The-Weaver-s-Loom-by-P-L-Reid.pdf
    • http://cefasfese.4pu.com/9733735737735732/Simply-Bonaventure-An-Introduction-to-His-Life-Thought-and-Writings-by-Ilia-Delio.pdf
    • http://cefasfese.4pu.com/4739733739730737/Holiday-in-Stone-Creek-A-Stone-Creek-Christmas-At-Home-in-Stone-Creek-Stone-Creek-4-amp-6-by-Linda-Lael-Miller.pdf
    • http://cefasfese.4pu.com/4738736734735730/The-Loom-of-Youth-by-Alec-Waugh.pdf
    • http://cefasfese.4pu.com/1736736734730738/Loom-by-Th-r-se-Soukar-Chehade.pdf
    • http://cefasfese.4pu.com/9733735735734736/The-Emergent-Christ-Exploring-the-Meaning-of-Catholic-in-an-Evolutionary-Universe-by-Ilia-Delio.pdf
    • http://cefasfese.4pu.com/2731732735735736/Colors-in-the-Dreamweaver-s-Loom-by-Beth-Hilgartner.pdf
    • http://cefasfese.4pu.com/1731732730735737732/Adaptive-Image-Processing-Algorithms-for-Printing-Signals-and-Communication-Technology-by-Ilia-V-Safonov.pdf
    • http://cefasfese.4pu.com/2737738731735736/Daughter-of-the-Loom-Bells-of-Lowell-1-by-Tracie-Peterson.pdf
    • http://cefasfese.4pu.com/6731730731737730/Bead-Tapestry-Patterns-Loom-Adele-Besson-by-Renoir-by-Georgia-Grisolia.pdf
    • http://cefasfese.4pu.com/1731739731738734730/Rainbow-Loom---Fr-chtchen-Die-erste-deutsche-Kindle-Buch-Serie-ber-diese-tolle-Basteltechnik-by-Karolinchen.pdf
    • http://cefasfese.4pu.com/9735735735732731/While-America-Aged-How-Pension-Debts-Ruined-General-Motors-Stopped-the-NYC-Subways-Bankrupted-San-Diego-and-Loom-as-the-Next-Financial-Crisis-by-Roger-Lowenstein.pdf
    • http://cefasfese.4pu.com/7735736730732739/Dressed-Stone-Types-of-Stone-Details-Examples-by-Theodor-Hugues.pdf
    • http://cefasfese.4pu.com/1735738730730737/Cast-the-First-Stone-Ellie-Stone-Mysteries-5-by-James-W-Ziskin.pdf