Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e76fbb45ae4923b…

MALICIOUS

PDF

14.6 KB Created: 2019-05-02 05:31:47 +01:00 Authoring application: mPDF 5.7
MD5: fb0768a46a2e273f41849b427882d97d SHA-1: 32250ca43289c4d25e21c4637469a569aaac8e6d SHA-256: 1e76fbb45ae4923bdc896e8a793662f97d0cee6ecb09eb649d406c5e93361c49
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a PDF_SEO_LINK_FARM heuristic firing, indicating a large number of embedded external links. These links, predominantly hosted on 'cefasfese.4pu.com', are likely part of a link farm designed to distribute malicious content or lead users to phishing pages. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6734737738736736/Vincent-Van-Gogh-Art-Life-And-Letters-by-Bernard-Zurcher.pdf
    • http://cefasfese.4pu.com/3733734738731735/Vincent-van-Gogh-His-Inner-Struggle-Secrets-of-Van-Gogh-by-Liesbeth-Heenk.pdf
    • http://cefasfese.4pu.com/8730736739737733/Van-Gogh-Portrait-de-l-artiste-Les-secrets-de-Van-Gogh-t-1-by-Liesbeth-Heenk.pdf
    • http://cefasfese.4pu.com/9738730732731736/Bernard-Herrmann-Film-Music-And-Narrative-by-Graham-Donald-Bruce.pdf
    • http://cefasfese.4pu.com/6736732733739737/What-Makes-A-Van-Gogh-A-Van-Gogh-by-Richard-Muhlberger.pdf
    • http://cefasfese.4pu.com/6736732734733730/Van-Gogh-At-The-Van-Gogh-Museum-by-Ronald-de-Leeuw.pdf
    • http://cefasfese.4pu.com/6736732734731730/Van-Gogh-Van-Gogh-by-Andrew-Hughes.pdf
    • http://cefasfese.4pu.com/1730734732730735735/The-Letters-of-Vincent-van-Gogh-902-pieces-ebook-by-Vincent-van-Gogh.pdf
    • http://cefasfese.4pu.com/6736732733737731/Complete-Letters-of-Vincent-Van-Gogh-by-Vincent-van-Gogh.pdf
    • http://cefasfese.4pu.com/3735738730730/The-Letters-of-Vincent-van-Gogh-by-Vincent-van-Gogh.pdf
    • http://cefasfese.4pu.com/9733731730732737/Bernard-Melzer-Solves-Your-Money-Problems-by-Bernard-Meltzer.pdf
    • http://cefasfese.4pu.com/5733730733732738/Bruce-s-History-Lessons-The-First-Five-Years-2001---2006-by-Bruce-Kauffmann.pdf
    • http://cefasfese.4pu.com/9739738738732738/Ein-B-r-erobert-die-Welt-Bruce-auf-Mallorca---Bruce-in-Wien-by-Gitta-Gampe.pdf
    • http://cefasfese.4pu.com/1730737730732731/Bruce-Coville-s-Book-of-Monsters-Tales-to-Give-You-the-Creeps-by-Bruce-Coville.pdf
    • http://cefasfese.4pu.com/6736732734733731/Van-Gogh-by-Federica-Armiraglio.pdf
    • http://cefasfese.4pu.com/6736732735732738/Van-Gogh-by-Frank-Elgar.pdf
    • http://cefasfese.4pu.com/6736732734732730/Van-Gogh-by-Melissa-McQuillan.pdf
    • http://cefasfese.4pu.com/6736732732737736/The-Lost-Van-Gogh-by-A-J-Zerries.pdf
    • http://cefasfese.4pu.com/8731733730735737/Van-Gogh-by-Judy-Sund.pdf
    • http://cefasfese.4pu.com/6736732732737739/Van-Gogh-by-Mike-Venezia.pdf
    • http://cefasfese.4pu.com/9