Malicious PDF — malware analysis report

Static analysis result for SHA-256 204472733ce5fc54…

MALICIOUS

PDF

14.7 KB Created: 2019-05-03 05:56:47 +01:00 Authoring application: mPDF 5.7
MD5: 9ededefd3e1215f90198bce5ed8e0129 SHA-1: 6b98969c98bacfe93cb6eebc1c10a327b073a325 SHA-256: 204472733ce5fc548e5f2c25e496e57caf82c10560f53394f3e870c2cc812f91
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with a high score. The embedded URLs, while individually marked as benign, are part of a link farm hosted on 'cefasfese.4pu.com', suggesting a potential SEO poisoning or redirection scheme to deliver malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese
    • http://cefasfese.4pu.com/2739736733734736/The-Greatest-Knight-William-Marshal-2-by-Elizabeth-Chadwick.pdf
    • http://cefasfese.4pu.com/2735731738733739/The-Conquest-by-Elizabeth-Chadwick.pdf
    • http://cefasfese.4pu.com/3731734732730739/The-Conquest-by-Elizabeth-Chadwick.pdf
    • http://cefasfese.4pu.com/8732731733739/The-Leopard-Unleashed-by-Elizabeth-Chadwick.pdf
    • http://cefasfese.4pu.com/8735733737733/Daughters-of-the-Grail-by-Elizabeth-Chadwick.pdf
    • http://cefasfese.4pu.com/8731737739733/The-Wild-Hunt-by-Elizabeth-Chadwick.pdf
    • http://cefasfese.4pu.com/5733737737739/Lady-of-the-English-by-Elizabeth-Chadwick.pdf
    • http://cefasfese.4pu.com/4735733732732732/The-Winter-Crown-by-Elizabeth-Chadwick.pdf
    • http://cefasfese.4pu.com/2731735732735738/The-Winter-Mantle-by-Elizabeth-Chadwick.pdf
    • http://cefasfese.4pu.com/5737730735738/The-Marsh-King-s-Daughter-by-Elizabeth-Chadwick.pdf
    • http://cefasfese.4pu.com/3731734734732735/For-the-King-s-Favor-William-Marshal-4-by-Elizabeth-Chadwick.pdf
    • http://cefasfese.4pu.com/1730739737735730730/Die-H-terin-der-Krone-Historischer-Roman-by-Elizabeth-Chadwick.pdf
    • http://cefasfese.4pu.com/1734737731737/The-Little-Knight-by-Elizabeth-Johnson.pdf
    • http://cefasfese.4pu.com/3738733733732734/A-Winter-s-Knight-by-Elizabeth-Cole.pdf
    • http://cefasfese.4pu.com/3738738731739730/TNE-Vampire-Fleets-by-Frank-Chadwick.pdf
    • http://cefasfese.4pu.com/1731737739731737734/Murder-Reigns-in-Wallisrose-by-Leise-Chadwick.pdf
    • http://cefasfese.4pu.com/1731732736737737730/A-Prince-of-Mars-Space-1889-amp-Beyond-5-by-Frank-Chadwick.pdf
    • http://cefasfese.4pu.com/3736736735739733/Swan-Knight-s-Son-The-Green-Knight-s-Squire-1-Moth-amp-Cobweb-1-by-John-C-Wright.pdf
    • http://cefasfese.4pu.com/1733732738730736/Hard-Day-s-Knight-Black-Knight-Chronicles-1-by-John-G-Hartness.pdf
    • http://cefasfese.4pu.com/1731732736739730739/Conklin-s-Atlas-of-the-Worlds-Space-1889-by-Frank-Chadwick.pdf