Malicious PDF — malware analysis report

Static analysis result for SHA-256 2425408d39f00503…

MALICIOUS

PDF

16.6 KB Created: 2019-06-13 11:33:15 +01:00 Authoring application: mPDF 5.7
MD5: f66b654b43393e0d983a4c66ccab8425 SHA-1: a09311c41179a4f77cb5db11f936de38ee042a73 SHA-256: 2425408d39f00503856e4c21c91fb28f3f52fc57f7f4f1e3d841e6df258a1423
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a lure to download further malicious content. No scripts were extracted from this sample, and the document body primarily consists of these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4735734732730/Light-on-Lucrezia-Lucrezia-Borgia-2-by-Jean-Plaidy.pdf
    • http://cefasfese.4pu.com/7737738736734731/Baci-Roventi---I-racconti-Segreti-di-Lucrezia-by-Lucrezia-.pdf
    • http://cefasfese.4pu.com/7736739735731738/Marc-S-guin-survol-Marc-S-guin-overview-essays-by-St-phane-Aquin-Robert-Enright-by-Doug-Fischer.pdf
    • http://cefasfese.4pu.com/1733734737739735/Marc-Brown-s-Playtime-Rhymes-A-Treasury-for-Families-to-Learn-and-Play-Together-by-Marc-Brown.pdf
    • http://cefasfese.4pu.com/7737738736734739/Letters-From-Derbyshire-by-Lucrezia-.pdf
    • http://cefasfese.4pu.com/7737738735736734/Lucrezia-in-Cile-by-Italy.pdf
    • http://cefasfese.4pu.com/7737738734731732/Lucrezia-by-John-Grahaam.pdf
    • http://cefasfese.4pu.com/7737738734737733/A-Judge-of-Their-Characters-by-Lucrezia-.pdf
    • http://cefasfese.4pu.com/7737738736735733/Their-Share-of-Vexations-by-Lucrezia-.pdf
    • http://cefasfese.4pu.com/7737738736734733/Sorn-English-Edition-by-Lucrezia.pdf
    • http://cefasfese.4pu.com/7737738734738733/Lucrezia-Borgia-by-Ferdinand-Gregorovius.pdf
    • http://cefasfese.4pu.com/7737738736735737/The-Knot-Nine-Moons-Nalee-7-by-Lucrezia.pdf
    • http://cefasfese.4pu.com/7737738734739739/Lucrezia-Borgia-The-Pope-s-Daughter-by-Unknown.pdf
    • http://cefasfese.4pu.com/7737738734737732/Il-Lupo-Nove-Lune-Nalee-Vol-1-by-Lucrezia.pdf
    • http://cefasfese.4pu.com/3736732736730731/Lucrezia-Borgia-and-the-Mother-of-Poisons-by-Roberta-Gellis.pdf
    • http://cefasfese.4pu.com/3739739736738733/Madonna-of-the-Seven-Hills-Lucrezia-Borgia-1-by-Jean-Plaidy.pdf
    • http://cefasfese.4pu.com/2730735732738732/Madonna-of-the-Seven-Hills-Lucrezia-Borgia-1-by-Jean-Plaidy.pdf
    • http://cefasfese.4pu.com/7737738734730734/Lucrezia-Borgia-A-Tragedy-1847-by-Victor-Hugo.pdf
    • http://cefasfese.4pu.com/7737738735735739/Courtesans-the-Forbidden-Diary-of-Lucrezia-Borgia-by-Hillary-Auteur.pdf
    • http://cefasfese.4pu.com/7737738734738739/The-Nobility-and-Excellence-of-Women-and-the-Defects-and-Vices-of-Men-by-Lucrezia-Marinella.pdf
    • http://cefasfese.4pu.com/7737738734738733/Lucrezia-Borgia-