Malicious PDF — malware analysis report

Static analysis result for SHA-256 2d711d37af713a31…

MALICIOUS

PDF

17.0 KB Created: 2019-09-27 13:28:31 +01:00 Authoring application: mPDF 5.7
MD5: 13783bced172eb6c7118f1f6e8d04692 SHA-1: 29bc0bea7c80a37584ad74daa7b5584d0191bcda SHA-256: 2d711d37af713a317c6ab95000265672297d79b8052fe7698fecce72a9c966da
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1737730739731739/Suite-Seventeen-by-Portia-Da-Costa.pdf
    • http://cefasfese.4pu.com/4734733738736736/How-to-Seduce-a-Billionaire-by-Portia-Da-Costa.pdf
    • http://cefasfese.4pu.com/5732734735739730/Ritual-of-the-Red-Chair-by-Portia-Da-Costa.pdf
    • http://cefasfese.4pu.com/5733733731739734/Noces-sensuelles-Jeux-de-hasard-T3-by-Portia-Da-Costa.pdf
    • http://cefasfese.4pu.com/2736731731734739/The-Accidental-Call-Girl-Accidental-1-by-Portia-Da-Costa.pdf
    • http://cefasfese.4pu.com/3730732736735738/At-the-Heart-of-the-Deep-A-Falling-in-Deep-Collection-Novella-The-Orotavan-Mermaid-Tales-1-by-Carrie-L-Wells.pdf
    • http://cefasfese.4pu.com/2733731733734735/Devil-and-the-Deep-Deep-Six-2-by-Julie-Ann-Walker.pdf
    • http://cefasfese.4pu.com/3735737739735739/The-Sweet-Under-His-Skin-by-Portia-Gray.pdf
    • http://cefasfese.4pu.com/7737732736732732/Pilates-Illustrated-by-Portia-Page.pdf
    • http://cefasfese.4pu.com/6735736734734/Lesson-Learned-It-Is-What-It-Is-by-Portia-A-Cosby.pdf
    • http://cefasfese.4pu.com/1732732732739734/Portia-Angelbound-Offspring-2-by-Christina-Bauer.pdf
    • http://cefasfese.4pu.com/4733731733731737/Shattered-Pieces-If-I-Break-4-by-Portia-Moore.pdf
    • http://cefasfese.4pu.com/9736735739733730/Deep-Drilling-in-Crystalline-Bedrock-The-Deep-Gas-Drilling-in-the-Siljan-Impact-Structure-Sweden-and-Astroblemes-by-A-Boden.pdf
    • http://cefasfese.4pu.com/4734735733732736/In-Too-Deep-In-Too-Deep-1-by-Eliza-Jane.pdf
    • http://cefasfese.4pu.com/2733735739736735/Jewel-of-the-Thames-Portia-Adams-Adventures-1-by-Angela-Misri.pdf
    • http://cefasfese.4pu.com/6735739735731736/Deep-Blue-The-Complete-Series-Deep-Blue-1-3-by-Amie-Nichols.pdf
    • http://cefasfese.4pu.com/3739731735739734/An-Indian-Portia-Selected-Writings-of-Cornelia-Sorabji-1866-to-1954-by-Kusoom-Vadgama.pdf
    • http://cefasfese.4pu.com/5730731737734734/The-Best-Man-by-Annabelle-Costa.pdf
    • http://cefasfese.4pu.com/7732733736734735/Deep-Blue-Deep-Blue-Trilogy-1-by-Kathleen-Duhamel.pdf
    • http://cefasfese.4pu.com/9734737734737/The-Scent-of-a-Lie-by-paulo-da-costa.pdf