Malicious PDF — malware analysis report

Static analysis result for SHA-256 2dd853be424cec88…

MALICIOUS

PDF

17.3 KB Created: 2019-06-04 13:00:23 +01:00 Authoring application: mPDF 5.7
MD5: 2ff2712fabdf7be27d3f9b8ac7efed4e SHA-1: 0d42461b015e8cc78dd0cdacaf8f651ee0f46c6d SHA-256: 2dd853be424cec88560081312f22b199bfd52a7d6fa4b2a86d92812e4f4944a9
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, as detected by the PDF_SEO_LINK_FARM heuristic. These URLs all point to the same domain, 'cefasfese.4pu.com', and appear to be designed to lure users into clicking them. The ML_NYX_PDF_MALICIOUS heuristic also flagged this PDF with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfes
    • http://cefasfese.4pu.com/4734732735737735/Time-Out-of-Mind-Cora-s-Bond-3-by-V-M-Black.pdf
    • http://cefasfese.4pu.com/3730738738730737/Blood-Bond-Cora-s-Choice-5-by-V-M-Black.pdf
    • http://cefasfese.4pu.com/4734732735737739/Rites-of-Blood-Cora-s-Choice-4-6-by-V-M-Black.pdf
    • http://cefasfese.4pu.com/3730738738731737/Blood-Born-Cora-s-Choice-2-by-V-M-Black.pdf
    • http://cefasfese.4pu.com/1731735732739737738/Blood-Rites-Cora-s-Choice-4-by-V-M-Black.pdf
    • http://cefasfese.4pu.com/1730731734733735730/How-To-Calm-Your-Mind-How-To-Calm-Your-Mind-In-Less-Time-by-sami-yaak.pdf
    • http://cefasfese.4pu.com/7739738733737737/HUMUS-the-black-gold-of-the-earth-by-Veronika-Bond.pdf
    • http://cefasfese.4pu.com/1733738730736736/Time-Stops-at-Shamli-and-Other-Stories-by-Ruskin-Bond.pdf
    • http://cefasfese.4pu.com/6738739737738/Time-To-Know-Time-Will-Reveal-4-by-Black-Coffee.pdf
    • http://cefasfese.4pu.com/1731735732739731734/Cora-Flash-and-the-Diamond-of-Madagascar-Cora-Flash-1-by-Tommy-Davey.pdf
    • http://cefasfese.4pu.com/1730738731734730737/Time-Magazine-The-Animal-Mind-by-Jeffrey-Kluger.pdf
    • http://cefasfese.4pu.com/1731730735730732735/Metapatterns-Across-Space-Time-and-Mind-by-Tyler-Volk.pdf
    • http://cefasfese.4pu.com/4735735735730731/Clint-Black----Spend-My-Time-Piano-Vocal-Chords-by-Clint-Black.pdf
    • http://cefasfese.4pu.com/1731732732738734738/Mysteries-of-Mind-Space-amp-Time-The-Unexplained-Volume-1-by-Orbis-Publishing.pdf
    • http://cefasfese.4pu.com/3732732734735731/DOING-TIME-on-Earth-Unmasking-the-Hidden-Mind-Directing-our-Lives-by-Catherine-Berger.pdf
    • http://cefasfese.4pu.com/8739735739733/A-Christmas-Bond-Sacred-Bond-0-5-by-Lee-Tobin-McClain.pdf
    • http://cefasfese.4pu.com/3734734737734737/Secret-Bond-Jamie-Bond-2-by-Gemma-Halliday.pdf
    • http://cefasfese.4pu.com/5733739738730739/Black-Tents-of-Arabia-Hungry-Mind-Find-Series-by-Carl-Reinhard-Raswan.pdf
    • http://cefasfese.4pu.com/3734736730737730/Broken-Silence-Opening-Your-Heart-and-Mind-to-Therapy--A-Black-Woman-s-Recovery-Guide-by-D-Kim-Singleton.pdf
    • http://cefasfese.4pu.com/5730739734736738/A-Maryland-Bride-in-the-Deep-South-The-Civil-War-Diary-of-Priscilla-Bond-by-Priscilla-Bond.pdf