Malicious PDF — malware analysis report

Static analysis result for SHA-256 2e689f5b41d9e9a0…

MALICIOUS

PDF

18.3 KB Created: 2020-01-02 06:04:26 +00:00 Authoring application: mPDF 5.7
MD5: 9fa15b04082a3d9fba0f1f68fc708ae7 SHA-1: d9a6b9cc9c04b215a744be2a748be66c339b08e8 SHA-256: 2e689f5b41d9e9a09bd15379c1b48028ac85d162069fbebe9379cf73d6954e96
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also flagged this PDF as malicious, supporting the assessment of a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730734733732735739/Der-Bergdoktor---Folge-1833-Bleib-bei-uns-Elli-by-Andreas-Kufsteiner.pdf
    • http://cefasfese.4pu.com/1730730737732731731/Der-Bergdoktor---Folge-1813-Verlassen-by-Andreas-Kufsteiner.pdf
    • http://cefasfese.4pu.com/1730735730732731734/Der-Bergdoktor---Folge-1695-Eine-ungeliebte-Frau-by-Andreas-Kufsteiner.pdf
    • http://cefasfese.4pu.com/9734738730738731/Der-Bergdoktor---Folge-1783-B-se-Frucht-der-Eifersucht-by-Andreas-Kufsteiner.pdf
    • http://cefasfese.4pu.com/9735730736737730/Der-Bergdoktor-1896---Heimatroman-Begegnung-in-der-Raunacht-by-Andreas-Kufsteiner.pdf
    • http://cefasfese.4pu.com/1730738739738732736/Elli-by-Tina-DeSalvo.pdf
    • http://cefasfese.4pu.com/3732730730730733/Dawn-by-the-River-by-Elli-Fitz.pdf
    • http://cefasfese.4pu.com/1730731731737735732/Minnesota-Winter-Eine-Liebe-in-der-Wildnis-by-Elli-H-Radinger.pdf
    • http://cefasfese.4pu.com/1731737730732732736/Voices-from-Finland-An-Anthology-of-Finlands-Verse-and-Prose-by-Elli-Tompuri.pdf
    • http://cefasfese.4pu.com/1730734732739735738/Ich-bleib-dann-mal-da-by-Stahn-Antonia.pdf
    • http://cefasfese.4pu.com/1730734732738738737/Bleib-gesund-by-Heere-Heeresma.pdf
    • http://cefasfese.4pu.com/3730737734736/Andrew-Jackson-The-Course-of-American-Democracy-1833-1845-by-Robert-V-Remini.pdf
    • http://cefasfese.4pu.com/1730734733731738736/Cantata-06-Bleib-Bei-Uns-Den-by-Johann-Sebastian-Bach.pdf
    • http://cefasfese.4pu.com/1730734732739736735/Bleib-franz-sisch-Ayvalik-by-Mustafa-Sa-lamer.pdf
    • http://cefasfese.4pu.com/1730734732739736736/Bleib-mein-goldener-Vogel-by-Hans-Stolp.pdf
    • http://cefasfese.4pu.com/1730734733731730734/Bleib-doch-einfach-mal-stehen-by-Brigitte-Emmerling.pdf
    • http://cefasfese.4pu.com/2735736736737732/The-Penal-Settlement-of-Macquarie-Harbour-1822-1833-An-Outline-of-its-History-by-Hans-Julen.pdf
    • http://cefasfese.4pu.com/6730735736732730/The-Business-of-Empire-The-East-India-Company-and-Imperial-Britain-1756-1833-by-H-V-Bowen.pdf
    • http://cefasfese.4pu.com/4730731734739735/Emancipation-Sugar-and-Federalism-Barbados-and-the-West-Indies-1833-1876-by-Claude-Levy.pdf
    • http://cefasfese.4pu.com/7736733731730731/En-Avant-Messieurs-Being-a-Tutor-s-Counsel-to-His-Pupils-by-George-Henry-Duncan-1833--1869-Mathias.pdf
    • http://cefasfese.4pu.com/3730737734736/Andrew-Jackson-The-Course-of-American-Democracy-1833-1845-by-R