Malicious PDF — malware analysis report

Static analysis result for SHA-256 30442df7fb65aaa7…

MALICIOUS

PDF

17.3 KB Created: 2019-05-24 17:46:50 +01:00 Authoring application: mPDF 5.7
MD5: c15aa3fbb06fa9f0cabbb64f41eefdb6 SHA-1: e68178535d63002e0483d252605853f797f4e9fa SHA-256: 30442df7fb65aaa7e5b827e7f0d054fdbfd75f424d5a5031c8a93bcca634054b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded links, forming a link farm. These links likely serve as a lure to direct users to potentially malicious content hosted on the dominant domain 'cefasfese.4pu.com'. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3732735736734731/Rooks-of-the-Knot-Book-1-by-R-N-S-Iliffe.pdf
    • http://cefasfese.4pu.com/2739732735734734/The-Knot-Book-An-Elementary-Introduction-to-the-Mathematical-Theory-of-Knots-by-Colin-Conrad-Adams.pdf
    • http://cefasfese.4pu.com/1739732739736731/Rooks-and-Romanticide-by-J-I-Radke.pdf
    • http://cefasfese.4pu.com/3736730735738734/Rayne-Queen-Water-Supplier-of-the-World-by-Elizabeth-Rooks.pdf
    • http://cefasfese.4pu.com/5731731736737731/A-Modern-History-of-Tanganyika-by-John-Iliffe.pdf
    • http://cefasfese.4pu.com/6735732732731733/The-Gates-of-Troy-Adventures-of-Odysseus-2-by-Glyn-Iliffe.pdf
    • http://cefasfese.4pu.com/6735732732731734/The-Armour-of-Achilles-Adventures-of-Odysseus-3-by-Glyn-Iliffe.pdf
    • http://cefasfese.4pu.com/6735732732731735/The-Oracles-of-Troy-Adventures-of-Odysseus-4-by-Glyn-Iliffe.pdf
    • http://cefasfese.4pu.com/8735736736733732/The-Shopaholic-Series-6-Book-Bundle-Confessions-of-a-Shopaholic-Shopaholic-Takes-Manhattan-Shopaholic-Ties-the-Knot-Shopaholic-amp-Sister-Shopaholic-amp-Baby-Mini-Shopaholic-by-Sophie-Kinsella.pdf
    • http://cefasfese.4pu.com/8733733736730734/A-Knot-of-Trolls-by-J-M-Ney-Grimm.pdf
    • http://cefasfese.4pu.com/3736739739732736/He-Loves-Me-KNOT-by-R-C-Boldt.pdf
    • http://cefasfese.4pu.com/2739738737737732/501-Ways-to-Tie-a-Knot-Has-Been-3-by-Kat-DeSalle.pdf
    • http://cefasfese.4pu.com/3737730737739737/Gordian-Knot-by-Joseph-DiFrancesco.pdf
    • http://cefasfese.4pu.com/4737734730737732/The-Lover-s-Knot-by-Jana-G-Oliver.pdf
    • http://cefasfese.4pu.com/1735734730735730/A-Triple-Knot-by-Emma-Campion.pdf
    • http://cefasfese.4pu.com/4736737732738730/The-Hangman-s-Knot-by-David-Wiltse.pdf
    • http://cefasfese.4pu.com/4737737735739738/The-Knot-Fairy-With-CD-by-Bobbie-Hinman.pdf
    • http://cefasfese.4pu.com/3733730731735732/Risk-Everything-on-It-Ready-or-Knot-2-by-K-A-Mitchell.pdf
    • http://cefasfese.4pu.com/7737738736735737/The-Knot-Nine-Moons-Nalee-7-by-Lucrezia.pdf
    • http://cefasfese.4pu.com/2738735736732730/Knot-of-Stone-by-Nicolaas-Vergunst.pdf
    • http://cefasfese.4pu.com/8735736736733732/The-Shopaholic-Series-6-Book-Bundle-Confessions-of-a-Shopaholic-Shopaholic-Takes-Manhattan-Shopaholic-Ties-the-Knot-Shopaholic-amp-Sister-Shopaholic-amp