Malicious PDF — malware analysis report

Static analysis result for SHA-256 31de3d187b9320b2…

MALICIOUS

PDF

15.3 KB Created: 2019-05-05 05:01:19 +01:00 Authoring application: mPDF 5.7
MD5: be5760051e541eac035ea50377dc48f1 SHA-1: d620281a718ae2108c19cf45894699e8bab7c6a7 SHA-256: 31de3d187b9320b2ac28e9a7bb334e9676e076d0076ee14a2ffe5843b545aaaa
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3735734737734738/Hanna-s-Daughters-by-Marianne-Fredriksson.pdf
    • http://cefasfese.4pu.com/3731734733733736/Hanna-s-Daughters-by-Marianne-Fredriksson.pdf
    • http://cefasfese.4pu.com/3730732733731730/Simon-and-the-Oaks-by-Marianne-Fredriksson.pdf
    • http://cefasfese.4pu.com/6734732736730737/Elisabeth-s-Daughter-by-Marianne-Fredriksson.pdf
    • http://cefasfese.4pu.com/4732731739733731/Hanna-s-Diary-1938-1941-Czechoslovakia-to-Canada-by-Hanna-Spencer.pdf
    • http://cefasfese.4pu.com/1731737733730738739/Marianne-Williamson-on-Relationships-Romantic-Delusions-and-Friendship-by-Marianne-Williamson.pdf
    • http://cefasfese.4pu.com/8738736738735739/Risk-f-r-regn-by-Anna-Fredriksson.pdf
    • http://cefasfese.4pu.com/8738736736739731/Der-Fr-hlingsclub-Roman-by-Anna-Fredriksson.pdf
    • http://cefasfese.4pu.com/1737735735733738/The-Daughters-Join-the-Party-The-Daughters-4-by-Joanna-Philbin.pdf
    • http://cefasfese.4pu.com/1735733733732730/The-Daughters-Break-the-Rules-The-Daughters-2-by-Joanna-Philbin.pdf
    • http://cefasfese.4pu.com/8738736737738731/Materials-Processing-During-Casting-by-Hasse-Fredriksson.pdf
    • http://cefasfese.4pu.com/1737735735734730/The-Daughters-Take-the-Stage-The-Daughters-3-by-Joanna-Philbin.pdf
    • http://cefasfese.4pu.com/8738736737737732/A-Century-of-Science-Publishing-A-Collection-of-Essays-by-Einar-H-Fredriksson.pdf
    • http://cefasfese.4pu.com/1731737733732732733/Marianne-Williamson-on-Death-Dying-by-Marianne-Williamson.pdf
    • http://cefasfese.4pu.com/4731735736737/The-Daughters-The-Daughters-1-by-Joanna-Philbin.pdf
    • http://cefasfese.4pu.com/2731732738732734/The-Daughters-The-Daughters-1-by-Joanna-Philbin.pdf
    • http://cefasfese.4pu.com/2733731735738734/Daughters-of-the-Moon-Volume-1-Daughters-of-the-Moon-1-3-by-Lynne-Ewing.pdf
    • http://cefasfese.4pu.com/9730738735731734/Marianne-Williamson-on-Abundance-by-Marianne-Williamson.pdf
    • http://cefasfese.4pu.com/1731737733730739733/Marianne-Williamson-On-Commitment-by-Marianne-Williamson.pdf
    • http://cefasfese.4pu.com/3739739734731732/Marianne-Williamson-On-Spirituality-by-Marianne-Williamson.pdf
    • http://cefasfese.4pu.com/1737735735734730/The-Daughters-Take-the-Stage-The-Daughters-