Malicious PDF — malware analysis report

Static analysis result for SHA-256 43c1052d47e40144…

MALICIOUS

PDF

15.5 KB Created: 2019-05-02 17:11:35 +01:00 Authoring application: mPDF 5.7
MD5: b728a928d5e10cccbacb8ff9f54c342c SHA-1: 6c1caf7aad672ca6c775a2057fc7f78a06079a60 SHA-256: 43c1052d47e401446e483a7b33f3782914d3810abb8373bd0735fd600e36768b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier and contains a large number of embedded links, identified as a PDF_SEO_LINK_FARM heuristic. These links, such as http://cefasfese.4pu.com/6738737736735731/Too-Many-Cooks-Champagne-for-One-by-Rex-Stout.pdf, likely lead to malicious content or phishing pages. The document body was not sufficiently readable to determine a more specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6738737736735731/Too-Many-Cooks-Champagne-for-One-by-Rex-Stout.pdf
    • http://cefasfese.4pu.com/2736737737733737/Too-Many-Cooks-Nero-Wolfe-5-by-Rex-Stout.pdf
    • http://cefasfese.4pu.com/2739735739731738/Champagne-for-One-Nero-Wolfe-31-by-Rex-Stout.pdf
    • http://cefasfese.4pu.com/9737730739739739/Selections-from-the-Journals-of-Myron-Stout-by-Myron-Stout.pdf
    • http://cefasfese.4pu.com/9737731731733736/Journals-of-Myron-Stout-by-Myron-Stout.pdf
    • http://cefasfese.4pu.com/4738733731738733/Too-Many-Cooks-by-Dana-Bate.pdf
    • http://cefasfese.4pu.com/3731730734733/The-Pioneer-Woman-Cooks-by-Ree-Drummond.pdf
    • http://cefasfese.4pu.com/5730731735738737/Dave-Cooks-the-Turkey-by-Stuart-McLean.pdf
    • http://cefasfese.4pu.com/3734733739737733/Abbey-Cooks-Entertain-by-Pamela-Foster.pdf
    • http://cefasfese.4pu.com/5738730734730736/Canal-House-Cooks-Every-Day-by-Melissa-Hamilton.pdf
    • http://cefasfese.4pu.com/3738731733731731/Books-Cooks-and-Crooks-Novel-Idea-3-by-Lucy-Arlington.pdf
    • http://cefasfese.4pu.com/1731734732731731737/The-Proof-is-in-the-Pudding-A-Della-Cooks-Mystery-3-by-Melinda-Wells.pdf
    • http://cefasfese.4pu.com/6738737736732739/Champagne-by-Anton-Chekhov.pdf
    • http://cefasfese.4pu.com/2737730737739736/The-Champagne-Gang-by-punkturnedwriter.pdf
    • http://cefasfese.4pu.com/6738737736731737/Champagne-for-Two-by-Patrice-Wilton.pdf
    • http://cefasfese.4pu.com/4736738738737737/Champagne-by-Debbie-McGowan.pdf
    • http://cefasfese.4pu.com/3730738735739736/Darn-Good-Eats-The-Cookbook-for-Creative-Chefs-and-Reluctant-Cooks-by-Jodi-Ambrose.pdf
    • http://cefasfese.4pu.com/4733738733730735/Cooking-the-Roman-Way-Authentic-Recipes-from-the-Home-Cooks-and-Trattorias-of-Rome-by-David-Downie.pdf
    • http://cefasfese.4pu.com/3739738730733732/Champagne-and-Chocolate-by-Denyse-Bridger.pdf
    • http://cefasfese.4pu.com/6738737737731739/That-Champagne-Feeling-by-Claudia-Bishop.pdf
    • http://cefasfese.4pu.com/6738737736732739/Champagne-by-Anton-Che