Malicious PDF — malware analysis report

Static analysis result for SHA-256 5481e194c264c8d7…

MALICIOUS

PDF

21.8 KB Created: 2019-05-02 08:27:05 +01:00 Authoring application: mPDF 5.7
MD5: cdf8354012fb7fdb5727796489a1cbe0 SHA-1: 0ee93ef1bfd68567e6c7280c840475f54b5205cb SHA-256: 5481e194c264c8d764fa2e52415629e5d0e315eae2b2fd6d9d7c9155312f7ae8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF files hosted on the 'cefasfese.4pu.com' domain. While individual links are marked as benign, the sheer volume and the nature of the heuristic suggest a link farm or spamming operation. The ML classifier also flagged the PDF as malicious, reinforcing the suspicious nature of the content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3732734735730734/A-Walk-Through-The-Market-Flaming-Sword-Series-Book-1-by-Wade-Carey.pdf
    • http://cefasfese.4pu.com/2733735731735733/Top-Of-The-Mountain-a-story-about-real-love-Parables-Book-3-by-Wade-Carey.pdf
    • http://cefasfese.4pu.com/1730734731737730732/The-Flaming-Sword-by-George-Hellstern.pdf
    • http://cefasfese.4pu.com/5730733738739735/The-Flaming-Sword-Queen-of-Freedom-3-by-Christian-Jacq.pdf
    • http://cefasfese.4pu.com/2730737735736/A-Summer-Sentence-The-Barbourville-Series-Book-1-by-Carolynn-Carey.pdf
    • http://cefasfese.4pu.com/1731737738733731734/Tsukiji-Market-photo-book-100-photos-Tokyo-series-3-by-Akira-Okubo.pdf
    • http://cefasfese.4pu.com/2734732738734735/Alfred-Hitchcock-And-The-3-Investigators-Mystery-Of-The-Flaming-Footprints-Mystery-Of-The-Coughing-Dragon-Mystery-Of-The-Singing-Serpent-by-M-V-Carey.pdf
    • http://cefasfese.4pu.com/4735734737734731/The-Meat-Market-Series-Boxed-Set-Meat-Market-1-3-by-Baylee-Crush.pdf
    • http://cefasfese.4pu.com/8738735730735737/Thunder-Jim-Wade-The-Complete-Series-by-Henry-Kuttner.pdf
    • http://cefasfese.4pu.com/3739732730735735/And-Then-It-Happened-Book-One-by-M-Wade.pdf
    • http://cefasfese.4pu.com/4732738737738739/Giant-In-Gray-A-Biography-Of-Wade-Hampton-Of-South-Carolina-by-Manly-Wade-Wellman.pdf
    • http://cefasfese.4pu.com/1738730732734739/Shattered-Secrets-Book-of-Red-1-by-Krystal-Wade.pdf
    • http://cefasfese.4pu.com/7735735733738733/James-Lee-Burke-Series-Reading-Order-amp-Checklist-Series-List-in-Order---Dave-Robicheaux-Series-Hackberry-Holland-Series-amp-All-Other-Books-Listabook-Series-Order-Book-29-by-Listabook.pdf
    • http://cefasfese.4pu.com/4732733731736733/How-To-Market-A-Book-by-Joanna-Penn.pdf
    • http://cefasfese.4pu.com/1730731736738736739/A-Walk-to-Remember-Student-edition-Novel-Learning-Series-by-Nicholas-Sparks.pdf
    • http://cefasfese.4pu.com/2731732732737736/The-complete-A-Glimpse-into-Hell-series---5-books-195-chapters-1700-pages-600K-words-of-pure-gore-by-Wade-H-Garrett.pdf
    • http://cefasfese.4pu.com/9737733735736731/Sword-and-the-Sundial-The-Bible-adventure-series-by-Phyllis-Prokop.pdf
    • http://cefasfese.4pu.com/5734733731733735/Tactical-Management-in-the-Secular-Bear-Market-How-Tactical-Management-and-Market-Phases-Can-Help-Manage-Risk-and-Make-Money-in-the-Secular-Bear-Market-by-Tahar-Mjigal.pdf
    • http://cefasfese.4pu.com/9739733733732731/Smile-and-Walk-Away-Shatter-Book-1-by-Danielle-Riedel.pdf
    • http://cefasfese.4pu.com/4738738730739733/The-George-Carlin-Letters-The-Permanent-Courtship-of-Sally-Wade-by-Sally-Wade.pdf