Malicious PDF — malware analysis report

Static analysis result for SHA-256 54b1f475d4ce0068…

MALICIOUS

PDF

16.6 KB Created: 2020-01-02 06:02:50 +00:00 Authoring application: mPDF 5.7
MD5: c5fe2c9299957ebc5166a629fe8d6513 SHA-1: ab36b3b8f05aa204d4547d361a117d1cb94b6e6e SHA-256: 54b1f475d4ce0068c9575539a202e047e12256de10f54e39229f5eb5a038227f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier also flagged this PDF as malicious with a high probability. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the direct user-facing content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9810

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4739736730737736/Guarded-by-Charlotte-Stein.pdf
    • http://cefasfese.4pu.com/3738737738731733/The-Horizon-by-Charlotte-Stein.pdf
    • http://cefasfese.4pu.com/1732733734739737/Addicted-by-Charlotte-Stein.pdf
    • http://cefasfese.4pu.com/2734734737734739/Telling-Tales-by-Charlotte-Stein.pdf
    • http://cefasfese.4pu.com/4736737734733736/Forbidden-Under-the-Skin-2-by-Charlotte-Stein.pdf
    • http://cefasfese.4pu.com/2731731735736738/Never-Loved-Dark-Obsession-1-by-Charlotte-Stein.pdf
    • http://cefasfese.4pu.com/1730730739730739732/Tabulos-Erotische-Storys-by-Charlotte-Stein.pdf
    • http://cefasfese.4pu.com/4735732735733736/Love-s-Learning-Curve-Learning-Curve-1-by-Felicia-Lynn.pdf
    • http://cefasfese.4pu.com/2737734736735731/Stein-on-Writing-A-Master-Editor-of-Some-of-the-Most-Successful-Writers-of-Our-Century-Shares-His-Craft-Techniques-and-Strategies-by-Sol-Stein.pdf
    • http://cefasfese.4pu.com/1731738736734737730/Ball-Four-Plus-Ball-Five-An-Update-1970-1980-by-Jim-Bouton.pdf
    • http://cefasfese.4pu.com/7731736739735734/Gertrude-Stein-Gertrude-Stein-Gertrude-Stein-by-Marty-Martin.pdf
    • http://cefasfese.4pu.com/7732731733734739/Wellengefl-ster-I-Neunzehn-Seeg-nge-mit-Brina-Stein-by-Brina-Stein.pdf
    • http://cefasfese.4pu.com/5736737737731739/Dragon-Ball-Vol-8-Taopaipai-and-Master-Karin-Dragon-Ball-8-by-Akira-Toriyama.pdf
    • http://cefasfese.4pu.com/4734730735730733/Dragon-Ball-Vol-1-Dragon-Ball-VIZBIG-Edition-1-by-Akira-Toriyama.pdf
    • http://cefasfese.4pu.com/3732733734738737/Dragon-Ball-Z-Vol-12-Enter-Trunks-Dragon-Ball-Z-12-by-Akira-Toriyama.pdf
    • http://cefasfese.4pu.com/1730730733739734733/Dragon-Ball-Z-Vol-7-The-Ginyu-Force-Dragon-Ball-Z-7-by-Akira-Toriyama.pdf
    • http://cefasfese.4pu.com/4737731738731731/Dragon-Ball-Z-Vol-17-The-Cell-Game-Dragon-Ball-Z-17-by-Akira-Toriyama.pdf
    • http://cefasfese.4pu.com/4730731737731735/Dragon-Ball-Z-Vol-23-Boo-Unleashed-Dragon-Ball-Z-23-by-Akira-Toriyama.pdf
    • http://cefasfese.4pu.com/7735733738739738/Charlotte-The-Price-of-Vengence-Charlotte-and-Associates-Investigators-Book-1-by-James-Moore.pdf
    • http://cefasfese.4pu.com/4737735734738734/A-Study-in-Charlotte-Charlotte-Holmes-1-by-Brittany-Cavallaro.pdf
    • http://cefasfese.4pu.com/1731738736734737730/Ball-Four-Plus-Ball-Five-An-Update-1970-1980-by-Jim-B