Malicious PDF — malware analysis report

Static analysis result for SHA-256 71331b1f1ae11bf9…

MALICIOUS

PDF

23.2 KB Created: 2019-11-07 11:42:03 +00:00 Authoring application: mPDF 5.7
MD5: c284eb93df3f9940d596e1829342c757 SHA-1: 44155d91d8655f1c9eb6bca7206754bc08f89a96 SHA-256: 71331b1f1ae11bf9c428ec14ad3d926d08cffd55f25b0f1a555ac97862bb2229
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDFs hosted on the domain 'cefasfese.4pu.com'. This is indicative of a link farm or SEO poisoning tactic, designed to drive traffic to potentially malicious or unwanted content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2739735736737732/Madeline-s-Christmas-by-Ludwig-Bemelmans.pdf
    • http://cefasfese.4pu.com/8731733738730734/When-You-Lunch-with-the-Emperor-The-Adventures-of-Ludwig-Bemelmans-by-Ludwig-Bemelmans.pdf
    • http://cefasfese.4pu.com/1731737738736739733/Madeline-and-Her-Dog-by-John-Bemelmans-Marciano.pdf
    • http://cefasfese.4pu.com/4737731732731/The-Golden-Basket-by-Ludwig-Bemelmans.pdf
    • http://cefasfese.4pu.com/1730737734737736735/Ludwig-Ganghofers-Gesammelte-Schriften-Vol-1-of-10-Volksausgabe-Mit-Dem-Bildnis-Des-Dichters-Von-Franz-Von-Stuck-by-Ludwig-Ganghofer.pdf
    • http://cefasfese.4pu.com/6734732736731731/The-Grand-Adventures-of-Madeline-Cain-Madeline-Cain-1-by-Emily-Craven.pdf
    • http://cefasfese.4pu.com/1731734733735735736/Ludwig-Van-Beethoven---8-Variations-on-t-Ndeln-Und-Scherzen-Woo76---A-Score-for-Solo-Piano-by-Ludwig-van-Beethoven.pdf
    • http://cefasfese.4pu.com/1730737734737738736/Ludwig-Ganghofer-Die-beliebtesten-Heimatromane-9-Titel-in-einem-Buch---Vollst-ndige-Ausgaben-Das-Gotteslehen-Der-Herrgottschnitzer-von-Ammergau-Besondere-Der-Dorfapostel-by-Ludwig-Ganghofer.pdf
    • http://cefasfese.4pu.com/3731739738730737/Planning-for-Freedom-and-Sixteen-Other-Essays-and-Addresses-Ludwig-Von-Mises-Also-the-Essential-Von-Mises-by-Ludwig-von-Mises.pdf
    • http://cefasfese.4pu.com/9738733739732730/Ludwig-Walrabe-s-Chronologie-Sammtlicher-Hamburger-Buhnen-Nebst-Angabe-Der-Meisten-Schauspieler-Sanger-Tanzer-Und-Musiker-Welche-Seit-1230-Bis-1846-an-Denselben-Engagirt-Gewesen-Und-Gastirt-Haben-Mit-Zwei-Stahlstichen-by-Ludwig-1808-1872-Wollrabe.pdf
    • http://cefasfese.4pu.com/1730738733735736736/Domicile-by-Madeline-Bussmann.pdf
    • http://cefasfese.4pu.com/2732733731739736/Illusions-by-Madeline-J-Reynolds.pdf
    • http://cefasfese.4pu.com/5736731739735/Circe-by-Madeline-Miller.pdf
    • http://cefasfese.4pu.com/6733735737730/The-Song-of-Achilles-by-Madeline-Miller.pdf
    • http://cefasfese.4pu.com/1732735736734735/Unattainable-Undeniable-3-by-Madeline-Sheehan.pdf
    • http://cefasfese.4pu.com/3733737730736731/Deception-of-a-Highlander-by-Madeline-Martin.pdf
    • http://cefasfese.4pu.com/4730736730738730/The-Spirit-Path-by-Madeline-Baker.pdf
    • http://cefasfese.4pu.com/8739730738732/By-Design-Medieval-2-by-Madeline-Hunter.pdf
    • http://cefasfese.4pu.com/4730733734730/Unbeautifully-Undeniable-2-by-Madeline-Sheehan.pdf
    • http://cefasfese.4pu.com/4731737731739731/Apache-Flame-by-Madeline-Baker.pdf