Malicious PDF — malware analysis report

Static analysis result for SHA-256 74e4b6a9ca19799b…

MALICIOUS

PDF

17.4 KB Created: 2019-06-04 08:23:34 +01:00 Authoring application: mPDF 5.7
MD5: 24a59576ba8a63c0c4210f3ad2d48227 SHA-1: 5e08cc9dcdacf42d12db62cd8d0444b8729c3231 SHA-256: 74e4b6a9ca19799b22eaa653771bdb4d69eca7359dc71e0b89a43a4660f1bb49
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on the suspicious domain 'cefasfese.4pu.com'. This heuristic firing, combined with the ML classifier, indicates a likely attempt to direct users to a content farm or potentially malicious resources. No scripts were extracted, and the document body was heavily obfuscated, preventing a more detailed analysis of the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4739739733733731/Mark-the-Match-Boy-Or-Richard-Hunter-s-Ward-by-Horatio-Alger-Jr-.pdf
    • http://cefasfese.4pu.com/8735737734734/The-Collected-Works-of-Horatio-Alger-57-Novels-Complete-in-One-Volume-Unexpurgated-Edition-by-Horatio-Alger-Jr-.pdf
    • http://cefasfese.4pu.com/5738730734733733/From-Canal-Boy-to-President-by-Horatio-Alger-Jr-.pdf
    • http://cefasfese.4pu.com/4739739736738737/In-Search-of-Treasure-by-Horatio-Alger-Jr-.pdf
    • http://cefasfese.4pu.com/4732734730736734/Ragged-Dick-Or-Street-Life-in-New-York-with-the-Boot-Blacks-by-Horatio-Alger-Jr-.pdf
    • http://cefasfese.4pu.com/2731736734731736/The-Perfect-Match-by-Denise-Hunter.pdf
    • http://cefasfese.4pu.com/3730736734731738/The-Match-The-Day-the-Game-of-Golf-Changed-Forever-by-Mark-Frost.pdf
    • http://cefasfese.4pu.com/1731730732737732736/Mizelle-Creek-The-Hunter-Legacy-Book-1-by-Thome-Ward.pdf
    • http://cefasfese.4pu.com/1730735737731734733/Rewiring-the-Real-In-Conversation-with-William-Gaddis-Richard-Powers-Mark-Danielewski-and-Don-Delillo-by-Mark-C-Taylor.pdf
    • http://cefasfese.4pu.com/9739735731739731/Mark-Twain-by-Geoffrey-C-Ward.pdf
    • http://cefasfese.4pu.com/3732738730733735/Game-Set-Match-Love-Match-1-by-Nana-Malone.pdf
    • http://cefasfese.4pu.com/3736738730731734/No-Match-for-Love-A-Match-Made-in-Texas-3-by-Carol-Cox.pdf
    • http://cefasfese.4pu.com/2731736737732739/Game-Set-Match-Love-Match-1-by-Nana-Malone.pdf
    • http://cefasfese.4pu.com/2731737730735735/Miss-Match-No-Match-for-Love-1-by-Lindzee-Armstrong.pdf
    • http://cefasfese.4pu.com/7736738735732730/Not-Your-Match-No-Match-for-Love-2-by-Lindzee-Armstrong.pdf
    • http://cefasfese.4pu.com/2734732732735731/Cyberforce-Hunter-Killer-by-Mark-Waid.pdf
    • http://cefasfese.4pu.com/2734731734731739/Hunter-Killer-Volume-1-by-Mark-Waid.pdf
    • http://cefasfese.4pu.com/7736738734735739/An-Unlikely-Match-Match-1-by-Barbara-Dunlop.pdf
    • http://cefasfese.4pu.com/1731739736734737732/Yamada-Monogatari-Demon-Hunter-by-Richard-Parks.pdf
    • http://cefasfese.4pu.com/8739730732738739/Hunter-Killer---Lautlos-und-t-dlich-Amerikas-geheimer-Drohnenkrieg---Der-Insiderbericht-by-T-Mark-McCurley.pdf