Malicious PDF — malware analysis report

Static analysis result for SHA-256 8008e8b4b9904c87…

MALICIOUS

PDF

16.6 KB Created: 2019-06-10 05:14:53 +01:00 Authoring application: mPDF 5.7
MD5: 23e082602cf1b8a8981390efc4344623 SHA-1: e00bb2e684d6ca4b6ff615b072a8d83cc1440c50 SHA-256: 8008e8b4b9904c87e4d5d393c8899d97a519e3513308f86d7a3e0f3057a164b4
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDFs on the domain 'cefasfese.4pu.com'. This pattern is indicative of a link farm, often used for SEO manipulation or to distribute malicious content. While no scripts were explicitly extracted, the heuristic 'PDF_SEO_LINK_FARM' and the ML classifier strongly suggest malicious intent. The embedded URLs are the primary IOCs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4730738738737738/Manhood-The-Rise-and-Fall-of-the-Penis-by-Mels-van-Driel.pdf
    • http://cefasfese.4pu.com/6738735735733734/Fitness-for-Penis-Top-Ten-Penis-Enlargement-Exercises-by-Peter-Pandore.pdf
    • http://cefasfese.4pu.com/7738733732737/Let-the-Sky-Fall-Trilogy-Let-the-Sky-Fall-Let-the-Storm-Break-Let-the-Wind-Rise-by-Shannon-Messenger.pdf
    • http://cefasfese.4pu.com/1734734736732730/Deeper-We-Fall-Fall-and-Rise-1-by-Chelsea-M-Cameron.pdf
    • http://cefasfese.4pu.com/1730738739732733733/Aufstieg-Und-Fall-Der-Stadt-Mahagonny-The-Rise-And-Fall-Of-The-City-Mahagonny-Libretto-by-Kurt-Weill.pdf
    • http://cefasfese.4pu.com/2739730736735734/Rise-and-Fall-H-E-R-O-3-by-Kevin-Rau.pdf
    • http://cefasfese.4pu.com/5737739735/The-Rise-and-Fall-of-D-O-D-O-by-Neal-Stephenson.pdf
    • http://cefasfese.4pu.com/4737734738734733/The-Rise-and-Fall-of-Athens-by-Plutarch.pdf
    • http://cefasfese.4pu.com/2736737732733739/The-Rise-and-Fall-of-the-House-of-Windsor-by-A-N-Wilson.pdf
    • http://cefasfese.4pu.com/9732733735736/The-Fall-of-the-Empire-The-Rise-of-the-Aztecs-5-by-Zoe-Saadia.pdf
    • http://cefasfese.4pu.com/2737736734731731/The-Rise-amp-Fall-of-Great-Powers-by-Tom-Rachman.pdf
    • http://cefasfese.4pu.com/4733735735733731/Together-We-Heal-Fall-and-Rise-4-by-Chelsea-M-Cameron.pdf
    • http://cefasfese.4pu.com/1730735731738/Last-Call-The-Rise-and-Fall-of-Prohibition-by-Daniel-Okrent.pdf
    • http://cefasfese.4pu.com/3735735735734737/The-Rise-and-Fall-of-Radiation-Canary-by-Geonn-Cannon.pdf
    • http://cefasfese.4pu.com/4734738734737734/Dynasty-The-Rise-and-Fall-of-the-House-of-Caesar-by-Tom-Holland.pdf
    • http://cefasfese.4pu.com/5736736736737734/The-Rise-and-Fall-of-Man-Decalogues-Book-One-by-Allen-L-Scarbrough.pdf
    • http://cefasfese.4pu.com/3734737731739734/Ricochet-Rise-amp-Fall-Book-1-by-Jessica-Wilde.pdf
    • http://cefasfese.4pu.com/1730736735737734737/The-Rise-and-Fall-of-the-Nuestra-Familia-by-Nina-Fuentes.pdf
    • http://cefasfese.4pu.com/2735731737735732/The-Rise-and-Fall-of-the-British-Empire-by-Lawrence-James.pdf
    • http://cefasfese.4pu.com/4732734738737734/Last-Lion-The-Fall-and-Rise-of-Ted-Kennedy-by-Peter-S-Canellos.pdf