Malicious PDF — malware analysis report

Static analysis result for SHA-256 84e878a111abcf18…

MALICIOUS

PDF

12.5 KB Created: 2019-05-04 12:18:37 +01:00 Authoring application: mPDF 5.7
MD5: b4465dbf018d3b79122d97c989f81a73 SHA-1: 09ae62408a83ecf28645d2d693bab4946fd7a87d SHA-256: 84e878a111abcf18aa0660457d18d87ac17c22e02f0cf79b9c06336f41a2b8c0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, primarily hosted on the 'cefasfese.4pu.com' domain. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also flagged this PDF as malicious, supporting the suspicious nature of the embedded links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8780

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6730739731731738/Portret-in-sepia-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/1730738737731730736/Portr-t-in-Sepia-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/2734737739735738/Ripper-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/5738732733731/Eva-Luna-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/3736736731735/Zorro-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/2738731738733732/Daughter-of-Fortune-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/2732736737738732/Daughter-of-Fortune-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/6737739738/In-the-Midst-of-Winter-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/3734732734737734/The-House-of-the-Spirits-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/4736733730733739/Daughter-of-Fortune-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/4735733730731732/Island-Beneath-the-Sea-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/2734739736734735/Maya-s-Notebook-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/3738738735733/Of-Love-and-Shadows-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/2734731736732736/Maya-s-Notebook-A-Novel-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/3732733731730/The-House-of-the-Spirits-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/4735734737735739/Ines-of-My-Soul-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/5735737738731/The-House-of-the-Spirits-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/2739730734734735/My-Invented-Country-A-Memoir-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/4730739733733/Forest-of-the-Pygmies-Eagle-and-Jaguar-3-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/7739731738730/My-Invented-Country-A-Nostalgic-Journey-Through-Chile-by-Isabel-Allende.pdf
    • http://cefasfese.4pu.com/2734