Malicious PDF — malware analysis report

Static analysis result for SHA-256 87012d705847b486…

MALICIOUS

PDF

18.1 KB Created: 2019-09-27 13:20:39 +01:00 Authoring application: mPDF 5.7
MD5: 06d5059faac622ed1c875259d8c79725 SHA-1: 70292a9f13325cc0da6b4480ec115b4dba8b1d2c SHA-256: 87012d705847b48609de0791be1534e58f943068511f8f7b0134f6ae268731f4
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links pointing to external PDFs hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730738732730738739/Grande-Polonaise-Brillante-Op-22-by-Fr-d-ric-Chopin.pdf
    • http://cefasfese.4pu.com/1730738731739731735/Andante-Spianato-and-Grande-Polonaise-Brillante-Op-22-by-Fr-d-ric-Chopin.pdf
    • http://cefasfese.4pu.com/7738735732734734/Polonaise-No-6-in-A-flat-Major-by-Fr-d-ric-Chopin.pdf
    • http://cefasfese.4pu.com/8735733735730732/La-Grande-Armee-Grande-Armee-Uniforms-of-La-Grande-Armee-Napoleonic-Tactics-Grande-Armee-Slang-List-of-Marshals-of-the-First-French-Empire-by-Source-Wikipedia.pdf
    • http://cefasfese.4pu.com/6734733732734733/Chopin-Waltzes-For-the-Piano-vol-27-by-Fr-d-ric-Chopin.pdf
    • http://cefasfese.4pu.com/5733737731737738/The-Awakening-1899-by-Kate-Chopin-Novel-Genre-Feminist-Literature-by-Kate-Chopin.pdf
    • http://cefasfese.4pu.com/5735731731732739/The-Awakening-By-Kate-Chopin-Illustrated-by-Kate-Chopin.pdf
    • http://cefasfese.4pu.com/4734735732738737/Polonaise-by-Piers-Paul-Read.pdf
    • http://cefasfese.4pu.com/1735732737732732/Polonaise-by-Jane-Aiken-Hodge.pdf
    • http://cefasfese.4pu.com/9739734737731734/Kate-Chopin-s-The-Awakening-by-Kate-Chopin.pdf
    • http://cefasfese.4pu.com/1731739737734731736/Edelsteine-Brillante-Zeugen-f-r-die-Erforschung-der-Erde-by-Florian-Neukirchen.pdf
    • http://cefasfese.4pu.com/1730738731738736732/The-Essentials-Supporting-Young-Children-with-Disabilities-in-the-Classroom-by-Pamela-Brillante.pdf
    • http://cefasfese.4pu.com/1730738731739731739/Valse-Brillante-Xylophone-Solo-with-Piano-by-George-Hamilton-Green.pdf
    • http://cefasfese.4pu.com/1730736731738738734/Eine-brillante-Masche-Die-fast-wahre-Geschichte-eines-L-gners-by-Jan-Zweyer.pdf
    • http://cefasfese.4pu.com/8734733736732739/85e-Anniversaire-Du-Centre-Scientifique-de-L-Academie-Polonaise-Des-Sciences-a-Paris-Session-Solennelle-by-Polska-Akademia-Nauk.pdf
    • http://cefasfese.4pu.com/6734733730733733/The-Storm-by-Kate-Chopin.pdf
    • http://cefasfese.4pu.com/7735739732735733/The-Awakening-by-Kate-Chopin.pdf
    • http://cefasfese.4pu.com/3734737734734737/The-Awakening-by-Kate-Chopin.pdf
    • http://cefasfese.4pu.com/3730733730732734/The-Awakening-by-Kate-Chopin.pdf
    • http://cefasfese.4pu.com/7733736737738/The-Awakening-by-Kate-Chopin.pdf