Malicious PDF — malware analysis report

Static analysis result for SHA-256 8deaaf1608bd6d06…

MALICIOUS

PDF

17.0 KB Created: 2019-05-02 07:53:54 +01:00 Authoring application: mPDF 5.7 First seen: 2020-12-28
MD5: ea92e26d9ef6ac02bf2b398f11a93f50 SHA-1: 16673ca2c9e0d115d6dd2dfaa4cabe722dd8d9ce SHA-256: 8deaaf1608bd6d063d9ae793b5314f759521ead088c827387ae27bb3209cfcac
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also flagged this PDF as malicious, supporting the suspicious nature of the embedded URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5736731738737730/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll-with-an-excerpt-from-The-Life-and-Letters-of-Lewis-Carroll-by-Lewis-Carroll.pdf In PDF document text
    • http://cefasfese.4pu.com/6736733735739732/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/8732735733732737/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/1730737739733731733/Alice-s-Adventures-in-Wonderland-amp-Through-the-Looking-Glass-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/2736734735731732/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/5737735730731732/Alice-s-Adventures-in-Wonderland-amp-Through-the-Looking-Glass-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/5734735738734738/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/5733732735732737/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/7739737733732738/Alice-s-Adventures-in-Wonderland-amp-Through-the-Looking-Glass-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/8737736739730/The-Collected-Stories-of-Lewis-Carroll-Alice-in-Wonderland-Through-the-Looking-Glass-Phantasmagoria-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/1737737739738738/Alice-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/5735733734738738/Alice-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/9730735731732731/Alice-in-Wonderland-And-Through-the-Looking-Glass-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/5739735737730736/Alice-in-Wonderland-Through-the-Looking-Glass-amp-Other-Comic-Pieces-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/5738733739738/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/7733735737736738/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/9732735735738739/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/4736734739730732/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/4739733737735736/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdfIn PDF document text
    • http://cefasfese.4pu.com/3737732731737739/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdfIn PDF document text