Malicious PDF — malware analysis report

Static analysis result for SHA-256 8ed4fb4f9c2db10d…

MALICIOUS

PDF

17.9 KB Created: 2019-05-02 05:41:02 +01:00 Authoring application: mPDF 5.7
MD5: 19353c27c60a4ed065553630a9e44638 SHA-1: 4515b0d2d6c39b89ddd36fd8ca1303f10a43ac92 SHA-256: 8ed4fb4f9c2db10db0d743646d2048e87386f90a6407db0920b733e38daed370
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs pointing to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to a domain hosting numerous documents, likely as a lure or to obscure malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.co
    • http://cefasfese.4pu.com/8732736734731730/Elsa-Triolet-Und-Louis-Aragon-Die-Liebenden-Des-Jahrhunderts-by-Unda-Horner.pdf
    • http://cefasfese.4pu.com/5733737737733732/Le-Cr-ve-c-ur-by-Louis-Aragon.pdf
    • http://cefasfese.4pu.com/6734733730734737/Henri-Matisse-by-Louis-Aragon.pdf
    • http://cefasfese.4pu.com/3738739737737732/By-Chance-or-By-Design-The-Story-of-Premier-Designs-amp-Founders-Andy-and-Joan-Horner-by-Andrew-J-Horner.pdf
    • http://cefasfese.4pu.com/9738737731739731/Die-liebenden-der-Lubjanka-Die-liebenden-der-Lubjanka-by-Andrea-Rossi.pdf
    • http://cefasfese.4pu.com/8732736733732738/Triolet-Indifference-the-Hero-Music-and-Senescene-by-Dipanjan-Rai-Chaudhuri.pdf
    • http://cefasfese.4pu.com/6734732739730735/England-s-Queens-From-Catherine-of-Aragon-to-Elizabeth-II-From-Catherine-of-Aragon-to-Elizabeth-II-by-Elizabeth-Norton.pdf
    • http://cefasfese.4pu.com/8732736734730739/Mastering-The-Real-Dating-Game-How-To-Build-Authentic-Relationships-With-A-Genuine-Approach-by-Ellery-Triolet.pdf
    • http://cefasfese.4pu.com/7730732739734732/The-REV-of-Bouvier-by-Jon-Horner.pdf
    • http://cefasfese.4pu.com/9738737733737730/Die-Liebenden-aus-der-B-cherbox-3-by-Sophie-Andrell.pdf
    • http://cefasfese.4pu.com/9738737733737734/Die-Liebenden-von-Cap-Ferrat-by-Judith-Lawrenz.pdf
    • http://cefasfese.4pu.com/7733733734736734/Maia-A-Dinosaur-Grows-Up-by-John-R-Horner.pdf
    • http://cefasfese.4pu.com/1730733731734736730/The-Hamlyn-Pocket-Dictionary-Of-Business-Terms-by-C-F-Horner.pdf
    • http://cefasfese.4pu.com/4730734738733730/100-Ghosts-A-Gallery-of-Harmless-Haunts-by-Doogie-Horner.pdf
    • http://cefasfese.4pu.com/4733737735735738/Impressions-of-England-and-Ireland-A-Photojournal-by-Kathleen-Horner.pdf
    • http://cefasfese.4pu.com/9738737733737736/Die-anal-liebenden-Metzen-im-Gang-by-Bella-Gavin.pdf
    • http://cefasfese.4pu.com/5731730738732731/Summer-of-Stars-The-Past-Lives-of-Lola-Ray-1-by-Leslee-Horner.pdf
    • http://cefasfese.4pu.com/9738737733732739/Die-anal-liebenden-Hausgehilfinnen-wund-genagelt-by-Belinda-Reingard.pdf
    • http://cefasfese.4pu.com/9738737733737735/Die-schwanz-liebenden-Schlampen-hart-geritten-by-Bella-Arndt.pdf
    • http://cefasfese.4pu.com/9732736730732737/Die-sperma-liebenden-Auserw-hlten-gefesselt-und-gev-gelt-by-Daphne-Francis.pdf