Malicious PDF — malware analysis report

Static analysis result for SHA-256 9885585619f95e01…

MALICIOUS

PDF

19.0 KB Created: 2019-05-26 23:26:51 +01:00 Authoring application: mPDF 5.7
MD5: a134f1ffab15ebc01c867c34fd271643 SHA-1: 0b48944900dffa86d4f0baad125d034c4f8f2d71 SHA-256: 9885585619f95e017950b33ad527d444348a71221afafd1bad009a935f1e09e5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, all hosted on the domain 'cefasfese.4pu.com'. This pattern is indicative of a link farm or a phishing lure designed to direct users to potentially malicious content. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8733732732738/Play-With-Fire-Kate-Shugak-5-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/2732731738732737/Though-Not-Dead-Kate-Shugak-18-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/8734736730736/Blood-Will-Tell-Kate-Shugak-6-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731734736731/The-Kate-Shugak-Novels-Vol-3-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/8735731735735/Hunter-s-Moon-Kate-Shugak-9-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/8735738738733/A-Taint-In-The-Blood-Kate-Shugak-14-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731734737733/Les-enqu-tes-de-Kate-Shugak---Int-grale-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/8736735730732/A-Fatal-Thaw-Kate-Shugak-2-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731732737730/Any-Taint-of-Vice-Kate-Shugak-19-5-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731732737736/Cherchez-la-Femme-Kate-Shugak-17-5-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/3738736737735737/A-Grave-Denied-Kate-Shugak-13-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/1734733733736739/Whisper-To-The-Blood-Kate-Shugak-16-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731734736736/No-Fixed-Line-Kate-Shugak-22-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/8734730735735/A-Cold-Blooded-Business-Kate-Shugak-4-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731735733731/Dana-Stabenow-Books-Checklist-Reading-Order-Of-Coast-Guard-Series-in-Order-Kate-Shugak-Series-in-Order-Silk-and-Song-Trilogy-Star-Svensdotter-Series-in-Order-and-List-of-All-Dana-Stabenow-Books-by-Kevin-Hanson.pdf
    • http://cefasfese.4pu.com/7737731735734731/DANA-STABENOW-SERIES-READING-ORDER-A-READ-TO-LIVE-LIVE-TO-READ-CHECKLIST-STAR-SVENSDOTTER-SERIES-KATE-SHUGAK-SERIES-LIAM-CAMPBELL-SERIES-COAST-GUARD-SILK-AND-SONG-SERIES-ALASKA-SERIES-by-Rita-Bookman.pdf
    • http://cefasfese.4pu.com/7737731734732733/Cheechako-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731734731739/The-Mysterious-North-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/4731733735731738/Wild-Crimes-by-Dana-Stabenow.pdf
    • http://cefasfese.4pu.com/7737731735732739/Taint-in-the-Blood-by-Dana-Stabenow.pdf