Malicious PDF — malware analysis report

Static analysis result for SHA-256 9911d35adfd3ceb7…

MALICIOUS

PDF

17.6 KB Created: 2019-06-04 10:09:28 +01:00 Authoring application: mPDF 5.7
MD5: f53e3502d5d7c803b83d3aa0a9b8f9b4 SHA-1: 8a114ba1456f420775e8f84f26ed4c31df9ecdc7 SHA-256: 9911d35adfd3ceb7a62dfd7e004e13ba13e1965d3ba619a37864a3fe47e198fc
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links pointing to external PDF files, hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a phishing lure designed to redirect users to potentially malicious content. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4734739737/The-Bone-Sparrow-by-Zana-Fraillon.pdf
    • http://cefasfese.4pu.com/4735735734733/Sold-by-Zana-Muhsen.pdf
    • http://cefasfese.4pu.com/8734735733730738/Prison-No-5-Eleven-Years-in-Turkish-Jails-by-Mehdi-Zana.pdf
    • http://cefasfese.4pu.com/8737730732735732/Noch-Einmal-Meine-Mutter-Sehen-Vom-Eigenen-Vater-In-Die-Sklaverei-Verkauft-by-Zana-Muhsen.pdf
    • http://cefasfese.4pu.com/3735730738739739/The-Day-We-Disappeared-by-Lucy-Robinson.pdf
    • http://cefasfese.4pu.com/5733731733738736/The-Disappeared-Jenny-Cooper-2-by-M-R-Hall.pdf
    • http://cefasfese.4pu.com/3737738739737739/When-the-Doves-Disappeared-by-Sofi-Oksanen.pdf
    • http://cefasfese.4pu.com/1739735733730735/Imperfect-Disappeared-1-by-Bronwyn-Kienapple.pdf
    • http://cefasfese.4pu.com/3739733738736735/Disappeared-Mantequero-2-by-Jenny-Twist.pdf
    • http://cefasfese.4pu.com/3730733736731736/If-Cats-Disappeared-from-the-World-by-Genki-Kawamura.pdf
    • http://cefasfese.4pu.com/2733738737739733/Apples-Are-from-Kazakhstan-The-Land-that-Disappeared-by-Christopher-Robbins.pdf
    • http://cefasfese.4pu.com/1734738735739733/The-Disappeared-Retrieval-Artist-1-by-Kristine-Kathryn-Rusch.pdf
    • http://cefasfese.4pu.com/2739730730733733/The-100-Year-Old-Man-Who-Climbed-Out-the-Window-and-Disappeared-by-Jonas-Jonasson.pdf
    • http://cefasfese.4pu.com/3731739733733735/The-One-Hundred-Year-Old-Man-Who-Climbed-Out-the-Window-and-Disappeared-by-Jonas-Jonasson.pdf
    • http://cefasfese.4pu.com/1730739734733739737/The-Disappeared-A-Silo-Story-Omnibus-by-Logan-Thomas-Snyder.pdf
    • http://cefasfese.4pu.com/3737732730732731/The-Disappeared-Fredrika-Bergman-amp-Alex-Recht-3-by-Kristina-Ohlsson.pdf
    • http://cefasfese.4pu.com/4734734739736733/The-Day-Miss-Bessie-Lewis-Disappeared-by-Doris-Miles-Disney.pdf
    • http://cefasfese.4pu.com/1731730733734731/The-Year-We-Disappeared-A-Father---Daughter-Memoir-by-Cylin-Busby.pdf
    • http://cefasfese.4pu.com/1730738732739731731/The-Fire-Engine-That-Disappeared-A-Martin-Beck-Mystery-by-Maj-Sjowall.pdf
    • http://cefasfese.4pu.com/3733730734737/The-Hundred-Year-Old-Man-Who-Climbed-Out-of-the-Window-and-Disappeared-by-Jonas-Jonasson.pdf