Malicious PDF — malware analysis report

Static analysis result for SHA-256 a6275601b295dcf1…

MALICIOUS

PDF

12.7 KB Created: 2019-05-03 06:27:33 +01:00 Authoring application: mPDF 5.7
MD5: b340edf34d14c2130bfbac108176e5d1 SHA-1: cf8f10731d3fa9d1002a33ec668e12003724e508 SHA-256: a6275601b295dcf1602f238c3ee061e46b5fa9d4522d397cca9a9bd4bd1bae93
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, primarily hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a redirection scheme designed to direct users to potentially malicious content. The ML classifier also flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8780

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730735730734733734/Gulls-by-George-K-Peck.pdf
    • http://cefasfese.4pu.com/8733734738736735/Tableau-8-The-Official-Guide-The-Official-Guide-by-George-Peck.pdf
    • http://cefasfese.4pu.com/1730735730734732738/Gulls-by-Kenneth-Wood.pdf
    • http://cefasfese.4pu.com/1730735730734732739/The-Gulls-by-Michael-A-J-Bailey.pdf
    • http://cefasfese.4pu.com/1730735730732733736/Ebb-and-Flo-and-the-Greedy-Gulls-by-Jane-Simmons.pdf
    • http://cefasfese.4pu.com/1730737730730733/The-Sea-Gulls-Woke-Me-by-Mary-Stolz.pdf
    • http://cefasfese.4pu.com/1730735730733731731/The-Gulls-of-the-Edmund-Fitzgerald-by-Tres-Seymour.pdf
    • http://cefasfese.4pu.com/1730735730734732732/On-the-Gulls-Road-and-the-Enchanted-Bluff-by-Willa-Cather.pdf
    • http://cefasfese.4pu.com/4732736736738739/Are-You-in-the-House-Alone-by-Richard-Peck.pdf
    • http://cefasfese.4pu.com/1731735731732735732/Something-for-Joey-by-Richard-E-Peck.pdf
    • http://cefasfese.4pu.com/1731733730730732735/Peck-A-Book-by-J-L-Hohler-III.pdf
    • http://cefasfese.4pu.com/4737733737731730/Through-a-Brief-Darkness-by-Richard-Peck.pdf
    • http://cefasfese.4pu.com/1739730735730/Sprout-by-Dale-Peck.pdf
    • http://cefasfese.4pu.com/2730730736738732/What-We-Lost-by-Dale-Peck.pdf
    • http://cefasfese.4pu.com/2734734733730730/Amanda-Miranda-by-Richard-Peck.pdf
    • http://cefasfese.4pu.com/3730731737736739/Fucking-Martin-by-Dale-Peck.pdf
    • http://cefasfese.4pu.com/1737736737734732/Three-Quarters-Dead-by-Richard-Peck.pdf
    • http://cefasfese.4pu.com/5734738738736/The-Road-Less-Travelled-by-M-Scott-Peck.pdf
    • http://cefasfese.4pu.com/8736737737734739/Peck-Me-Up-My-Wing-by-Friederike-Mayr-cker.pdf
    • http://cefasfese.4pu.com/9736730732735735/A-Day-No-Pigs-Would-Die-by-Robert-Newton-Peck.pdf
    • http://cefasfese.4pu.com/173973