Malicious PDF — malware analysis report

Static analysis result for SHA-256 a9529ce00fbf9a18…

MALICIOUS

PDF

18.5 KB Created: 2019-06-05 22:56:37 +01:00 Authoring application: mPDF 5.7
MD5: d9f511b972c828cca516289e181908bf SHA-1: 745e80138c82271e5aab1dd6c29b5c7585b66384 SHA-256: a9529ce00fbf9a1818ba46713e5902850fac205cb6ee967709d038b0d8467093
130 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains an eval() call and a large number of external links, indicating a potential SEO spam or redirection tactic. The dominant host 'cefasfese.4pu.com' appears to be used for hosting numerous PDF files, likely as a lure. While the document body is heavily obfuscated, the presence of embedded URLs and the PDF_SEO_LINK_FARM heuristic strongly suggest a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2738738731733/Black-Sea-Gods-Chronicles-of-Fu-Xi-1-by-Brian-Braden.pdf
    • http://cefasfese.4pu.com/7730738738738738/When-Gods-Go-to-War-by-Brian-Rompre.pdf
    • http://cefasfese.4pu.com/1738733738735738/Trail-of-the-Gods-The-Morcyth-Saga-4-by-Brian-S-Pratt.pdf
    • http://cefasfese.4pu.com/3736736732733739/God-Against-the-Gods-Storytelling-Imagination-and-Apologetics-in-the-Bible-by-Brian-Godawa.pdf
    • http://cefasfese.4pu.com/4733734737732739/Fear-of-a-Black-Marker-Another-K-Chronicles-Compendium-K-Chronicles-2-by-Keith-Knight.pdf
    • http://cefasfese.4pu.com/1735737736737731/The-Black-Shriving-Chronicles-of-the-Black-Gate-2-by-Phil-Tucker.pdf
    • http://cefasfese.4pu.com/1730734739734738730/HOLLY-BLACK-SERIES-READING-ORDER-MAGISTERIUM-BOOKS-MODERN-TALE-OF-FAERIE-BOOKS-SPIDERWICK-CHRONICLES-BOOKS-BEYONG-SPIDERWICK-CHRONICLES-GOOD-NEIGHBORS-BOOKS-BY-HOLLY-BLACK-by-List-Series.pdf
    • http://cefasfese.4pu.com/1731734731736733739/Gods-and-Steel-The-Cor-Chronicles-4-by-Martin-Parece.pdf
    • http://cefasfese.4pu.com/2738737736739735/Whispering-Gods-Lacuna-Chronicles-3-by-A-M-Daily.pdf
    • http://cefasfese.4pu.com/4734739730737731/The-Black-Rose-Princess-of-the-Gods-2-by-Ky-Tyrand.pdf
    • http://cefasfese.4pu.com/6734733730736734/Black-Gods-and-Scarlet-Dreams-by-C-L-Moore.pdf
    • http://cefasfese.4pu.com/4732730736733/A-Game-of-Gods-The-Dystopian-Chronicles-1-by-Hari-Kumar-K-.pdf
    • http://cefasfese.4pu.com/1730733737732731739/Fade-to-Black-BurnBlack-Rock-Gods-1-by-Jax-Newman.pdf
    • http://cefasfese.4pu.com/1735738736734734/Betrayed-by-the-Gods-Book-One-The-Chronicles-of-the-Crystal-Skulls-by-Cassandra-Cade.pdf
    • http://cefasfese.4pu.com/3739737735734736/Stretch-by-Brian-Black.pdf
    • http://cefasfese.4pu.com/2730735736734734/Black-Robe-by-Brian-Moore.pdf
    • http://cefasfese.4pu.com/3737732732739738/Hurt-DS-Lucy-Black-2-by-Brian-McGilloway.pdf
    • http://cefasfese.4pu.com/2739732733736735/Black-Boy-White-School-by-Brian-F-Walker.pdf
    • http://cefasfese.4pu.com/4733738730737733/Noah-Primeval-Chronicles-of-the-Nephilim-1-by-Brian-Godawa.pdf
    • http://cefasfese.4pu.com/8735733737738732/Caleb-Vigilant-Chronicles-of-the-Nephilim-6-by-Brian-Godawa.pdf
    • http://cefasfese.4pu.com/1730734739734738730/HOLLY-BLACK-SERIES-READING-ORDER-MAGISTERIUM-BOOKS-MODERN-TALE-OF-FAERIE-BOOKS-SPIDERWICK-CHRONICLES-BOOKS-BEYONG-SPIDERWICK-CHRONICLES-GOOD-NEIGHBORS-BOOKS-BY-HOLLY-BLACK-by-List