Malicious PDF — malware analysis report

Static analysis result for SHA-256 ac3e19ad796cebc2…

MALICIOUS

PDF

18.8 KB Created: 2019-11-09 21:44:22 +00:00 Authoring application: mPDF 5.7
MD5: 9a607f282d6792288138266f1bbc4977 SHA-1: 1e96ead45408080b4293fcc625955a3a06358fbc SHA-256: ac3e19ad796cebc29c59776fff60dd198d2a55d8aef5dace3a694793a066f291
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, all hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9735734730735734/Atlantis-Dark-Tides-Lost-Daughters-of-Atlantis-4-by-Allie-Burton.pdf
    • http://cefasfese.4pu.com/4731737737735730/Atlantis-Rising-Tide-Lost-Daughters-of-Atlantis-3-by-Allie-Burton.pdf
    • http://cefasfese.4pu.com/4731737737734739/Atlantis-Red-Tide-Lost-Daughters-of-Atlantis-2-by-Allie-Burton.pdf
    • http://cefasfese.4pu.com/3736737733738734/The-United-States-of-Atlantis-Atlantis-2-by-Harry-Turtledove.pdf
    • http://cefasfese.4pu.com/1737732734734737/Jewel-of-Atlantis-Atlantis-2-by-Gena-Showalter.pdf
    • http://cefasfese.4pu.com/4733734739731734/Atlantis-Atlantis-1-by-Robert-Doherty.pdf
    • http://cefasfese.4pu.com/1731737737732738733/Atlantis-And-Other-Lost-Civilizations-by-Herbie-Brennan.pdf
    • http://cefasfese.4pu.com/5736736736737737/DECALOGUE-LOST-ATLANTIS-OR-DEMOCRACY-OF-BIG-TIME-A-NOVELLA-by-Nikos-Kolesis.pdf
    • http://cefasfese.4pu.com/2733739731732732/The-Lost-Empire-of-Atlantis-History-s-Greatest-Mystery-Revealed-by-Gavin-Menzies.pdf
    • http://cefasfese.4pu.com/4739739738738730/The-Lost-Continent-The-Story-of-Atlantis-by-Charles-John-Cutcliffe-Wright-Hyne.pdf
    • http://cefasfese.4pu.com/1739735734736738/Atlantis-Rising-Atlantis-Rising-1-by-Gloria-Craw.pdf
    • http://cefasfese.4pu.com/1730731739734733731/John-Sinclair-Die-Werw-lfe-aus-Atlantis-Herr-der-Schattenburg---2-Romane-in-einem-Band-by-Jason-Dark.pdf
    • http://cefasfese.4pu.com/3739736730733737/CONSPIRACY-THEORIES-GOVERNMENT-COVER-UPS-ALIENS-amp-UNSOLVED-MYSTERIES-GLOBAL-WARMING-TRUMP-Area-51-Unexplained-Phenomena-The-lost-city-of-Atlantis-The-New-World-Order-False-Flags-CIA-by-Jack-Steiner.pdf
    • http://cefasfese.4pu.com/4731737739731732/The-New-Atlantis-by-Francis-Bacon.pdf
    • http://cefasfese.4pu.com/1730736734731739739/All-Around-Atlantis-by-Deborah-Eisenberg.pdf
    • http://cefasfese.4pu.com/3730739734737737/Second-Chance-New-Atlantis-9-by-Nhys-Glover.pdf
    • http://cefasfese.4pu.com/2736732730730/Hearts-in-Atlantis-by-Stephen-King.pdf
    • http://cefasfese.4pu.com/1731734737732735736/Blue-Road-to-Atlantis-by-Jay-Nussbaum.pdf
    • http://cefasfese.4pu.com/9739734733730735/Harten-in-Atlantis-by-Stephen-King.pdf
    • http://cefasfese.4pu.com/6733735733732/Win-The-Atlantis-Grail-3-by-Vera-Nazarian.pdf
    • http://cefasfese.4pu.com/