Malicious PDF — malware analysis report

Static analysis result for SHA-256 adb19cbb9258a592…

MALICIOUS

PDF

19.2 KB Created: 2019-05-03 17:58:23 +01:00 Authoring application: mPDF 5.7
MD5: 97060621025330b8b392aebad9c26bc3 SHA-1: e86666a61949b6c3c43c79d95440807c1f174d73 SHA-256: adb19cbb9258a592f1ba43c7bac0abc376c394ed8b189756a99017a5a1623166
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a mechanism to distribute malicious content through seemingly benign documents. The ML classifier strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1739733730735/Bird-Eyes-by-Madelyn-Arnold.pdf
    • http://cefasfese.4pu.com/9739734735734731/Star-Wars-Fanon---Capital-Ships-Lucrehulk-Class-Battleships-New-Republic-Capital-Ships-Republic-Capital-Ships-Star-Destroyers-True-Republic-Capital-Ships-Astraeus-Class-Battleship-Contessa-Entarian-Olean-Erebos-Esvelde-Federation-Swarm-Freedom-by-Source-Wikipedia.pdf
    • http://cefasfese.4pu.com/5730732739736739/The-Book-of-Old-Ships-From-Egyptian-Galleys-to-Clipper-Ships-by-Henry-B-Culver.pdf
    • http://cefasfese.4pu.com/1731736735733736734/Viking-Age-Ships-And-Shipbuilding-In-Hedeby-Haithabu-And-Schleswig-Ships-And-Boats-Of-The-North-by-Ole-Crumlin-Pedersen.pdf
    • http://cefasfese.4pu.com/4739737731737736/Nanny-X-Returns-by-Madelyn-Rosenberg.pdf
    • http://cefasfese.4pu.com/2735730732735731/Heather-In-The-Mist-by-Madelyn-Hill.pdf
    • http://cefasfese.4pu.com/1735732730736730/A-Witch-in-Time-A-Bewitching-Mystery-6-by-Madelyn-Alt.pdf
    • http://cefasfese.4pu.com/3730734739736739/Arnold-The-Education-of-a-Bodybuilder-by-Arnold-Schwarzenegger.pdf
    • http://cefasfese.4pu.com/1731738731737730735/Runt-and-Arnold-Slay-Monster-Hognose-The-Adventures-of-Runt-and-Arnold-by-Gean-Penny.pdf
    • http://cefasfese.4pu.com/1737730737738731/For-Her-Sins-Sins-and-Sacrifices-1-by-Madelyn-King-Moore.pdf
    • http://cefasfese.4pu.com/6732734732738736/Sol-Silver-Ships-5-by-S-H-Jucha.pdf
    • http://cefasfese.4pu.com/8736732736733732/Some-Go-Beneath-the-Sea-in-Ships-by-P-B-McMorris.pdf
    • http://cefasfese.4pu.com/8730739739735736/M-ridien-Silver-Ships-3-by-S-H-Jucha.pdf
    • http://cefasfese.4pu.com/8731731733732731/The-Somber-Ships-by-Gregory-Vickers.pdf
    • http://cefasfese.4pu.com/7730736731738735/Know-Your-Ships-2013-by-Roger-Lelievre.pdf
    • http://cefasfese.4pu.com/4737732736739/The-Long-Ships-by-Frans-G-Bengtsson.pdf
    • http://cefasfese.4pu.com/8733735736732/They-Came-On-Viking-Ships-by-Jackie-French.pdf
    • http://cefasfese.4pu.com/6732731732734739/The-Last-of-the-Wind-Ships-by-Alan-Villiers.pdf
    • http://cefasfese.4pu.com/6738739737731733/Of-Sinking-Ships-and-Broken-Walls-by-Valerie-A-Beauchene.pdf
    • http://cefasfese.4pu.com/5731737735732730/Pepys-s-Navy-Ships-Men-amp-Warfare-1649-1689-by-J-D-Davies.pdf