Malicious PDF — malware analysis report

Static analysis result for SHA-256 b9be1926d5dc99be…

MALICIOUS

PDF

15.1 KB Created: 2019-11-09 23:28:04 +00:00 Authoring application: mPDF 5.7
MD5: 13c9e123cb03cf589a3851b85db6da79 SHA-1: 57a15c53e901c6860cbe805bdcfa5ac80e0a501e SHA-256: b9be1926d5dc99be2b6acbd242d20721a1e2c85eb2daadd24f412736efec3733
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to the domain 'cefasfese.4pu.com'. While individual links are marked as confirmed benign, the sheer volume and the nature of the heuristic suggest a link farm or SEO poisoning tactic. The ML_NYX_PDF_MALICIOUS classifier also flagged this PDF with high confidence. The document body is heavily corrupted, preventing analysis of its content, but the link farm structure is indicative of a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2736739735735738/Don-t-Text-and-Drive-by-Trish-Jackson.pdf
    • http://cefasfese.4pu.com/4737730738730735/Aquarius-Addiction-Zodiac-Series-by-Trish-Jackson.pdf
    • http://cefasfese.4pu.com/4733730737738732/Trish-Just-Trish-This-Can-t-Be-Happening-2-by-Lynda-LeeAnne.pdf
    • http://cefasfese.4pu.com/2731739739732734/Trish-Just-Trish-This-Can-t-Be-Happening-2-by-Lynda-LeeAnne.pdf
    • http://cefasfese.4pu.com/3739732737738735/Indecent-Cravings-Part-5-Indecent-Cravings-5-by-S-K-Cross.pdf
    • http://cefasfese.4pu.com/4733732730739735/Campus-Cravings-Vol-5-Campus-Cravings-10-11-by-Carol-Lynne.pdf
    • http://cefasfese.4pu.com/4733732730739734/Campus-Cravings-Vol-2-Campus-Cravings-4-5-by-Carol-Lynne.pdf
    • http://cefasfese.4pu.com/3738739734730730/Dangerous-Cravings-Dangerous-Cravings-1-by-Evangeline-Anderson.pdf
    • http://cefasfese.4pu.com/4733732730738731/Campus-Cravings-Vol-4-Campus-Cravings-8-9-by-Carol-Lynne.pdf
    • http://cefasfese.4pu.com/4733732730739731/Campus-Cravings-Vol-1-Campus-Cravings-1-3-by-Carol-Lynne.pdf
    • http://cefasfese.4pu.com/3739732737738737/Indecent-Cravings-3-Indecent-Cravings-3-by-S-K-Cross.pdf
    • http://cefasfese.4pu.com/1730739731732730730/Capricorn-85-by-Beim.pdf
    • http://cefasfese.4pu.com/1730739731731734736/Capricorn-84-by-Beim.pdf
    • http://cefasfese.4pu.com/1730739731731731732/Capricorn-85-X-by-Beim.pdf
    • http://cefasfese.4pu.com/8735739735737/The-Capricorn-Stone-by-Madeleine-Brent.pdf
    • http://cefasfese.4pu.com/4737733739739738/Tropic-of-Capricorn-by-Simon-Reeve.pdf
    • http://cefasfese.4pu.com/1737731737739736/Gemini-Keeps-Capricorn-Signs-of-Love-3-by-Anyta-Sunday.pdf
    • http://cefasfese.4pu.com/7738736735733734/Super-Horoscope-Capricorn-1990-by-Michael-Lutin.pdf
    • http://cefasfese.4pu.com/5737737735730735/The-Rockefeller-Gift-Merle-Capricorn-6-by-Pauline-Glen-Winslow.pdf
    • http://cefasfese.4pu.com/2732733733739/In-The-Service-Of-Community-An-Honored-Elder-The-Honorable-Judge-Perry-Brooks-Jackson-by-Anita-P-Jackson.pdf