Malicious PDF — malware analysis report

Static analysis result for SHA-256 bed4016b721c034e…

MALICIOUS

PDF

19.3 KB Created: 2019-11-07 12:45:15 +00:00 Authoring application: mPDF 5.7
MD5: 9d9a0ed596b12adaa04a7dcfa628efb7 SHA-1: 0813f80c9148a8909ad74bfb994a5e98493a0ad5 SHA-256: bed4016b721c034e85261116a5fd164d710feb1f4278b747b1d81be277a900b4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3739735738737737/Extinction-The-Wasteland-Chronicles-6-by-Kyle-West.pdf
    • http://cefasfese.4pu.com/9738736738/Extinction-Horizon-The-Extinction-Cycle-1-by-Nicholas-Sansbury-Smith.pdf
    • http://cefasfese.4pu.com/4738736733739736/Bastion-The-Xenoworld-Saga-Book-2-by-Kyle-West.pdf
    • http://cefasfese.4pu.com/1735735734733735/Wasteland-Wasteland-1-by-Lynn-Rush.pdf
    • http://cefasfese.4pu.com/1732736737731730/Extinction-Point-Extinction-Point-1-by-Paul-Antony-Jones.pdf
    • http://cefasfese.4pu.com/4730736739731734/Dead-Pulse-Rising-The-Kyle-Walker-Chronicles-Volume-1-by-K-Michael-Gibson.pdf
    • http://cefasfese.4pu.com/3734738739737734/Wasteland-Wasteland-1-by-Ann-Bakshis.pdf
    • http://cefasfese.4pu.com/8733734736737/Wasteland-Wasteland-1-by-Susan-Kim.pdf
    • http://cefasfese.4pu.com/1736731730739733/Kyle-s-New-Stepbrother-II-Long-Hot-Summer-Nick-and-Kyle-Book-2-by-Brad-Vance.pdf
    • http://cefasfese.4pu.com/1736731730737736/Kyle-s-New-Stepbrother-V-Winter-Wonderland-Nick-and-Kyle-Book-5-by-Brad-Vance.pdf
    • http://cefasfese.4pu.com/1736731731730738/Kyle-s-New-Stepbrother-Nick-and-Kyle-Book-1-by-Brad-Vance.pdf
    • http://cefasfese.4pu.com/1731734738731737737/Witch-s-Pie-A-Coby-and-Kyle-Adventure-Coby-and-Kyle-Adventures-Book-1-by-Dortone-Brothers.pdf
    • http://cefasfese.4pu.com/1731730734739737731/Tales-from-the-West-Imago-Chronicles-2-by-L-T-Suzuki.pdf
    • http://cefasfese.4pu.com/2732731734731732/West-by-West-My-Charmed-Tormented-Life-by-Jerry-West.pdf
    • http://cefasfese.4pu.com/8734738734730737/Valkyria---Games-Valkyria-Chronicles-Valkyria-Chronicles-2-Valkyria-Chronicles-3-Valkyria-Chronicles-Valkyria-Chronicles-2-Valkyria-Chronicles-3-Action-Points-Challenges-of-the-Edy-Detachment-Class-Change-System-Col-Nonnenkof-by-Source-Wikia.pdf
    • http://cefasfese.4pu.com/9739735732736737/Science-Fiction-Westerns-The-Adventures-of-Brisco-County-Jr-the-Wild-Wild-West-Jonah-Hex-Weird-West-Wild-West-C-O-W--Boys-of-Moo-Mesa-by-Source-Wikipedia.pdf
    • http://cefasfese.4pu.com/3739736734735735/Wasteland-by-Francesca-Lia-Block.pdf
    • http://cefasfese.4pu.com/9732739737737730/Wasteland-by-Deborah-Wheeler.pdf
    • http://cefasfese.4pu.com/3735739734736736/Wasteland-Contamination-3-by-T-W-Piperbrook.pdf
    • http://cefasfese.4pu.com/2735733736736735/Extinction-by-Mark-Alpert.pdf
    • http://cefasfese.4pu.com/1731734738731737737/Witch-s-Pie-A-Coby-and-Kyle-Adventure-Coby-and-Kyle