Malicious PDF — malware analysis report

Static analysis result for SHA-256 c8f197b1980d6999…

MALICIOUS

PDF

20.1 KB Created: 2019-06-04 09:56:06 +01:00 Authoring application: mPDF 5.7
MD5: 1cbbd98cd9773d23a941ba8fa4d1587e SHA-1: f4112a07b9e27788414027587a284d8ad90aa87f SHA-256: c8f197b1980d69997512acd3409d96f6a509ac9869d40ff9b7aa1710246d342d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, all hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also flagged this PDF as malicious with a high probability. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9805

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730739735733734730/A-Higher-Education-A-Modern-Retelling-of-Pride-amp-Prejudice-by-Rosalie-Stanton.pdf
    • http://cefasfese.4pu.com/2738731739738739/Dear-Mr-Darcy-A-Retelling-of-Pride-and-Prejudice-by-Amanda-Grange.pdf
    • http://cefasfese.4pu.com/2731736733733736/A-Little-Bit-Psychic-Pride-amp-Prejudice-with-a-Modern-Twist-by-Aim-e-Avery.pdf
    • http://cefasfese.4pu.com/2738732733739737/Pride-and-Prejudice-and-Poison-A-Pride-and-Prejudice-Novel-Variation-by-Bella-Breen.pdf
    • http://cefasfese.4pu.com/2738732731736739/President-Darcy-A-Modern-Pride-and-Prejudice-Variation-by-Victoria-Kincaid.pdf
    • http://cefasfese.4pu.com/6739733737735738/Sparks-Fly-Tires-Skid-A-Modern-Pride-and-Prejudice-Variation-Romantic-Comedy-by-Ari-Rhoge.pdf
    • http://cefasfese.4pu.com/8739737730735/Firsts-by-Rosalie-Stanton.pdf
    • http://cefasfese.4pu.com/2738732734732733/Pride-amp-Prejudice-amp-Assassinations-Pride-amp-Prejudice-amp-Assassinations-Book-1-by-Leo-Charles-Taylor.pdf
    • http://cefasfese.4pu.com/1730737734732736739/Diversification-Of-European-Systems-Of-Higher-Education-Studies-In-Comparative-Education-Bd-3-by-Claudius-Gellert.pdf
    • http://cefasfese.4pu.com/3739730730738733/Mr-Darcy-s-Pride-and-Joy-A-Pride-and-Prejudice-Variation-The-Darcy-Novels-3-by-Monica-Fairview.pdf
    • http://cefasfese.4pu.com/1730739735732730736/Professed-A-Novel-of-Higher-Education-by-Lowell-Mick-White.pdf
    • http://cefasfese.4pu.com/4736735734739739/Organization-and-Governance-in-Higher-Education-by-M-Christopher-Brown-II.pdf
    • http://cefasfese.4pu.com/4736735739730737/Financing-Higher-Education-Worldwide-Who-Pays-Who-Should-Pay-by-D-Bruce-Johnstone.pdf
    • http://cefasfese.4pu.com/9738733739737737/A-Struggle-to-Survive-Funding-Higher-Education-in-the-Next-Century-by-David-S-Honeyman.pdf
    • http://cefasfese.4pu.com/4731738731739738/Pride-amp-Prejudice-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/8733733737730732/Pride-and-Prejudice-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/6730733738731734/Pride-amp-Prejudice-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/6738733736731736/Pride-and-Prejudice-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/5737730733731736/Pride-and-Prejudice-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/6731732730738735/Pride-and-Prejudice-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/2738732734732733/Pride-amp-Prejudice-amp-Assassinations-Pride-amp-Prejudice-amp-Assassinations-