Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca2a644884a7ecf1…

MALICIOUS

PDF

18.1 KB Created: 2019-05-02 17:16:59 +01:00 Authoring application: mPDF 5.7
MD5: d70ea47fb60623212e079f71419e9c88 SHA-1: 972dcbcaca2a97b753c943ce2efca7ad1f937f06 SHA-256: ca2a644884a7ecf1379df6b2a5883a4f64aa64968278f1fdd26d1ef56dc51f8a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links pointing to external PDFs hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or SEO poisoning attack, designed to redirect users to potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9807

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5739739732735/Girl-Next-Door-by-Max-Cummings.pdf
    • http://cefasfese.4pu.com/3736733737739732/Friends-with-Benefits-Girl-Next-Door-1-by-C-C-Wood.pdf
    • http://cefasfese.4pu.com/1733734736736734/The-Girl-Next-Door-by-Augusta-Huiell-Seaman.pdf
    • http://cefasfese.4pu.com/7737731732732730/Touch-Me-The-Girl-Next-Door-3-by-Elle-Erotique.pdf
    • http://cefasfese.4pu.com/5731739730738730/Revolutionary-Parks-Conservation-Social-Justice-and-Mexico-s-National-Parks-1910-1940-by-Emily-Wakild.pdf
    • http://cefasfese.4pu.com/6734735738/A-Short-History-of-the-Girl-Next-Door-by-Jared-Reck.pdf
    • http://cefasfese.4pu.com/9731733738738730/Doris-Day-The-Untold-Story-of-the-Girl-Next-Door-by-David-Kaufman.pdf
    • http://cefasfese.4pu.com/8739731739735730/Denying-Mr-Parks-Parks-1-by-Lilly-James.pdf
    • http://cefasfese.4pu.com/5733733735734/When-The-Girl-Next-Door-Kills-The-True-Story-of-Alyssa-Bustamante-by-Heidi-Poole.pdf
    • http://cefasfese.4pu.com/6734730730730738/Aboriginal-Peoples-amp-Canada-s-Parks-amp-Protected-Areas-Case-Studies-Peuples-Autochtones-Les-Parcs-Et-Aires-Protegees-Du-Canada-Etudes-de-Cas-by-Canadian-Parks-Council.pdf
    • http://cefasfese.4pu.com/8731736733733739/Door-to-Door-by-Mariam-Razek.pdf
    • http://cefasfese.4pu.com/2732735739735735/Surprise-Me-A-Billionaire-Next-Door-Novel-The-Billionaire-Next-Door-Book-10-by-Violette-Paradis.pdf
    • http://cefasfese.4pu.com/3736739730735735/Girl-with-the-Dragon-Tattoo-Trilogy-Bundle-The-Girl-with-the-Dragon-Tattoo-The-Girl-Who-Played-with-Fire-The-Girl-Who-Kicked-the-Hornet-s-Nest-by-Stieg-Larsson.pdf
    • http://cefasfese.4pu.com/6737731733733/Destiny-by-Tim-Parks.pdf
    • http://cefasfese.4pu.com/5734732734738/The-Heavenly-Fox-by-Richard-Parks.pdf
    • http://cefasfese.4pu.com/4738733736736738/The-State-We-re-In-by-Adele-Parks.pdf
    • http://cefasfese.4pu.com/1739731734735732/Italian-Neighbors-by-Tim-Parks.pdf
    • http://cefasfese.4pu.com/3736732738733/Judge-Savage-by-Tim-Parks.pdf
    • http://cefasfese.4pu.com/6733738734730732/The-Diocese-of-Wilmington-by-Jim-Parks.pdf
    • http://cefasfese.4pu.com/4735734733739736/Painting-Death-by-Tim-Parks.pdf
    • http://cefasfese.4pu.com/6734730730730738/Aboriginal-Peoples-amp-Canada-s-Parks-amp-Protected-Areas-Case-Studies-Peuples-Autochtones-Les-Parcs-Et-Aires-Protegees-Du-Canada-Etudes