Malicious PDF — malware analysis report

Static analysis result for SHA-256 d1388d46b0254d8e…

MALICIOUS

PDF

21.3 KB Created: 2019-11-09 21:47:33 +00:00 Authoring application: mPDF 5.7
MD5: ac5cea1b2bd0a1afbdcba390394c73f1 SHA-1: 7b18bed41cd51f60a87b74d124042ce310651eea SHA-256: d1388d46b0254d8e549915a77fd2e31e9f83f693077d4bec8ad81036b4378be7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, primarily hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier also flagged this PDF as malicious with a high probability. No scripts were extracted, and the document body was heavily obfuscated, making it difficult to determine the exact lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5732733736733735/The-Confessions-of-Saint-Augustine-Confessions-of-St-Augustine-Image-Books-by-Augustine-of-Hippo.pdf
    • http://cefasfese.4pu.com/6735733734732739/The-Confessions-of-St-Augustine-Books-I-IX-by-Augustine-of-Hippo.pdf
    • http://cefasfese.4pu.com/8737733733731734/Confessions-of-Saint-Augustine-by-Augustine-of-Hippo.pdf
    • http://cefasfese.4pu.com/6735730736732732/The-Confessions-of-Saint-Augustine-by-Augustine-of-Hippo.pdf
    • http://cefasfese.4pu.com/1731730739732737731/The-Complete-Works-of-Saint-Augustine-The-Confessions-On-Grace-and-Free-Will-The-City-of-God-On-Christian-Doctrine-Expositions-on-the-Book-Of-Psalms-50-Books-With-Active-Table-of-Contents-by-Augustine-of-Hippo.pdf
    • http://cefasfese.4pu.com/4733732738735/City-of-God-by-Augustine-of-Hippo.pdf
    • http://cefasfese.4pu.com/6739731730731739/The-Letters-of-St-Augustin-Vol-1-by-Augustine-of-Hippo.pdf
    • http://cefasfese.4pu.com/1731730737734734736/Answer-to-Faustus-a-Manichean-by-Augustine-of-Hippo.pdf
    • http://cefasfese.4pu.com/8732730736739739/La-parabole-du-fils-prodigue-Expliqu-e-par-les-P-res-de-l-Eglise-by-Augustine-of-Hippo.pdf
    • http://cefasfese.4pu.com/3739737733732730/The-Confessions-The-City-of-God-On-Christian-Doctrine-Great-Books-of-the-Western-World-18-by-Augustine-of-Hippo.pdf
    • http://cefasfese.4pu.com/9731730735730732/Augustinus-Die-Bekenntnisse---Confessiones-Vollst-ndige-deutsche-Ausgabe-Eine-der-einflussreichsten-autobiographischen-Texte-der-Weltliteratur-by-Augustine-of-Hippo.pdf
    • http://cefasfese.4pu.com/6730736738736737/Early-Political-Writings-by-Auguste-Comte.pdf
    • http://cefasfese.4pu.com/5733734739737736/The-Basic-Political-Writings-by-Jean-Jacques-Rousseau.pdf
    • http://cefasfese.4pu.com/5733735730737739/The-Discourses-amp-Other-Early-Political-Writings-by-Jean-Jacques-Rousseau.pdf
    • http://cefasfese.4pu.com/5736731732733/The-Prince-and-Other-Political-Writings-Everyman-s-Library-by-Niccol-Machiavelli.pdf
    • http://cefasfese.4pu.com/4739731737739737/The-Social-Contract-amp-Other-Later-Political-Writings-by-Jean-Jacques-Rousseau.pdf
    • http://cefasfese.4pu.com/5730736739738731/Selections-from-Political-Writings-1921-1926-by-Antonio-Gramsci.pdf
    • http://cefasfese.4pu.com/9736737732/Duck-and-Hippo-in-the-Rainstorm-Duck-and-Hippo-1-by-Jonathan-London.pdf
    • http://cefasfese.4pu.com/8735731739738734/Thoreau-Political-Writings-by-Henry-David-Thoreau.pdf
    • http://cefasfese.4pu.com/5730737738733739/A-Vindication-of-Political-Virtue-The-Political-Theory-of-Mary-Wollstonecraft-by-Virginia-Sapiro.pdf