Malicious PDF — malware analysis report

Static analysis result for SHA-256 d5db9a1fa827badc…

MALICIOUS

PDF

16.1 KB Created: 2019-04-24 14:11:45 +01:00 Authoring application: mPDF 5.7
MD5: 1f08bc04e5e8fe1f6a8fc046e7bfeb83 SHA-1: 69d8d0008f3f5d5d05f0cd2640bf2b60afb5176e SHA-256: d5db9a1fa827badc31b35edf98b5e6cdec6ffcf6bf87728baae8aea4e5eef0cb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or SEO poisoning attack, designed to drive traffic to potentially malicious or unwanted content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731735732738733732/Verzaubert-von-deinen-K-ssen-JULIA-1959-by-Tina-Duncan.pdf
    • http://cefasfese.4pu.com/1731735732739731738/Julia-Extra-Band-322---Titel-4-Verzaubert-vom-Fest-der-Liebe-by-Jackie-Braun.pdf
    • http://cefasfese.4pu.com/1730734735733739734/Einleitung-in-Die-Mengenlehre-Eine-Gemeinverst-ndliche-Einf-hrung-in-Das-Reich-Der-Unendlichen-Gr-ssen-by-Abraham-Adolf-Fraenkel.pdf
    • http://cefasfese.4pu.com/6732739734739733/Life-Into-Art-Isadora-Duncan-and-Her-World-by-Doree-Duncan.pdf
    • http://cefasfese.4pu.com/3730736739732739/-I-Tina-What-s-Love-Got-To-Do-With-It-by-Tina-Turner.pdf
    • http://cefasfese.4pu.com/7739731733734732/Tina-s-Story-Urban-Fiction-Gone-Viral-by-Tina-Story.pdf
    • http://cefasfese.4pu.com/1731735732736739735/Verzaubert-by-Nancy-Madore.pdf
    • http://cefasfese.4pu.com/6730730731730/Von-der-Nacht-verzaubert-Die-for-Me-1-by-Amy-Plum.pdf
    • http://cefasfese.4pu.com/3739730731733733/I-Tina-by-Tina-Turner.pdf
    • http://cefasfese.4pu.com/1731735732737730734/Verzaubert-von-deinem-Blick-by-Tally-Bandet.pdf
    • http://cefasfese.4pu.com/4731738731733/The-Complete-Peanuts-Vol-5-1959-1960-by-Charles-M-Schulz.pdf
    • http://cefasfese.4pu.com/4739735732730739/Julia-the-Secret-Keeper-Julia-s-Secrets-1-by-Franky-A-Brown.pdf
    • http://cefasfese.4pu.com/5739739736734737/Lebe-deinen-Traum-by-Lucy-Sky.pdf
    • http://cefasfese.4pu.com/1731735732738730731/Samtpfote---ganz-verzaubert-Ein-Katzenroman-by-Martina-Magyari.pdf
    • http://cefasfese.4pu.com/1731735732738732734/Zauberhaft-Verzaubert---BeWitchED-Band-13-by-Serena-S-Murray.pdf
    • http://cefasfese.4pu.com/1731735732738733738/Verzaubert-Eine-Herzensfabel-in-Versen-by-Maria-Janitschek.pdf
    • http://cefasfese.4pu.com/1731735732739732734/Pl-tzlich-verzaubert-The-Unicorns-of-Blossom-Wood-1-by-Catherine-Coe.pdf
    • http://cefasfese.4pu.com/1731735732738737732/Zum-zweiten-Mal-von-dir-verzaubert-BIANCA-1602-by-Kristin-Hardy.pdf
    • http://cefasfese.4pu.com/3730737735736735/In-Julia-s-Kitchen-with-Master-Chefs-by-Julia-Child.pdf
    • http://cefasfese.4pu.com/6735735732732/Airport-1968-The-Final-Diagnosis-1959-by-Arthur-Hailey.pdf
    • http://cefasfese.4pu.com/4731738731733/T