Malicious PDF — malware analysis report

Static analysis result for SHA-256 d82409fc484b1f78…

MALICIOUS

PDF

14.6 KB Created: 2019-05-01 12:01:55 +01:00 Authoring application: mPDF 5.7
MD5: aa229bdbbe3186744e2a42668cc676eb SHA-1: f8496de82a038786143efbf5d48fca1b54d6afab SHA-256: d82409fc484b1f78b9e285a79b416f988e04b5602b85eab6bc305350bdfc096e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a redirection scheme designed to drive traffic to potentially malicious content. The ML classifier also flagged this PDF as malicious with a high probability. While no scripts were extracted, the sheer volume of links and the suspicious domain suggest a malicious intent to redirect users.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7734732736732736/Patterns-Revealed-Patterns-3-by-Suede-Delray.pdf
    • http://cefasfese.4pu.com/7734732736733732/Patterns-Uncharted-Patterns-4-by-Suede-Delray.pdf
    • http://cefasfese.4pu.com/7734732735736730/Patterns-Patterns-1-by-Suede-Delray.pdf
    • http://cefasfese.4pu.com/7734732736733733/DIA-One-Night-at-the-Denver-International-Airport-by-Suede-Delray.pdf
    • http://cefasfese.4pu.com/8738735739736732/Kinship-Patterns-by-Terrance-Oberst.pdf
    • http://cefasfese.4pu.com/7732733730731/Patterns-of-Childhood-by-Christa-Wolf.pdf
    • http://cefasfese.4pu.com/1732732737736733/Refactoring-to-Patterns-by-Joshua-Kerievsky.pdf
    • http://cefasfese.4pu.com/1731734736731736737/How-to-Draft-Basic-Patterns-by-Ernestine-Kopp.pdf
    • http://cefasfese.4pu.com/7730732731734738/AVSIKTLIG-10-Gruppen-Patterns-and-people-by-IKEA.pdf
    • http://cefasfese.4pu.com/1731738731739738739/Victorian-Scroll-Saw-Patterns-by-Patrick-Spielman.pdf
    • http://cefasfese.4pu.com/1731738731739739732/Scroll-Saw-Country-Patterns-by-Patrick-Spielman.pdf
    • http://cefasfese.4pu.com/1731732734736739731/Rhythm-and-Meter-Patterns-by-Gary-Chaffee.pdf
    • http://cefasfese.4pu.com/1735732737733733/A-Parcel-of-Patterns-by-Jill-Paton-Walsh.pdf
    • http://cefasfese.4pu.com/7731738739738735/Patterns-for-Jazz-Bass-Clef-by-Jerry-Coker.pdf
    • http://cefasfese.4pu.com/9734739730739733/212---Strickanleitung---Baby-Jacke-Hut-und-Booties-Set-by-ShiFio-39-s-Patterns.pdf
    • http://cefasfese.4pu.com/9735734736738736/Grrrhhhh-A-Study-of-Social-Patterns-by-Warren-Lehrer.pdf
    • http://cefasfese.4pu.com/8730736738735731/Patterns-of-Body-and-Soul-Connections-by-Hassine-Saidane.pdf
    • http://cefasfese.4pu.com/1731738731734736739/Knitting-Essentials-How-to-Knit-the-Best-Patterns-for-Beginners-by-MS-Jamy-J.pdf
    • http://cefasfese.4pu.com/1731738732730731732/Decorative-Ornamental-Scroll-Saw-Patterns-by-Patrick-Spielman.pdf
    • http://cefasfese.4pu.com/1731732736737736736/Garment-Patterns-1889-with-Instructions-by-Jules-Kliot.pdf