Malicious PDF — malware analysis report

Static analysis result for SHA-256 d906a19cd80db501…

MALICIOUS

PDF

20.0 KB Created: 2019-05-02 05:26:26 +01:00 Authoring application: mPDF 5.7
MD5: fc784daf85787785531f10bf6f5891a3 SHA-1: 7bb341e2dde16119b5f5127aa0e5fd31ebc53147 SHA-256: d906a19cd80db501bdb7761d2ea3f2e15d47b9d368f092262b3e69d3d37cd59e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier and contains a large number of external links to PDF documents hosted on the domain 'cefasfese.4pu.com'. This indicates a link farm designed to lure users to potentially malicious content. No scripts were extracted from this sample, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8737732739734735/Odes-by-Sharon-Olds.pdf
    • http://cefasfese.4pu.com/8730733734739/Adobe-Odes-by-Pat-Mora.pdf
    • http://cefasfese.4pu.com/7733730737732733/Odes-en-son-honneur-by-Paul-Verlaine.pdf
    • http://cefasfese.4pu.com/8731736732732739/Odes-to-Opposites-by-Pablo-Neruda.pdf
    • http://cefasfese.4pu.com/5734737734733731/Odes-Hymns-and-Other-Poems-by-Pierre-de-Ronsard.pdf
    • http://cefasfese.4pu.com/2732739735737733/Dancing-With-the-Devil-Nikki-amp-Michael-1-by-Keri-Arthur.pdf
    • http://cefasfese.4pu.com/1731733736731734737/Jenseits-Des-Nihilismus-Dreizehnte-Vorlesung-Zum-Gedaechtnis-Von-Arthur-Stanley-Eddington-by-Michael-Polanyi.pdf
    • http://cefasfese.4pu.com/4736737738732732/Le-Morte-d-Arthur-King-Arthur-and-the-Legends-of-the-Round-Table-by-Thomas-Malory.pdf
    • http://cefasfese.4pu.com/2734731731737732/Arthur-s-Baby-Arthur-Adventure-Series-by-Marc-Brown.pdf
    • http://cefasfese.4pu.com/4730730732735737/Arthur-s-Eyes-Arthur-Adventure-Series-by-Marc-Brown.pdf
    • http://cefasfese.4pu.com/3731731737731730/Arthur-s-Valentine-Arthur-Adventure-Series-by-Marc-Brown.pdf
    • http://cefasfese.4pu.com/3739739731738733/Arthur-s-New-Puppy-An-Arthur-Adventure-by-Marc-Brown.pdf
    • http://cefasfese.4pu.com/8733732739738735/Horace-Odes-And-Epodes-by-Horace.pdf
    • http://cefasfese.4pu.com/1730738735737736731/The-Exploits-of-Brigadier-Gerard-1896-by-Arthur-Conan-Doyle-Illustrated-By-William-Barnes-Wollen-Ri-1857-1936-Brigadier-Gerard-Is-the-Hero-of-a-Series-of-Historical-Short-Stories-by-the-British-Writer-Arthur-Conan-Doyle-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/2734730732734737/The-Boy-s-King-Arthur-Sir-Thomas-Malory-s-History-of-King-Arthur-and-His-Knights-of-the-Round-Table-by-Sidney-Lanier.pdf
    • http://cefasfese.4pu.com/5733738738730/The-Tragedy-of-Arthur-by-Arthur-Phillips.pdf
    • http://cefasfese.4pu.com/3735734731737735/The-Trials-of-Arthur-by-Arthur-Pendragon.pdf
    • http://cefasfese.4pu.com/2732737735739735/Return-of-the-Grudstone-Ghosts-Arthur-Slade-s-Canadian-Chills-1-by-Arthur-Slade.pdf
    • http://cefasfese.4pu.com/6733734737737734/King-Arthur-Sir-Mordred-and-Sir-Marrock-King-Arthur-series-by-Barbara-Sullivan.pdf
    • http://cefasfese.4pu.com/4735737731739737/The-Best-Science-Fiction-of-Arthur-Conan-Doyle-Alternatives-SF-Series-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/2734731