Malicious PDF — malware analysis report

Static analysis result for SHA-256 da72a63feee89826…

MALICIOUS

PDF

15.5 KB Created: 2019-11-07 21:18:18 +00:00 Authoring application: mPDF 5.7
MD5: ec8997b9141ce03ded9d81430d8e69b4 SHA-1: 3d9965ea1530f1164371342e0f101064a5416a59 SHA-256: da72a63feee8982668bc675e7e4e6a03484dfb09524ef2b2d13205941533afde
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document contains a large number of embedded links, forming a link farm hosted on the domain 'cefasfese.4pu.com'. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm. While the specific URLs are currently marked as benign, the overall structure and heuristic firing suggest a malicious intent to direct users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2734730733733738/Less-than-Zero-by-Bret-Easton-Ellis.pdf
    • http://cefasfese.4pu.com/4730736738737/The-Informers-by-Bret-Easton-Ellis.pdf
    • http://cefasfese.4pu.com/3735732731737735/Glamorama-by-Bret-Easton-Ellis.pdf
    • http://cefasfese.4pu.com/4730735734735730/The-Informers-by-Bret-Easton-Ellis.pdf
    • http://cefasfese.4pu.com/3736731739732/Glamorama-by-Bret-Easton-Ellis.pdf
    • http://cefasfese.4pu.com/4733733732732733/Water-from-the-Sun-and-Discovering-Japan-by-Bret-Easton-Ellis.pdf
    • http://cefasfese.4pu.com/1731730734736735736/Autobiography-in-the-Works-of-Bret-Easton-Ellis-by-Christian-Hensgens.pdf
    • http://cefasfese.4pu.com/9739739731736730/Psycho-Proctologists-and-the-Flaming-Buttholes-of-Doom-Psycho-Proctologists-1-by-W-W-Pecker.pdf
    • http://cefasfese.4pu.com/2731737733731/American-Sphinx-The-Character-of-Thomas-Jefferson-by-Joseph-J-Ellis.pdf
    • http://cefasfese.4pu.com/1739734737733738/American-Creation-Triumphs-and-Tragedies-at-the-Founding-of-the-Republic-by-Joseph-J-Ellis.pdf
    • http://cefasfese.4pu.com/3738736735738735/The-Difference-Between-Women-and-Men-by-Bret-Lott.pdf
    • http://cefasfese.4pu.com/9731733739736736/Doris-Day-A-Reluctant-Star-by-David-Bret.pdf
    • http://cefasfese.4pu.com/8734733735734739/The-Hunt-Club-Huger-Dillard-1-by-Bret-Lott.pdf
    • http://cefasfese.4pu.com/4739731738734730/Wheels-Down-Adjusting-to-Life-After-Deployment-by-Bret-A-Moore.pdf
    • http://cefasfese.4pu.com/9735730732732733/Greta-Garbo-Divine-Star-by-David-Bret.pdf
    • http://cefasfese.4pu.com/2731732734734736/Psycho-by-Robert-Bloch.pdf
    • http://cefasfese.4pu.com/4734732731737731/The-Psycho-by-James-Hudnall.pdf
    • http://cefasfese.4pu.com/9739739733731731/Psycho-Busters-4-by-Akinari-Nao.pdf
    • http://cefasfese.4pu.com/9739739732737731/Psycho-Busters-2-by-Akinari-Nao.pdf
    • http://cefasfese.4pu.com/4739738733739735/The-Freddy-Mercury-Story-Living-on-the-Edge-by-David-Bret.pdf
    • http://cefasfese.4pu.com/1739734737733738/American-Creation-Triumphs-and-Tragedies-at-the-Foundi