Malicious PDF — malware analysis report

Static analysis result for SHA-256 dd7f6bea3920b17b…

MALICIOUS

PDF

17.5 KB Created: 2019-06-04 19:26:26 +01:00 Authoring application: mPDF 5.7
MD5: 9fb05f25603cd4554414461f1925ef0a SHA-1: 518c9e4557123f04ccf3c718e2c299c08448095c SHA-256: dd7f6bea3920b17b095e8058a033f8e9ac0c92a0b4ae3c929936285394d98e68
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'cefasfese.4pu.com'. This is indicative of a link farm or a lure to download further malicious content. The ML classifier also flagged this PDF as malicious with a high probability. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the immediate user-facing content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9684

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2737731739733/Morons-and-Madmen-Mac-Fontana-3-by-Earl-Emerson.pdf
    • http://cefasfese.4pu.com/4738738736733731/The-Dead-Horse-Paint-Company-Mac-Fontana-5-by-Earl-Emerson.pdf
    • http://cefasfese.4pu.com/3734734733737736/Into-the-Inferno-by-Earl-Emerson.pdf
    • http://cefasfese.4pu.com/1737732736738/Poverty-Bay-Thomas-Black-2-by-Earl-Emerson.pdf
    • http://cefasfese.4pu.com/3734734733737738/The-Portland-Laugher-Thomas-Black-7-by-Earl-Emerson.pdf
    • http://cefasfese.4pu.com/1730737735737735734/Dear-Asshole-101-Tear-Out-Letters-to-the-Morons-Who-Muck-Up-Your-Life-by-Jillian-Madison.pdf
    • http://cefasfese.4pu.com/4733739732733739/The-Madmen-s-City-by-Cady-Vance.pdf
    • http://cefasfese.4pu.com/3730736736731737/Gotham-Central-Book-Two-Jokers-and-Madmen-by-Ed-Brubaker.pdf
    • http://cefasfese.4pu.com/4734730733735732/Lovers-and-Madmen-Brothers-Maledetti-Book-0-by-Nichole-Van.pdf
    • http://cefasfese.4pu.com/6735736733739734/Earl-Proulx-s-Yankee-Home-Hints-From-Stains-on-the-Rug-to-Squirrels-in-the-Attic-Over-1-500-Ingenious-Solutions-to-Everyday-Household-Problems-by-Earl-Proulx.pdf
    • http://cefasfese.4pu.com/4732731738737739/My-Fat-Mad-Teenage-Diary-Rae-Earl-1-by-Rae-Earl.pdf
    • http://cefasfese.4pu.com/3732736735739736/Short-Stories-of-Earl-Staggs-Mystery-Tales-from-Hardboiled-to-Humor-by-Earl-Staggs.pdf
    • http://cefasfese.4pu.com/3738737739734737/The-Questor-Tapes-by-D-C-Fontana.pdf
    • http://cefasfese.4pu.com/4735737734730734/Fontana-by-Joshua-Martino.pdf
    • http://cefasfese.4pu.com/3734738738734736/This-Star-Won-t-Go-Out-The-Life-and-Words-of-Esther-Grace-Earl-by-Esther-Earl.pdf
    • http://cefasfese.4pu.com/9735738730/This-Star-Won-t-Go-Out-The-Life-and-Words-of-Esther-Grace-Earl-by-Esther-Earl.pdf
    • http://cefasfese.4pu.com/2737739735739732/Madmen-s-Manifestos-Chris-Dorner-Charles-Manson-Timothy-McVeigh-and-others-by-Grigory-Lukin.pdf
    • http://cefasfese.4pu.com/6730730733737731/Lucio-Fontana-The-Artist-s-Materials-by-Pia-Gottschaller.pdf
    • http://cefasfese.4pu.com/6730730733733733/Lucio-Fontana-Between-Utopia-and-Kitsch-by-Anthony-White.pdf
    • http://cefasfese.4pu.com/6730730733732730/Lucio-Fontana-1899-1968-by-Barbara-Hess.pdf
    • http://cefasfese.4pu.com/6735736733739734/Earl-Proulx-s-Yankee-Home-Hints-From-Stains-on-the-Rug-to-Squirrels-in-the-Attic-Over-1-500-Ingenious-Solutions-to-E