Malicious PDF — malware analysis report

Static analysis result for SHA-256 df484ac17fdba7d7…

MALICIOUS

PDF

16.2 KB Created: 2019-05-02 06:11:13 +01:00 Authoring application: mPDF 5.7
MD5: b907a7af3d0898628bff069f7ca420a7 SHA-1: 45cc77295d82d15d4e5e2636e7c658996bfea463 SHA-256: df484ac17fdba7d7ac928b2a41ae1b0f42d0fdf18a97794306d671642113ed01
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDFs hosted on the domain 'cefasfese.4pu.com'. This heuristic firing indicates a link farm, suggesting a social engineering tactic to direct users to potentially malicious content. The ML classifier also flagged this PDF with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3739738739737732/Mica-Rebel-Wayfarers-MC-1-by-MariaLisa-deMora.pdf
    • http://cefasfese.4pu.com/1730736733733730731/Rebel-Wayfarers-MC-Vol-1-3-by-MariaLisa-deMora.pdf
    • http://cefasfese.4pu.com/1730736733732735738/Duck-Rebel-Wayfarers-MC-8-by-MariaLisa-deMora.pdf
    • http://cefasfese.4pu.com/3730738738730736/Slate-Rebel-Wayfarers-MC-2-by-MariaLisa-deMora.pdf
    • http://cefasfese.4pu.com/1730736733733731730/Biker-Chick-Campout-Rebel-Wayfarers-MC-8-5-by-MariaLisa-deMora.pdf
    • http://cefasfese.4pu.com/1730736733733731731/With-My-Whole-Heart-by-MariaLisa-deMora.pdf
    • http://cefasfese.4pu.com/1730736733733731734/Hot-Wicked-Romances-by-MariaLisa-deMora.pdf
    • http://cefasfese.4pu.com/1730736733733731735/Born-Into-Trouble-Occupy-Yourself-1-by-MariaLisa-deMora.pdf
    • http://cefasfese.4pu.com/1730736737737738/Mica-Moon-and-the-Domed-Cities-Mica-Moon-1-by-Leia-Stone.pdf
    • http://cefasfese.4pu.com/9739735738739731/As-Lamperl-mit-de-Dramsockn-by-Mica-N-Brandau.pdf
    • http://cefasfese.4pu.com/2739737732733730/Rogue-Rebel-Part-II-Bad-Blooded-Rebel-1-by-Mellie-George.pdf
    • http://cefasfese.4pu.com/1730736738735732/The-Rebel-Within-Rebel-1-by-Lance-Erlick.pdf
    • http://cefasfese.4pu.com/2736730736733733/A-Closed-and-Common-Orbit-Wayfarers-2-by-Becky-Chambers.pdf
    • http://cefasfese.4pu.com/4734730738735737/A-Closed-and-Common-Orbit-Wayfarers-2-by-Becky-Chambers.pdf
    • http://cefasfese.4pu.com/4732730730/A-Closed-and-Common-Orbit-Wayfarers-2-by-Becky-Chambers.pdf
    • http://cefasfese.4pu.com/3730733736732737/The-Long-Way-to-a-Small-Angry-Planet-Wayfarers-1-by-Becky-Chambers.pdf
    • http://cefasfese.4pu.com/4737731736736731/Barbarians-at-the-Plate-Taming-and-Feeding-the-American-Family-by-Marialisa-Calta.pdf
    • http://cefasfese.4pu.com/1730736733733735734/A-Responsabilidade-Do-Estado-Pela-Demora-Na-Prestac-ao-Jurisdicional-by-Danielle-Annoni.pdf
    • http://cefasfese.4pu.com/4731735739736736/Rebel-Song-Rebel-Song-1-by-Amanda-J-Clay.pdf
    • http://cefasfese.4pu.com/1730736733733735736/Los-Intereses-Por-Retraso-O-Demora-a-Favor-de-La-Hacienda-Publica-by-Rosa-Maria-Alfonso-Galan.pdf
    • http://cefasfese.4pu.com/1730736738735732/The-Rebel-Within-Rebel-