Malicious PDF — malware analysis report

Static analysis result for SHA-256 e0d3014e1ddb2847…

MALICIOUS

PDF

19.4 KB Created: 2019-11-28 22:25:27 +00:00 Authoring application: mPDF 5.7
MD5: cd95336aad203b1fc5cf6193676fc3aa SHA-1: a342f3ca1c3f44f56b875e2999b1a91d004a13c4 SHA-256: e0d3014e1ddb28478269cc446a9e32faa94356ce84565fcb59648530c288c0a4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDFs hosted on the domain 'cefasfese.4pu.com'. This is indicative of a link farm or SEO spamming technique, likely intended to drive traffic or distribute further malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730735734730730/The-Complete-Peter-Rabbit-Library-23-Book-Boxed-Set-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/5738736736733737/The-Tale-of-Peter-Rabbit-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/5730734735736730/The-Tale-Of-Peter-Rabbit-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/5739737730735733/The-Tale-of-Peter-Rabbit-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/6739738738730733/The-Tale-Of-Peter-Rabbit-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/8733731734733731/Giant-Treasury-of-Peter-Rabbit-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/8733731733737738/Tales-of-Peter-Rabbit-and-His-Friends-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/8733734739737734/THE-TALE-OF-TOM-KITTEN---Peter-Rabbit-Series-08-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/8735732739739736/The-Tale-of-Peter-Rabbit-Illustrated-Edition-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/6739739732732731/The-Tale-of-Peter-Rabbit-Sticker-Storybook-R-I-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/7733738735733737/El-Cuento-de-Pedrito-Conejo-The-Tale-of-Peter-Rabbit-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/9732731739734730/The-Tale-of-Peter-Rabbit-1000-Copy-Limited-Edition-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/6731736732738739/The-Tale-of-Peter-Rabbit-Presented-By-Frendees-English-French-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/5733735734735739/L-Histoire-de-Pierre-Lapin-Livre-D-Histoires-En-Coulteurs-Peter-Rabbit-in-Fre-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/2736734730739730/The-Story-of-A-Fierce-Bad-Rabbit-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/4738731736731737/Articles-on-Books-by-Beatrix-Potter-Including-The-Tale-of-Peter-Rabbit-the-Tale-of-Samuel-Whiskers-or-the-Roly-Poly-Pudding-the-Tale-of-the-Flopsy-Bunnies-the-Tale-of-Squirrel-Nutkin-the-Tale-of-Mr-Jeremy-Fisher-by-Hephaestus-Books.pdf
    • http://cefasfese.4pu.com/9733733735734731/Die-Geschichte-von-den-Flopsy-Bunnies-illustriert-Eine-Bildergeschichte-f-r-Kinder-im-Alter-von-2-bis-6-Jahren-Beatrix-Potter-Serie-10-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/3731738735731733/The-Complete-Adventures-of-Tom-Kitten-and-His-Friends-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/8739730739734739/Die-Geschichte-Von-Peter-Hase-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/8733731733738738/The-Beatrix-Potter-Collection-Volume-Two-by-Beatrix-Potter.pdf
    • http://cefasfese.4pu.com/6739739732732731/The-Tale-of-Peter-Rabbit-Sticker-Storyboo