Malicious PDF — malware analysis report

Static analysis result for SHA-256 e17ec0813282cd13…

MALICIOUS

PDF

15.4 KB Created: 2019-06-13 20:42:16 +01:00 Authoring application: mPDF 5.7
MD5: d449d1da6055c94af6525d166dcb796a SHA-1: 24cf7594374806f5dbb410b57d6e0846b1ffe124 SHA-256: e17ec0813282cd13f5734c6bc520fc57e10ce09954f2a7b9974f13cf69d2aa68
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, primarily hosted on the domain 'cefasfese.4pu.com'. This pattern is indicative of a link farm or a method to distribute malicious content disguised as legitimate documents. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6732733730736736/A-Formidable-Hero-2nd-Edition-by-Stuart-E-Soward.pdf
    • http://cefasfese.4pu.com/6738739737733737/L-Utilitarisme-seconde-dition-by-John-Stuart-Mill.pdf
    • http://cefasfese.4pu.com/1731738730733738731/ITIL-Service-Transition-2011-Edition-by-Stuart-Rance.pdf
    • http://cefasfese.4pu.com/4731738735734735/Rough-Magick-GnomeSaga-1-by-Kenny-Soward.pdf
    • http://cefasfese.4pu.com/1735730730731732/The-Royal-Road-to-Fotheringhay-Stuart-Saga-1-Mary-Stuart-1-by-Jean-Plaidy.pdf
    • http://cefasfese.4pu.com/3734739731735737/Hero-in-the-Highlands-No-Ordinary-Hero-1-by-Suzanne-Enoch.pdf
    • http://cefasfese.4pu.com/7733735734738/TITAN-From-Earth-s-Past-A-Hero-Rises-A-Young-Adult-Super-Hero-Adventure-Novel-Adventures-Of-An-Olympian-Book-1-by-Jeff-Fuell.pdf
    • http://cefasfese.4pu.com/6732732739739730/Formidable-Imposition-by-Tim-Johnson.pdf
    • http://cefasfese.4pu.com/6732732739736735/The-Formidable-Genius-by-D-C-Ranatunga.pdf
    • http://cefasfese.4pu.com/3730732733733731/Eyes-Of-A-Hero-Hero-2-by-Cheryl-Yeko.pdf
    • http://cefasfese.4pu.com/2732735735737732/Her-Forbidden-Hero-The-Hero-1-by-Laura-Kaye.pdf
    • http://cefasfese.4pu.com/3734732734734739/Puffy-and-the-Formidable-Foe-by-Marie-G-Lepkowski.pdf
    • http://cefasfese.4pu.com/6732732739732734/Conan-the-Formidable-by-Steve-Perry.pdf
    • http://cefasfese.4pu.com/6732733730736739/The-Most-Formidable-Thing-by-William-Jameson.pdf
    • http://cefasfese.4pu.com/6732732739739734/The-Formidable-Family-by-Dominic-J-Arcuri.pdf
    • http://cefasfese.4pu.com/6732732739732737/The-Formidable-King-by-Alyssa-J-Montgomery.pdf
    • http://cefasfese.4pu.com/6732733730730734/The-Formidable-Employee-by-Dominic-J-Arcuri.pdf
    • http://cefasfese.4pu.com/6732733730735739/Rosie-and-her-Formidable-Bark-by-Vivienne-Williams.pdf
    • http://cefasfese.4pu.com/6732733730732738/The-Formidable-Stranger-Volume-1-by-Ronzeno-Edwards.pdf
    • http://cefasfese.4pu.com/6732733730737734/Fast-and-Formidable-Animals-by-Agatha-Gregson.pdf
    • http://cefasfese.4pu.com/7733735734738/TITAN-From-Earth-s-Past-A-Hero-Rises-A-Young-Adult-Super-Hero-Adventure-Novel-Adventures-Of-An-Olympian-Book-1