Malicious PDF — malware analysis report

Static analysis result for SHA-256 e303efdf9aff157a…

MALICIOUS

PDF

17.1 KB Created: 2019-06-05 06:03:31 +01:00 Authoring application: mPDF 5.7
MD5: 97b4e4ee73220da1417f2df8750f5237 SHA-1: c2bfc743c10941816f0e18aaf7ec0e445961dc74 SHA-256: e303efdf9aff157a21ddae9ab5512163c93b80263961ecf17ccedcdd9447dbd0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded links to external websites, as indicated by the PDF_SEO_LINK_FARM heuristic. While the specific content of the document body is heavily obfuscated, the presence of numerous links suggests an attempt to direct users to potentially malicious or spam-related content. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the file. The primary attack pattern appears to be a link farm designed to distribute traffic or host malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4733734735732736/My-Fair-Mistress-Mistress-Trilogy-1-by-Tracy-Anne-Warren.pdf
    • http://cefasfese.4pu.com/8739733733739/His-Favorite-Mistress-Mistress-Trilogy-3-by-Tracy-Anne-Warren.pdf
    • http://cefasfese.4pu.com/4732738732739732/Mistresses-The-Italian-s-Inexperienced-Mistress-Emerald-Mistress-Mistress-Bought-and-Paid-For-by-Lynne-Graham.pdf
    • http://cefasfese.4pu.com/8739734731734/More-Than-a-Mistress-Mistress-Trilogy-1-by-Mary-Balogh.pdf
    • http://cefasfese.4pu.com/4732735735738734/His-Fall-From-Power---Part-II-Mistress-Doreen-and-Slave-Thomas-by-Mistress-Benay.pdf
    • http://cefasfese.4pu.com/2730730735739/Mistress-Moderately-Fair-by-Katherine-Sturtevant.pdf
    • http://cefasfese.4pu.com/2736734734737731/To-His-Mistress-Book-3-by-Ann-Tracy-Marr.pdf
    • http://cefasfese.4pu.com/2734734737734737/Sweetest-Mistress-Fem-Dom-1-by-Skye-Warren.pdf
    • http://cefasfese.4pu.com/3739734730736737/The-Wife-Trap-The-Trap-Trilogy-2-by-Tracy-Anne-Warren.pdf
    • http://cefasfese.4pu.com/1731730735737/The-Husband-Trap-The-Trap-Trilogy-1-by-Tracy-Anne-Warren.pdf
    • http://cefasfese.4pu.com/1731737738735/One-Night-Mistress-Convenient-Wife-by-Anne-McAllister.pdf
    • http://cefasfese.4pu.com/4732738731733731/The-King-the-Queen-and-the-Mistress-The-Tudors-1-by-Anne-Gracie.pdf
    • http://cefasfese.4pu.com/1732736732735739/Madame-s-Deception-Mistress-Trilogy-2-by-Renee-Bernard.pdf
    • http://cefasfese.4pu.com/2738736738730734/The-Mistress-Great-Chicago-Fire-Trilogy-2-by-Susan-Wiggs.pdf
    • http://cefasfese.4pu.com/2737739737734730/Her-Highness-and-the-Highlander-The-Princess-Brides-2-by-Tracy-Anne-Warren.pdf
    • http://cefasfese.4pu.com/2730734732733735/Bedchamber-Games-The-Rakes-of-Cavendish-Square-3-by-Tracy-Anne-Warren.pdf
    • http://cefasfese.4pu.com/1739737732739732/Wicked-Delights-of-a-Bridal-Bed-The-Byrons-of-Braebourne-4-by-Tracy-Anne-Warren.pdf
    • http://cefasfese.4pu.com/4739732735738735/Mistress-of-the-City-Mistress-of-the-City-1-by-Mina-Carter.pdf
    • http://cefasfese.4pu.com/2733730738730737/The-Complete-Empire-Trilogy-Daughter-of-the-Empire-Mistress-of-the-Empire-Servant-of-the-Empire-The-Empire-Trilogy-1-3-by-Raymond-E-Feist.pdf
    • http://cefasfese.4pu.com/4734736730731/Mistress-of-the-Empire-The-Empire-Trilogy-3-by-Raymond-E-Feist.pdf