Malicious PDF — malware analysis report

Static analysis result for SHA-256 e3c1dc23b9a08654…

MALICIOUS

PDF

19.4 KB Created: 2019-11-08 00:25:36 +00:00 Authoring application: mPDF 5.7
MD5: d33c73598cd6d88cc60988cc27ab90c6 SHA-1: ab31f0539d800e852051b5d17a83bb0b87e28e3d SHA-256: e3c1dc23b9a08654195c6ea3508964cc4444ac89127868aa8966ba4073302bb6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, hosted on the domain 'cefasfese.4pu.com'. This is indicative of a link farm or a phishing lure designed to direct users to potentially malicious content. The ML classifier also strongly flagged this document as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731739738730730736/The-Wrong-Man-Out-by-Kenneth-J-Ratajczak.pdf
    • http://cefasfese.4pu.com/4735735731736732/Chose-the-Wrong-Guy-Gave-Him-the-Wrong-Finger-by-Beth-Harbison.pdf
    • http://cefasfese.4pu.com/5730737735730/Wrong-Place-Wrong-Time-by-Tilia-Klebenov-Jacobs.pdf
    • http://cefasfese.4pu.com/1736732736731731/Chose-the-Wrong-Guy-Gave-Him-the-Wrong-Finger-by-Beth-Harbison.pdf
    • http://cefasfese.4pu.com/1731739738730730734/My-5-Senses-by-Jenni-Ratajczak.pdf
    • http://cefasfese.4pu.com/1731739738730730737/The-Choice-by-Brent-W-Ratajczak.pdf
    • http://cefasfese.4pu.com/1731739737739737739/Precious-Babies-by-Jenni-Ratajczak.pdf
    • http://cefasfese.4pu.com/3731738736736736/A-Year-Gone-Wrong-A-Bet-Gone-Wrong-3-by-xXTheBelieverXx.pdf
    • http://cefasfese.4pu.com/1739730734/Wrong-Wrong-1-by-Jana-Aston.pdf
    • http://cefasfese.4pu.com/3739730733739736/The-Wrong-Man-Right-and-Wrong-2-by-Lane-Hayes.pdf
    • http://cefasfese.4pu.com/1731739738730731731/Z-Perspektywy-Wartosci-O-Prozie-Dla-Dzieci-I-Modziezy-by-Maria-Kwiatkowska-Ratajczak.pdf
    • http://cefasfese.4pu.com/1730738732733731737/Leseprobe-Flurfunk-3-0---Ihr-Erfolgsgeheimnis-dauerhafter-Kundenbindung-Verbesserung-von-Projektmanagement-Zusammenarbeit-Wissensmanagement-amp-Motivation-mit-Unternehmens-Wikis-by-Oliver-Ratajczak.pdf
    • http://cefasfese.4pu.com/2732738738736737/Wrong-Wrong-1-by-L-P-Lovell.pdf
    • http://cefasfese.4pu.com/1731739738730730733/Fantastyczno-i-cudowno-cz-owiek-w-zwierciadle-przesz-o-ci-ucieczka-od-historii-do-Historii-by-Tomasz-Ratajczak.pdf
    • http://cefasfese.4pu.com/3739734734734731/Kenneth-Anger-A-Demonic-Visionary-by-Kenneth-Anger.pdf
    • http://cefasfese.4pu.com/3733739730739738/The-Kenneth-Anderson-Omnibus-Volume-2-by-Kenneth-Anderson.pdf
    • http://cefasfese.4pu.com/8739731734736/The-Kenneth-Williams-Diaries-by-Kenneth-Williams.pdf
    • http://cefasfese.4pu.com/6734737731735/Is-It-Wrong-to-Try-to-Pick-Up-Girls-in-a-Dungeon-Light-Novels-Vol-1-Is-It-Wrong-to-Try-to-Pick-Up-Girls-in-a-Dungeon-Light-Novels-1-by-Fujino-mori.pdf
    • http://cefasfese.4pu.com/3738737734730731/Mr-All-Wrong-by-R-C-Stephens.pdf
    • http://cefasfese.4pu.com/3731738736735737/A-Bet-Gone-Wrong-by-xXTheBelieverXx.pdf
    • http://cefasfese.4pu.com/1731739738730731731/Z-Perspektywy-Wartosci-O-Prozie-Dla-Dzieci-I-Modziezy-by-Maria-Kwiatkowska-Ratajcz