Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5f922acb4b27d48…

MALICIOUS

PDF

22.2 KB Created: 2019-09-27 13:20:27 +01:00 Authoring application: mPDF 5.7
MD5: bbe75fade988ee612ff21af069529ece SHA-1: b567aecf6bf44b18dfd57c17594a3f327ea903ce SHA-256: e5f922acb4b27d4807ccff2cda8ab80a2cea9ce7a1ee47cd3512bfb9cd560ead
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF document contains a large number of embedded links to external PDF files, hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a redirection mechanism designed to lead users to potentially malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9731733734735739/Stimmen-in-der-Nacht-by-Phyllis-A-Whitney.pdf
    • http://cefasfese.4pu.com/9731733736731733/Die-Stimmen-in-der-Nacht-by-Surprise-Sithpole.pdf
    • http://cefasfese.4pu.com/9735738737735735/Warrior-Cats---Zeichen-der-Sterne-Stimmen-der-Nacht-IV-Band-3-by-Erin-Hunter.pdf
    • http://cefasfese.4pu.com/4737737735738735/Love-in-a-Time-of-Homeschooling-A-Mother-and-Daughter-s-Uncommon-Year-by-Laura-Brodie.pdf
    • http://cefasfese.4pu.com/1730731736732735734/Phantastische-Nacht-und-5-andere-Erz-hlungen-Sommernovellette-Die-Gouvernante-Die-sp-t-bezahlte-Schuld-Vierundzwanzig-Stunden-aus-dem-Leben-einer-Phantastische-Nacht-by-Stefan-Zweig.pdf
    • http://cefasfese.4pu.com/1731732737732734739/Ferne-Stimmen-in-Ihrer-N-he-by-Dal-Ja-Shin.pdf
    • http://cefasfese.4pu.com/9731738734734736/Joseph-Roth-Irmgard-Keun-Der-Leviathan-Die-Kapuzinergruft-Radetzkymarsch-Die-Hundert-Tage-Der-Stumme-Prophet-Die-Geschichte-Von-Der-1002-Nacht-Tarabas-Beichte-Eines-Morders-Erzahlt-in-Einer-Nacht-Zipper-Und-Sein-Vater-by-Source-Wikipedia.pdf
    • http://cefasfese.4pu.com/8735732736731735/Auf-Andere-Art-So-Groe-Hoffnung-Literatur-in-Der-Ddr-1951-Stimmen-Und-Texte-by-Evelyn-Doerr.pdf
    • http://cefasfese.4pu.com/9738731735737733/Und-sah-die-Himmel-offen-SPIRITUALIT-T-DIESSEITS-UND-JENSEITS-VON-RELIGION---Erz-hlungen-Stimmen-Reflexionen-by-Peter-Erlenwein.pdf
    • http://cefasfese.4pu.com/1739731736734730/No-Man-Knows-My-History-by-Fawn-M-Brodie.pdf
    • http://cefasfese.4pu.com/1739738731732732/In-His-Love-by-Deborah-Brodie.pdf
    • http://cefasfese.4pu.com/1730737735737734735/Liars-All-Brodie-Farrell-9-by-Jo-Bannister.pdf
    • http://cefasfese.4pu.com/1730737735736737731/Reflections-Brodie-Farrell-3-by-Jo-Bannister.pdf
    • http://cefasfese.4pu.com/2739730731734732/The-Watcher-Brodie-MacLennan-3-by-Grace-Monroe.pdf
    • http://cefasfese.4pu.com/1733739738734736/Brodie-s-Report-by-Jorge-Luis-Borges.pdf
    • http://cefasfese.4pu.com/1738733737731737/Death-Has-a-Name-Brodie-Wade-1-by-Jerry-Hanel.pdf
    • http://cefasfese.4pu.com/1730737735736737730/Echoes-of-Lies-Brodie-Farrell-1-by-Jo-Bannister.pdf
    • http://cefasfese.4pu.com/1730737735737735731/Requiem-for-a-Dealer-Brodie-Farrell-6-by-Jo-Bannister.pdf
    • http://cefasfese.4pu.com/8730739737735730/The-Prime-of-Miss-Jean-Brodie-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/4734739733735736/The-Prime-of-Miss-Jean-Brodie-by-Muriel-Spark.pdf
    • http://cefasfese.4pu.com/1731732737732734739/Ferne-Stimme