Malicious PDF — malware analysis report

Static analysis result for SHA-256 e985ee0df049fea2…

MALICIOUS

PDF

20.2 KB Created: 2020-01-04 08:24:31 +00:00 Authoring application: mPDF 5.7
MD5: 9a73874e0d100324e07cbb9eaed51663 SHA-1: 1cff231e4ad499a73eacbf09674c76813ff778d3 SHA-256: e985ee0df049fea270fbbc9157da361850dc88e27531be71530cb29220db9348
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links pointing to external PDF documents, predominantly hosted on the domain 'cefasfese.4pu.com'. This pattern is indicative of a link farm or a lure to a large collection of potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3733739737734731/The-Art-of-Star-Wars-Episode-V-The-Empire-Strikes-Back-by-Deborah-Call.pdf
    • http://cefasfese.4pu.com/3733739737733731/Star-Wars-The-Empire-Strikes-Back---The-Special-Edition-by-Archie-Goodwin.pdf
    • http://cefasfese.4pu.com/8731733730732739/Star-Wars-Episode-1-Journal-Pack--Anakin-Skywalker-and-Queen-Amidala-Star-Wars-Episode-1-Journal-by-Todd-Strasser.pdf
    • http://cefasfese.4pu.com/2731735735736737/The-Empire-Strikes-Back-The-National-Public-Radio-Dramatization-by-Brian-Daley.pdf
    • http://cefasfese.4pu.com/4737739733731739/William-Shakespeare-s-The-Empire-Striketh-Back-William-Shakespeare-s-Star-Wars-5-by-Ian-Doescher.pdf
    • http://cefasfese.4pu.com/3730734732733734/A-New-Hope-Star-Wars-Episode-IV-by-George-Lucas.pdf
    • http://cefasfese.4pu.com/3733739737735736/The-Art-of-Star-Wars-Episode-VI-Return-of-the-Jedi-by-Carol-Titelman.pdf
    • http://cefasfese.4pu.com/3734730731731734/Star-Wars-Episode-II-Attack-of-the-Clones-Volume-4-by-Henry-Gilroy.pdf
    • http://cefasfese.4pu.com/3734730731731735/Star-Wars-Episode-II-Attack-of-the-Clones-Volume-1-by-Henry-Gilroy.pdf
    • http://cefasfese.4pu.com/3734730730733737/Star-Wars-Episode-I-The-Phantom-Menace-Volume-1-by-Henry-Gilroy.pdf
    • http://cefasfese.4pu.com/5738735736732734/The-Making-of-Star-Wars-Episode-I---The-Phantom-Menace-by-Laurent-Bouzereau.pdf
    • http://cefasfese.4pu.com/3733739733735734/The-Visual-Dictionary-of-Star-Wars-Episode-I---The-Phantom-Menace-by-David-West-Reynolds.pdf
    • http://cefasfese.4pu.com/3733739737732736/Star-Wars-Episode-II---Attack-of-the-Clones-The-Visual-Dictionary-by-David-West-Reynolds.pdf
    • http://cefasfese.4pu.com/6738736736735732/Star-Wars-Shadows-of-The-Empire-by-John-Wagner.pdf
    • http://cefasfese.4pu.com/5730735733/Empire-s-End-Star-Wars-Aftermath-3-by-Chuck-Wendig.pdf
    • http://cefasfese.4pu.com/6731735731733736/Heir-to-the-Empire-Star-Wars-The-Thrawn-Trilogy-1-by-Timothy-Zahn.pdf
    • http://cefasfese.4pu.com/3739738731734739/Razor-s-Edge-Star-Wars-Empire-and-Rebellion-1-by-Martha-Wells.pdf
    • http://cefasfese.4pu.com/3734730730734737/Slave-to-the-Empire-An-Erotic-Star-Wars-Adventure-Outer-Rim-Affairs-Book-1-by-Ravyn-Jade.pdf
    • http://cefasfese.4pu.com/6736731736738736/Star-Wars-Chevaliers-de-l-ancienne-r-publique-T05-Sans-piti-Star-Wars-Knights-of-the-Old-Republic-6-by-John-Jackson-Miller.pdf
    • http://cefasfese.4pu.com/3733739737733739/Star-Wars-Vol-3-Rebel-Jail-Star-Wars-3-by-Jason-Aaron.pdf
    • http://cefasfese.4pu.com/3730734732733734/A-New-Hope-Star-