Malicious PDF — malware analysis report

Static analysis result for SHA-256 eae52ca61a1af912…

MALICIOUS

PDF

17.4 KB Created: 2019-11-07 16:00:07 +00:00 Authoring application: mPDF 5.7
MD5: bcd4c9d8d0749452ef087f6138890ce3 SHA-1: 3f25d4ed6e281f40ebee7ff753e5a0a1345f4596 SHA-256: eae52ca61a1af912148dcb54bcd854a04752e53fb8f7142707838aec7b74fa92
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDFs hosted on the domain 'cefasfese.4pu.com'. This domain and the structure of the links strongly suggest a link farm or SEO poisoning tactic, likely intended to drive traffic to potentially malicious content or to obscure the true malicious intent. The ML classifier also flagged this PDF with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3733732739734732/Unconditional-Love-Seven-Days-2-by-Andrew-Grey.pdf
    • http://cefasfese.4pu.com/4734738733737734/Love-Comes-Around-Senses-4-by-Andrew-Grey.pdf
    • http://cefasfese.4pu.com/2738737735735737/Love-in-War-Satyr-1-5-by-Andrew-Grey.pdf
    • http://cefasfese.4pu.com/2739739731733736/A-Taste-of-Love-Of-Love-1-by-Andrew-Grey.pdf
    • http://cefasfese.4pu.com/3732731739735734/A-Serving-of-Love-Of-Love-2-by-Andrew-Grey.pdf
    • http://cefasfese.4pu.com/3733732730732730/Love-Means-Patience-by-Andrew-Grey.pdf
    • http://cefasfese.4pu.com/3738731737733736/Love-Comes-to-Light-Senses-6-by-Andrew-Grey.pdf
    • http://cefasfese.4pu.com/2735737731734735/Love-Comes-in-Darkness-Senses-2-by-Andrew-Grey.pdf
    • http://cefasfese.4pu.com/4736739738737731/Love-Comes-in-Darkness-Senses-2-by-Andrew-Grey.pdf
    • http://cefasfese.4pu.com/4731738731734734/Love-Means-Freedom-Farm-3-by-Andrew-Grey.pdf
    • http://cefasfese.4pu.com/4734738735730738/Love-Means-No-Limits-Farm-9-by-Andrew-Grey.pdf
    • http://cefasfese.4pu.com/3736734733731730/Love-Comes-Unheard-Senses-Series-by-Andrew-Grey.pdf
    • http://cefasfese.4pu.com/2732733735739739/Love-Means-No-Boundaries-Farm-2-by-Andrew-Grey.pdf
    • http://cefasfese.4pu.com/4737738739733738/Unconditional-Love-Love-Life-amp-Happiness-3-by-Sheena-Binkley.pdf
    • http://cefasfese.4pu.com/3739736733731731/Unconditional-Love-Journey-of-Love-1-by-Kelly-Elliott.pdf
    • http://cefasfese.4pu.com/8736735736732736/Kugel-Chaos-amp-Unconditional-Love-by-Mrs-Chana-Gittle-Deray.pdf
    • http://cefasfese.4pu.com/3734735733738732/The-Underdogs-Children-Dogs-and-the-Power-of-Unconditional-Love-by-Melissa-Fay-Greene.pdf
    • http://cefasfese.4pu.com/3739739735737733/Unconditional-Parenting-Moving-from-Rewards-and-Punishments-to-Love-and-Reason-by-Alfie-Kohn.pdf
    • http://cefasfese.4pu.com/3737735735736739/How-to-Make-the-Most-of-Your-Earth-Experience-14-Principles-for-Living-Unconditional-Love-by-Glenn-Younger.pdf
    • http://cefasfese.4pu.com/9737737736738/Unbinding-the-Heart-A-Dose-of-Greek-Wisdom-Generosity-and-Unconditional-Love-by-Agapi-Stassinopoulos.pdf
    • http://cefasfese.4pu.com/2732733735739739/Love-Means-No-