Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef9797474f51f743…

MALICIOUS

PDF

25.8 KB Created: 2019-05-02 06:51:16 +01:00 Authoring application: mPDF 5.7
MD5: e8518926babfed66c3ecbbb9f9ae4d41 SHA-1: 561d5f0c55eee826ff46f2eddb1860145aff5749 SHA-256: ef9797474f51f74374fecaa504f6821817e94103686b00053aa0d08662df8548
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF contains a large number of embedded links to external PDF files, all hosted on the domain 'cefasfese.4pu.com'. This heuristic firing, combined with the ML classifier's high confidence, suggests a malicious intent. The document body, though heavily obfuscated, contains URLs that are also present in the link farm heuristic. The primary attack pattern appears to be SEO poisoning or a similar traffic-driving scheme, rather than direct payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731738738738734736/I-Saw-the-Light---A-True-Story-of-a-Near-Death-Experience-by-Jeannie-Walker.pdf
    • http://cefasfese.4pu.com/1737737731733739/Thomas-The-Friendly-Ghost---A-True-Story-of-Ghostly-Encounters-by-Jeannie-Walker.pdf
    • http://cefasfese.4pu.com/4738731738730734/Fighting-the-Devil-A-True-Story-of-Consuming-Passion-Deadly-Poison-and-Murder-by-Jeannie-Walker.pdf
    • http://cefasfese.4pu.com/1737737731733734/Fighting-the-Devil-A-True-Story-of-Consuming-Passion-Deadly-Poison-and-Murder-by-Jeannie-Walker.pdf
    • http://cefasfese.4pu.com/1737737731734730/I-Saw-the-Light-by-Jeannie-Walker.pdf
    • http://cefasfese.4pu.com/1738734731739730/The-Men-with-the-Pink-Triangle-The-True-Life-and-Death-Story-of-Homosexuals-in-the-Nazi-Death-Camps-by-Heinz-Heger.pdf
    • http://cefasfese.4pu.com/3733735738738739/Mary-Walker-Wears-the-Pants-The-True-Story-of-the-Doctor-Reformer-and-Civil-War-Hero-by-Cheryl-Harness.pdf
    • http://cefasfese.4pu.com/6733734736739/NARUTO------Naruto-Itachi-Shinden-K-my--hen-Naruto-True-Chronicles-1-Itachi-s-True-Story-Book-of-Bright-Light-by-Masashi-Kishimoto.pdf
    • http://cefasfese.4pu.com/4733737731733732/To-Die-A-Dry-Death-The-True-Story-of-the-Batavia-Shipwreck-by-Greta-van-der-Rol.pdf
    • http://cefasfese.4pu.com/1735731730730732/To-Die-A-Dry-Death-The-True-Story-of-the-Batavia-Shipwreck-by-Greta-van-der-Rol.pdf
    • http://cefasfese.4pu.com/6735733731731732/With-You-There-Is-Light-Based-on-the-True-Story-about-Sophie-Scholl-and-Fritz-Hartnagel-by-Alexandra-Lehmann.pdf
    • http://cefasfese.4pu.com/3738732731738732/Saved-by-the-Light-The-True-Story-of-a-Man-Who-Died-Twice-and-the-Profound-Revelations-He-Received-by-Dannion-Brinkley.pdf
    • http://cefasfese.4pu.com/2735732733732730/Anyone-You-Want-Me-to-Be-A-True-Story-of-Sex-and-Death-on-the-Internet-by-John-Edward-Douglas.pdf
    • http://cefasfese.4pu.com/1730737/Winnie-The-True-Story-of-the-Bear-Who-Inspired-Winnie-the-Pooh-by-Sally-M-Walker.pdf
    • http://cefasfese.4pu.com/2737739736731739/Death-at-the-Harbourview-Cafe-A-True-Crime-Story-by-Fred-Humber.pdf
    • http://cefasfese.4pu.com/3735739732739735/The-Hand-on-the-Mirror-A-True-Story-of-Life-Beyond-Death-by-Janis-Heaphy-Durham.pdf
    • http://cefasfese.4pu.com/9732736739738730/Blasphemy-the-true-heartbreaking-story-of-the-woman-sentenced-to-death-over-a-cup-of-water-by-Asia-Bibi.pdf
    • http://cefasfese.4pu.com/7733737737730739/Grave-Accusations-A-True-Story-of-Lies-Family-Secrets-and-Death-by-Andrea-Egger.pdf
    • http://cefasfese.4pu.com/1736734736733/The-Death-of-Innocents-A-True-Story-of-Murder-Medicine-and-High-Stake-Science-by-Richard-Firstman.pdf
    • http://cefasfese.4pu.com/6731731739734737/God-s-Gift-of-Another-Angel-A-True-Story-About-a-Man-s-Dramatic-Life-Change-After-the-Death-of-His-Wife-by-Peter-Maheux.pdf
    • http://cefasfese.4pu.com/1738734731739730/The-Men-with-the-Pink-Triangle-The-True-Life-and-Death-Story-of-Homosexuals-in-the-Nazi-Death-Camps-by-Hei