Malicious PDF — malware analysis report

Static analysis result for SHA-256 0254f1b5fe36167b…

MALICIOUS

PDF

25.9 KB Created: 2019-05-02 19:42:21 +01:00 Authoring application: mPDF 5.7
MD5: 8dcb7c5f3b2c9195b3363174e0adc474 SHA-1: f0de1f1b6a90725cfb76458ce09fcd3334ec4fd5 SHA-256: 0254f1b5fe36167bb28baae42da140376f4467483c75cf6faed8b07bc0ee3496
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various book titles. While the URLs themselves are marked as benign, the sheer volume and structure suggest a link farm intended to drive traffic or potentially distribute further malicious content. The ML classifier also flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730733731739733738/Biografie-sessuali-I-casi-clinici-dalla-Psychopathia-sexualis-di-Richard-von-Krafft-Ebing-by-F-Verzotto.pdf
    • http://cefasfese.4pu.com/1730733731739732732/Psychopathia-Sexualis-avec-recherches-sp-ciales-sur-l-inversion-sexuelle-by-R-von-Richard-Krafft-Ebing.pdf
    • http://cefasfese.4pu.com/1730733731738736735/Psychopathia-Sexualis-With-Especial-Reference-to-Contrary-Sexual-Instinct-A-Medico-Legal-Study-by-R-von-1840-1902-Krafft-Ebing.pdf
    • http://cefasfese.4pu.com/1730733731737730739/Psychopathia-Sexualis-by-John-Patrick-Shanley.pdf
    • http://cefasfese.4pu.com/1730733731737736737/The-Use-of-Hypnosis-in-Psychopathia-Sexualis-by-Albert-Freiherr-Von-Schrenck-Notzing.pdf
    • http://cefasfese.4pu.com/1730733731739734737/Love-Lust-Kink-20-Book-3-Venus-in-Furs-Psychopathia-Sexualis-Oscar-Wilde-by-Tony-Kelbrat.pdf
    • http://cefasfese.4pu.com/1730733731739731734/Psychopathia-Sexualis-with-Especial-Reference-to-Contrary-Sexual-Instinct-A-Medico-Legal-Study-by-Charles-Gilbert-Chaddock.pdf
    • http://cefasfese.4pu.com/1730733731737737735/Psychopathia-Sexualis-with-especial-reference-to-the-antipathic-sexual-instinct-a-medico-forensic-study-by-Francis-Joseph-Rehman.pdf
    • http://cefasfese.4pu.com/1730733731738735733/Heinrich-Kaan-s-quot-psychopathia-Sexualis-quot-1844-A-Classic-Text-in-the-History-of-Sexuality-by-Heinrich-Kaan.pdf
    • http://cefasfese.4pu.com/2736738739734735/Beyond-the-Mist-Lake-Lanier-Mysteries-2-by-Casi-McLean.pdf
    • http://cefasfese.4pu.com/1730733730738739734/Caruso-the-song-Lucio-Dalla-e-Sorrento-by-Raffaele-Lauro.pdf
    • http://cefasfese.4pu.com/1731734731736734737/The-Beatles-de-biografie-by-Bob-Spitz.pdf
    • http://cefasfese.4pu.com/2736734730739739/Vita-Sexualis-by-gai-Mori.pdf
    • http://cefasfese.4pu.com/1730733731737731736/Illustrated-Encyclopedia-Sexualis-by-Unknown.pdf
    • http://cefasfese.4pu.com/1730738732738733733/I-primi-casi-di-Martin-Beck-Roseanna---L-uomo-che-and-in-fumo---L-uomo-al-balcone-by-Maj-Sj-wall.pdf
    • http://cefasfese.4pu.com/3737739736732731/One-of-a-Kind-The-Rise-and-Fall-of-Stuey-The-Kid-Ungar-The-World-s-Greatest-Poker-Player-by-Nolan-Dalla.pdf
    • http://cefasfese.4pu.com/1730735738736734734/Il-Museo-Renato-Marino-Mazzacurati-Opere-Dalla-Donazione-Carla-Marzi-by-Martina-De-Luca.pdf
    • http://cefasfese.4pu.com/9731731731731735/Frank-Stronach-Die-Biografie-by-Wolfgang-F-rweger.pdf
    • http://cefasfese.4pu.com/9735735734730732/An-Rutgers-Van-Der-Loeff-Een-Biografie-by-Joke-Linders.pdf
    • http://cefasfese.4pu.com/8733737736730/I-grandi-casi-di-Sherlock-Holmes-Tutti-i-romanzi-Uno-studio-in-rosso---Il-segno-dei-quattro---Il-mastino-di-Baskerville---La-valle-della-paura-by-Arthur-Conan-Doyle.pdf