Malicious PDF — malware analysis report

Static analysis result for SHA-256 025faac621ab768a…

MALICIOUS

PDF

14.8 KB Created: 2019-05-04 05:29:22 +01:00 Authoring application: mPDF 5.7
MD5: c1e8dd701d153242f0c19e038ece7579 SHA-1: b0b9baae1f3ab72d55c5076c0d1f153fe0a3ba49 SHA-256: 025faac621ab768af250b078ab5a012bec795ce6352f197b7cc6515fba2b0b93
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious. The embedded links likely lead to a phishing site or a download server for further malicious payloads. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9735731730734739/Verkauft-Verzweifelter-Ausweg-Leseprobe-by-Valuta-Tomas.pdf
    • http://cefasfese.4pu.com/8737734739736739/Letzter-Ausweg-by-Tiara-Flyable.pdf
    • http://cefasfese.4pu.com/1730734732732738737/Ohne-Ausweg-CSI-New-York-Bd-4-by-Keith-R-A-DeCandido.pdf
    • http://cefasfese.4pu.com/1730734732732733733/En-dernier-recours-Als-letzten-Ausweg-by-Ailis-Regin.pdf
    • http://cefasfese.4pu.com/1730734732732732738/Ausweg-Liebe-Ein-Chick-Lit-Liebesroman-by-Jenna-Rick.pdf
    • http://cefasfese.4pu.com/1730732738734737738/Verdammt-verliebt-Ausweg-aus-der-Eheh-lle-by-Doreen-Znaidi.pdf
    • http://cefasfese.4pu.com/1730734732733737739/Ohne-Ausweg-Burnout-und-die-Angst-vor-der-Arbeit-by-Clemens-L-Bachstein.pdf
    • http://cefasfese.4pu.com/9735730739732735/Verkauft-an-den-L-wen-by-T-S-Ryder.pdf
    • http://cefasfese.4pu.com/9735730737738739/Verkauft-by-Sophie-Stern.pdf
    • http://cefasfese.4pu.com/1730734732732733735/Kein-Ausweg-mehr-Eine-erotisch-schwule-Fantasie-by-K-Windsor.pdf
    • http://cefasfese.4pu.com/9735730738735731/Verkauft-und-verloren-by-Marie-Bernhard.pdf
    • http://cefasfese.4pu.com/9735730739732730/In-der-Karibik---Verkauft-by-Maria-Caviglia.pdf
    • http://cefasfese.4pu.com/9735730739732731/AUF-DEM-SKLAVENMARKT-VERKAUFT-by-J-rgen-Prommersberger.pdf
    • http://cefasfese.4pu.com/9735730738736732/Kidnapping-entf-hrt-und-verkauft-by-Allison-Parkham.pdf
    • http://cefasfese.4pu.com/9735730738735730/Tot-verkauft-s-sich-besser-by-Sabine-Herzig.pdf
    • http://cefasfese.4pu.com/9735731730735732/Verkauft-Auszug-aus-Ponytales-3-by-Monika-von-Neuenkirchen.pdf
    • http://cefasfese.4pu.com/2732737739739731/Without-Sin-by-J-Tomas.pdf
    • http://cefasfese.4pu.com/9735730739733732/Verschleppt-Verkauft-Versendet-Ein-Erfahrungsbericht-by-Miriam-Malik.pdf
    • http://cefasfese.4pu.com/9735731730732738/Online-Verkaufskonzepte-So-verkauft-man-heute-by-John-Palameyo.pdf
    • http://cefasfese.4pu.com/9735730738736730/Stieftochter-Jana-Abgerichtet-amp-Verkauft-by-Bianca-Lange.pdf