Malicious PDF — malware analysis report

Static analysis result for SHA-256 1862433712a0fe91…

MALICIOUS

PDF

20.7 KB Created: 2019-09-06 17:29:54 +01:00 Authoring application: mPDF 5.7
MD5: f5a374b22e7a0fef7d7a281d9acad53d SHA-1: e92792d7aa502b2da8592d2389911d9054239b3e SHA-256: 1862433712a0fe91c7db6ba1221f57a232ebb55743fed0e4a13db4914f239ea5
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. While the specific URLs appear benign, the sheer volume and the ML classifier's high confidence indicate a malicious intent. No scripts were extracted, but the PDF structure itself is the primary vector for this attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5732738738734739/Hymnen-f-r-die-Erde-by-Walt-Whitman.pdf
    • http://cefasfese.4pu.com/5732735732733734/Leaves-of-Grass---A-poetry-collection-by-the-American-poet-Walt-Whitman-Annotated-amp-illustrated-Free-Audio-Links-by-Walt-Whitman.pdf
    • http://cefasfese.4pu.com/7737730732734738/Voyages-Poems-by-Walt-Whitman-by-Walt-Whitman.pdf
    • http://cefasfese.4pu.com/2738739739738735/The-Portable-Walt-Whitman-by-Walt-Whitman.pdf
    • http://cefasfese.4pu.com/4739730733732733/Song-of-Myself-by-Walt-Whitman.pdf
    • http://cefasfese.4pu.com/7733733730736731/Leaves-of-Grass-by-Walt-Whitman.pdf
    • http://cefasfese.4pu.com/1730730734732733734/Leaves-of-Grass-by-Walt-Whitman.pdf
    • http://cefasfese.4pu.com/4733736737739736/The-Complete-Poems-by-Walt-Whitman.pdf
    • http://cefasfese.4pu.com/8734734730730737/Leaves-of-Grass-by-Walt-Whitman.pdf
    • http://cefasfese.4pu.com/2732730732731/Walt-Whitman-A-Life-by-Justin-Kaplan.pdf
    • http://cefasfese.4pu.com/1738731731732/Walt-Whitman-The-Measure-of-His-Song-by-Jim-Perlman.pdf
    • http://cefasfese.4pu.com/2731737736737/Walt-Whitman-s-America-by-David-S-Reynolds.pdf
    • http://cefasfese.4pu.com/6739736734730732/Ivory-Apes-and-Peacocks-Joseph-Conrad-Walt-Whitman-Jules-Laforgue-Dostoievsky-and-Tolstoy-Schoenberg-Wedekind-Moussorgsky-Cezanne-Vermeer-Matisse-Van-Gogh-Gauguin-Italian-Futurists-Various-Latter-Day-Poets-Painters-Composers-and-Dramatists-by-James-Huneker.pdf
    • http://cefasfese.4pu.com/1730736732733730735/Hymnen-an-die-Nacht-Heinrich-von-Ofterdingen-by-Novalis.pdf
    • http://cefasfese.4pu.com/5730733733731733/Walt-Disney-s-Santa-s-Toy-Shop-Walt-Disney-Classic-Edition-by-Monique-Peterson.pdf
    • http://cefasfese.4pu.com/3734739736735730/Story-Walt-Disney-Animation-Studios-The-Archive-Series-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/3734739736737732/Design-Walt-Disney-Animation-Studios-The-Archive-Series-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/2733733734732734/Walt-Disney-s-Peter-Pan-Walt-Disney-Classic-Edition-by-Monique-Peterson.pdf
    • http://cefasfese.4pu.com/9732735738732738/The-Troopers-by-S-E-Whitman.pdf
    • http://cefasfese.4pu.com/1730730732739739731/Gesammelte-Werke-Gedichte-Dramen-Historiografische-Werke-M-rchen-Biografie-Vollst-ndige-Ausgaben-Der-romantische-dipus-Rosensohn-Geschichte-Sonette-Oden-Hymnen-by-August-von-Platen.pdf