Malicious PDF — malware analysis report

Static analysis result for SHA-256 28addce1089564ea…

MALICIOUS

PDF

21.3 KB Created: 2019-05-02 05:31:43 +01:00 Authoring application: mPDF 5.7 First seen: 2021-06-28
MD5: 7405449f14c3415bef41722acb332e2d SHA-1: 7a234a752ca2d20610003c53d86e6a9b14200d77 SHA-256: 28addce1089564eadfd182205ad1fc46419e0565ab4c90a9011b118e0dbcbce5
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which suggests a malicious intent to manipulate search engine results or redirect users to potentially harmful content. While no scripts were extracted, the presence of numerous external links points towards a phishing or SEO-based attack. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9796

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6736730736730/Disney-s-DuckTales-The-Hunt-for-the-Giant-Pearl-A-Little-Golden-Book-by-Walt-Disney-Company.pdf In PDF document text
    • http://cefasfese.4pu.com/4737732730738730/Big-Hero-6-Big-Golden-Book-Disney-Big-Hero-6-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/4730739734739737/Finding-Dory-Little-Golden-Book-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/3734739736735730/Story-Walt-Disney-Animation-Studios-The-Archive-Series-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/3734739736737732/Design-Walt-Disney-Animation-Studios-The-Archive-Series-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/2735734739733739/The-Haunted-House-Disney-s-Wonderful-World-of-Reading-33-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/2731735733730732/The-Emperor-s-New-Clothes-Disney-s-wonderful-world-of-reading-29-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/1730736738732730734/Gulliver-Mickey-Disney-s-Wonderful-World-of-Reading-27-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/8736736731734731/Peter-Pan-Disney-Classics-Collection-Storybook-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/4737730731732731/Let-Your-Heart-Be-Your-Guide-Stories-About-Happiness-Disney-s-Family-Storybook-Library-11-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/5730733731734735/Walt-Disney-s-Christmas-Parade-2-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/4736731734730733/Mickey-and-the-Roadster-Racers-Race-for-the-Rigatoni-Ribbon-Disney-Storybook-eBook-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/3731731735731730/Cooking-with-Mickey-Around-our-World-The-Most-Requested-Recipes-from-Walt-Disney-World-and-Disneyland-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/3730732732738730/The-Little-Mermaid-Disney-Princess-2-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/6736738735732731/Cendrillon---Disney-Cin-ma-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/3734739736735733/Animation-Walt-Disney-Animation-Studios-The-Archive-Series-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/4730732736732737/Walt-Disney-s-America-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/8738733735733/The-Jungle-Book-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/9733731732735734/Frozen-Olaf-Book-and-Plush-by-Walt-Disney-Company.pdfIn PDF document text
    • http://cefasfese.4pu.com/7731731738736/Walt-Disney-s-The-Sorcerer-s-Apprentice-A-Little-Golden-Book-by-Don-Ferguson.pdfIn PDF document text