Malicious PDF — malware analysis report

Static analysis result for SHA-256 33180fd2756a27ec…

MALICIOUS

PDF

18.2 KB Created: 2019-05-03 22:35:41 +01:00 Authoring application: mPDF 5.7
MD5: f3ac8d131ec306a5a44f1ad04445002f SHA-1: e6dd8147e6dd850af91bb722256dee23eb25f656 SHA-256: 33180fd2756a27ec5a144d4ffc8246cae39bc342a428fb315b65412eb7d989df
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links resolve to benign content, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to serve as a distribution point for further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9807

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7736730735/Herding-Cats-Sarah-s-Scribbles-3-by-Sarah-Andersen.pdf
    • http://cefasfese.4pu.com/3733736736734735/Adulthood-Is-a-Myth-A-Sarah-s-Scribbles-Collection-by-Sarah-Andersen.pdf
    • http://cefasfese.4pu.com/8738739738739737/Erwachsen-werd-ich-vielleicht-sp-ter-Die-besten-quot-Sarah-s-Scribbles-quot--Cartoons-by-Sarah-Andersen.pdf
    • http://cefasfese.4pu.com/1735730730733736/Sarah-s-Quilt-A-Novel-of-Sarah-Agnes-Prine-and-the-Arizona-Territories-1906-by-Nancy-E-Turner.pdf
    • http://cefasfese.4pu.com/3737737733737734/Sarah-Plain-and-Tall-Trilogy-Pack-Sarah-Plain-and-Tall-Caleb-s-Story-Skylark-Sarah-Plain-and-Tall-1-3-by-Patricia-MacLachlan.pdf
    • http://cefasfese.4pu.com/1732737738738733/The-Secret-Diary-of-Sarah-Chamberlain-by-Sarah-Norkus.pdf
    • http://cefasfese.4pu.com/1730737737733738739/A-Woman-of-Quality-Sarah-Vinke-quot-The-Divine-Sarah-quot-by-James-Essinger.pdf
    • http://cefasfese.4pu.com/6737731731739/Throne-of-glass-series-sarah-j-maas-6-books-collection-set-by-Sarah-J-Maas.pdf
    • http://cefasfese.4pu.com/4739738738735736/The-View-From-Flyover-Country-Essays-by-Sarah-Kendzior-by-Sarah-Kendzior.pdf
    • http://cefasfese.4pu.com/1731732736737738735/Sarah-Dessen-Books-2017-Checklist-List-of-All-Sarah-Dessen-Books-by-Series-Order.pdf
    • http://cefasfese.4pu.com/1730733733739737733/Kerst-met-Sarah-Morgan-Kerst-vol-verleiding-Samen-in-de-sneeuw-Verrassing-op-kerstavond-by-Sarah-Morgan.pdf
    • http://cefasfese.4pu.com/3731731731731739/Sarah-Leah-Chase-s-Year-Around-Cookbook-by-Sarah-Leah-Chase.pdf
    • http://cefasfese.4pu.com/1731732735739734735/Sarah-Moon-Coincidences-by-Sarah-Moon.pdf
    • http://cefasfese.4pu.com/8736738737733/Sarah-Dessen-Gift-Set-by-Sarah-Dessen.pdf
    • http://cefasfese.4pu.com/8737731737730/Sarah-Moon-12345-by-Sarah-Moon.pdf
    • http://cefasfese.4pu.com/3730736738730/B-by-Sarah-Kay.pdf
    • http://cefasfese.4pu.com/7737733732730733/Contes-d-Andersen-by-Hans-Christian-Andersen.pdf
    • http://cefasfese.4pu.com/4734731731733738/Don-t-Even-Think-About-It-by-Sarah-Mlynowski.pdf
    • http://cefasfese.4pu.com/2737733734737/And-Then-There-Were-N-One-by-Sarah-Pinsker.pdf
    • http://cefasfese.4pu.com/3734738735730736/Unexpected-by-Sarah-G-.pdf
    • http://cefasfese.4pu.com/1730737737733738739/A-Woman-of-Quality-Sarah-Vinke-quot-The-Divine-Sarah-quot-by-James-Es