Malicious PDF — malware analysis report

Static analysis result for SHA-256 3544587843ca96ac…

MALICIOUS

PDF

17.2 KB Created: 2019-05-03 17:12:14 +01:00 Authoring application: mPDF 5.7
MD5: f99890ed9e3c458378abe60c8f0b9258 SHA-1: 22c0bcc19bca1aa25a0145424bbf9d669a1b84dd SHA-256: 3544587843ca96acc8b7d68011d485f4284449a6c3d2d12ec9c3f7dbbbac740b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious File

The PDF contains a large number of embedded URLs, identified as a link farm. While the specific URLs extracted were benign, the heuristic 'PDF_SEO_LINK_FARM' indicates a pattern of hosting numerous external links. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be the distribution of a large number of links, potentially for SEO manipulation or to lead users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1735734731733739/The-Orphan-Conspiracies-29-Conspiracy-Theories-from-The-Orphan-Trilogy-by-James-Morcan.pdf
    • http://cefasfese.4pu.com/2732730731736732/Behind-Closed-Doors-Behind-Closed-Doors-1-Inside-Out-0-1-by-Lisa-Renee-Jones.pdf
    • http://cefasfese.4pu.com/3739733736739738/The-Orphan-Queen-The-Orphan-Queen-1-by-Jodi-Meadows.pdf
    • http://cefasfese.4pu.com/6738737730739/Little-Orphan-Anvil-Little-Orphan-Anvil-1-by-Joseph-Beekman.pdf
    • http://cefasfese.4pu.com/1737739737736737/The-French-Orphan-The-French-Orphan-1-by-Michael-Stolle.pdf
    • http://cefasfese.4pu.com/8736735734733/The-House-of-Doors-House-of-Doors-1-by-Brian-Lumley.pdf
    • http://cefasfese.4pu.com/1730733735735730732/Durst-by-B-E-Seidl.pdf
    • http://cefasfese.4pu.com/1730733735735738737/Stitched-Together-by-Laraine-Seidl.pdf
    • http://cefasfese.4pu.com/1730733735735730738/Learn-to-Fly-by-Ramona-Seidl.pdf
    • http://cefasfese.4pu.com/9735735737733736/The-House-of-Closed-Doors-The-House-of-Closed-Doors-1-by-Jane-Steen.pdf
    • http://cefasfese.4pu.com/1730733735734739738/Fun-and-Games-for-Cats-by-Denise-Seidl.pdf
    • http://cefasfese.4pu.com/1730739734737732737/Unglaubliche-Scheidungsgeschichten-by-Dr-Helmut-Seidl.pdf
    • http://cefasfese.4pu.com/1730733735735731730/Grammar-One-One-Pupil-s-Book-by-Jennifer-Seidl.pdf
    • http://cefasfese.4pu.com/1730733735735739733/Drawing-and-Painting-on-the-iPad-by-Diana-Seidl.pdf
    • http://cefasfese.4pu.com/1730733735734733735/Ulrich-Seidl-In-the-Basement-by-Claus-Philipp.pdf
    • http://cefasfese.4pu.com/1730734737736739735/Radiogeschichten-1-Der-kleine-Angsthase-Liebezeit-by-Josef-Seidl.pdf
    • http://cefasfese.4pu.com/1730732737739732737/Gedichte-in-Nieder-sterreichischer-Mundart-by-Johann-Gabriel-Seidl.pdf
    • http://cefasfese.4pu.com/1735734731738732/Sky-City-The-Rise-of-an-Orphan-Sky-City-The-Rise-of-an-Orphan-1-6-by-R-D-Hale.pdf
    • http://cefasfese.4pu.com/1730733735735738735/Od-al-e-k-olt-i-Emancipace-homosexuality-v-esk-ch-zem-ch-od-roku-1867-do-sou-asnosti-by-Jan-Seidl.pdf
    • http://cefasfese.4pu.com/1731730732732736733/Verfall-oder-Wandel-Sprachkritik-als-Thema-des-ffentlichen-Diskurses-in-Japan-by-Bernhard-Seidl.pdf