Malicious PDF — malware analysis report

Static analysis result for SHA-256 38471a9ef229ca24…

MALICIOUS

PDF

17.2 KB Created: 2019-05-02 05:02:10 +01:00 Authoring application: mPDF 5.7
MD5: 186718deb8742c6df0252d009e9821a1 SHA-1: a3912e08c05ed16947e1b371c5aed404cb4a911c SHA-256: 38471a9ef229ca24718bc15abb167cba37d1646d13ac07c1b266548367811cdb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a machine learning classifier and contains a large number of external links, indicating a link farm. The primary heuristic identified a "PDF_SEO_LINK_FARM" with 23 external links, many of which are structured with numeric slugs. While the extracted URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent to distribute traffic or potentially host malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9734732734738738/Kaninchen-Kecky-das-Kaninchenkind-Spannendes-Kaninchen-Abenteuer-f-r-Kinder-ab-5-Jahre-German-Edition-by-Hannah-Jennings.pdf
    • http://cefasfese.4pu.com/7731731731734736/Joana-Vasconcelos-I-m-Your-Mirror-by-Joana-Vasconcelos.pdf
    • http://cefasfese.4pu.com/6732738738737730/Bloody-Apparitions-by-Miranda-Doerfler.pdf
    • http://cefasfese.4pu.com/1730738738737735739/Die-Bedeutung-des-Verlustes-der-Wohnung-f-r-Frauen-die-in-einem-Frauenhaus-Schutz-suchen-by-Iris-Annabell-Maclean.pdf
    • http://cefasfese.4pu.com/8738733738734736/Die-Teufelsfrucht-by-Joana-Brouwer.pdf
    • http://cefasfese.4pu.com/1730732738732735/The-Second-Chance-by-Joana-Starnes.pdf
    • http://cefasfese.4pu.com/9734732734737737/Benny-Blu---Kaninchen-und-Hasen-by-Nicola-Herbst.pdf
    • http://cefasfese.4pu.com/9734732734738731/Das-gro-e-Buch-vom-Kaninchen-by-Klaus-Lange.pdf
    • http://cefasfese.4pu.com/1730737731730738733/Esel-halten-by-Marisa-Hafner.pdf
    • http://cefasfese.4pu.com/4732732730737730/Trusting-God-with-your-Future-by-Joana-James.pdf
    • http://cefasfese.4pu.com/9734732735737736/Akupunktur-und-Phytotherapie-bei-Kaninchen-und-Meerschweinchen-by-Carola-Krokowski.pdf
    • http://cefasfese.4pu.com/9734732734737739/Gefl-gel-und-Kaninchen-selbst-schlachten-by-Wilhelm-Bauer.pdf
    • http://cefasfese.4pu.com/1731735739736731733/Ordnung-halten-f-r-Dummies-by-Eileen-Roth.pdf
    • http://cefasfese.4pu.com/8735739734733734/Jardi-Vivent-by-Joana-Raspall-I-Juanola.pdf
    • http://cefasfese.4pu.com/1730731733733738/Mr-Bennet-s-Dutiful-Daughter-by-Joana-Starnes.pdf
    • http://cefasfese.4pu.com/9734732735738734/Salat-muss-durchs-Kaninchen-AMELIE-14-by-Silke-Porath.pdf
    • http://cefasfese.4pu.com/1731735739736737734/Eurasier-halten-aber-vern-nftig-by-Michael-Moos.pdf
    • http://cefasfese.4pu.com/1731735739736737730/Beagle-halten-aber-vern-nftig-by-Michael-Moos.pdf
    • http://cefasfese.4pu.com/9734732736733734/Kinderbuch-Erstaunliche-Fakten-amp-Bilder-ber-Kaninchen-by-Sandra-Klaus.pdf
    • http://cefasfese.4pu.com/4732732738730739/Alana-amp-Alyssa-s-Secret-Rise-from-the-Ashes-by-Joana-James.pdf
    • http://cefasfese.4pu.com/1730732738732735/The-Second-Chan