Malicious PDF — malware analysis report

Static analysis result for SHA-256 4cde9359438d22d6…

MALICIOUS

PDF

16.2 KB Created: 2019-05-04 10:37:43 +01:00 Authoring application: mPDF 5.7
MD5: 2029b2264a28a67c2d62d03c010521ea SHA-1: b41fb6a6476d5a3d7c42a24cb8f3c616417390c0 SHA-256: 4cde9359438d22d63449cd2d4f1d92c56bc12109d23b776e698c0d15acf0b225
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links. The primary heuristic indicates a 'PDF_SEO_LINK_FARM', suggesting the document's purpose is to redirect users to numerous URLs. While no scripts were extracted, the sheer volume of links points to a potential SEO manipulation or a distribution point for further malicious content. The document body itself is heavily obfuscated and unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731730733739735738/T-dliche-Hilfe-Bericht-Von-Meiner-Letzten-Dienstreise-In-Sachen-Entwicklungshilfe-by-Brigitte-Erler.pdf
    • http://cefasfese.4pu.com/3731731731734738/Mastering-Pasta-The-Art-and-Practice-of-Handmade-Pasta-Gnocchi-and-Risotto-by-Marc-Vetri.pdf
    • http://cefasfese.4pu.com/1731736738732731733/Die-Brille-des-Teufels-by-Till-Rien-cker.pdf
    • http://cefasfese.4pu.com/1731736738732730735/DIE-BRILLE-IM-FILM-by-Sabine-Walter.pdf
    • http://cefasfese.4pu.com/4736730737730730/Ali-and-Nino-by-Kurban-Said.pdf
    • http://cefasfese.4pu.com/1731736738735733737/Blood-Lad-06-Wut-Brille-Zack-by-Yuuki-Kodama.pdf
    • http://cefasfese.4pu.com/1734731738737731/Testament-by-Nino-Ricci.pdf
    • http://cefasfese.4pu.com/1731736738731739736/Carlotta-Eine-Brille-will-ich-nicht-by-Annette-Langen.pdf
    • http://cefasfese.4pu.com/1731736738732730733/Eine-Brille-Fur-Ille-by-Rosemarie-Kunzler-Behncke.pdf
    • http://cefasfese.4pu.com/1731736739733738739/18-Stunden-by-Daniela-M-ller.pdf
    • http://cefasfese.4pu.com/3739730733731/The-Dog-That-Nino-Didn-t-Have-by-Edward-van-de-Vendel.pdf
    • http://cefasfese.4pu.com/1731737733737739732/El-Ni-o---Bitters-e-Lust-by-Lea-Petersen.pdf
    • http://cefasfese.4pu.com/1731736738735734736/L-ve-Toi-Et-Brille-Cr-dans-la-Gloire-by-Gregory-Toussaint.pdf
    • http://cefasfese.4pu.com/9734737730735732/Friday-Evening-Eight-O-Clock-by-Nino-Gugunishvili.pdf
    • http://cefasfese.4pu.com/1730732731735736739/Montezuma-airbag-your-pardon-by-Nino-G-D-39-Attis.pdf
    • http://cefasfese.4pu.com/1731731730733731/Mother-El-Nino-amp-La-Nina-by-Jali-Kenoi.pdf
    • http://cefasfese.4pu.com/1731737733739730733/Bitters-e-Stunden-der-Liebe-by-Susan-Mallery.pdf
    • http://cefasfese.4pu.com/1730735739731735736/Der-endlose-Tag-In-24-Stunden-um-die-Welt-by-Charles-Fr-lich.pdf
    • http://cefasfese.4pu.com/1731736735735731737/Spieler-Eins-Roman-in-5-Stunden-by-Douglas-Coupland.pdf
    • http://cefasfese.4pu.com/1730733735734739735/Zwei-Stunden-Vom-Traum-den-Marathon-zu-laufen-by-Ed-Caesar.pdf
    • http://cefasfese.4pu.com/1731736738731739736/Carlotta-Eine-Brille-will-ich-nicht-by-Annett