Malicious PDF — malware analysis report

Static analysis result for SHA-256 4df9ef618f9197e3…

MALICIOUS

PDF

26.0 KB Created: 2019-05-02 06:14:13 +01:00 Authoring application: mPDF 5.7
MD5: df7f4eb2cb2e09e808036a3af0553ac7 SHA-1: 6d21376ed2884c303b025f5619fe6036d44389a0 SHA-256: 4df9ef618f9197e36ca99b9381f761175a305490902f58d894cde7dd0e2ee472
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs, forming a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be SEO poisoning, where the document lures users to a large collection of external PDF files, likely to drive traffic or potentially host malicious content on those linked sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3736735732739730/Foundations-of-Christian-Faith-An-Introduction-to-the-Idea-of-Christianity-by-Karl-Rahner.pdf
    • http://cefasfese.4pu.com/4732733739731730/Christianity-and-Culture-The-Idea-of-a-Christian-Society-and-Notes-Towards-the-Definition-of-Culture-by-T-S-Eliot.pdf
    • http://cefasfese.4pu.com/3736738731734731/Encounters-With-Silence-by-Karl-Rahner.pdf
    • http://cefasfese.4pu.com/6736730739731730/Encyclopedia-of-Theology-The-Concise-Sacramentum-Mundi-by-Karl-Rahner.pdf
    • http://cefasfese.4pu.com/1731731730732734735/Befreiungstheologie-Und-Transzendentaltheologie-Enrique-Dussel-Und-Karl-Rahner-Im-Vergleich-by-Anton-Peter.pdf
    • http://cefasfese.4pu.com/6735730732733/A-New-Christianity-for-a-New-World-Why-Traditional-Faith-is-Dying-How-a-New-Faith-is-Being-Born-by-John-Shelby-Spong.pdf
    • http://cefasfese.4pu.com/1730731738738730/Faith-Has-Its-Reasons-Integrative-Approaches-to-Defending-the-Christian-Faith-by-Kenneth-D-Boa.pdf
    • http://cefasfese.4pu.com/7736739734731735/Foundations-of-Programming---Building-Better-Software-by-Karl-Seguin.pdf
    • http://cefasfese.4pu.com/7730738738732733/The-Christian-Remembrancer-or-Short-Reflections-Upon-the-Faith-Life-and-Conduct-of-a-Real-Christian-by-Ambrose-Serle.pdf
    • http://cefasfese.4pu.com/7730738738737730/The-Christian-Remembrancer-Or-Short-Reflections-Upon-the-Faith-Life-and-Conduct-of-a-Real-Christian-by-Ambrose-Serle.pdf
    • http://cefasfese.4pu.com/5736738738732738/Grundrisse-Foundations-of-the-Critique-of-Political-Economy-by-Karl-Marx.pdf
    • http://cefasfese.4pu.com/1730735735734733734/The-Foundations-of-Christian-Bioethics-by-H-Tristram-Engelhardt-Jr-.pdf
    • http://cefasfese.4pu.com/3736739737738739/Foundations-of-Christian-Education-by-Louis-Berkhof.pdf
    • http://cefasfese.4pu.com/3739735736731731/Sea-of-Faith-Islam-and-Christianity-in-the-Medieval-Mediterranean-World-by-Stephen-O-39-Shea.pdf
    • http://cefasfese.4pu.com/1736737732738736/Divine-Commodity-Discovering-a-Faith-Beyond-Consumer-Christianity-by-Skye-Jethani.pdf
    • http://cefasfese.4pu.com/9738735734734732/An-Introduction-to-the-Thought-of-Karl-Popper-by-Roberta-Corvi.pdf
    • http://cefasfese.4pu.com/1731734731732737733/Introduction-to-the-Theology-of-Karl-Barth-by-Geoffrey-William-Bromiley.pdf
    • http://cefasfese.4pu.com/1731735739732730735/Nietzsche-An-Introduction-to-the-Understanding-of-His-Philosophical-Activity-by-Karl-Jaspers.pdf
    • http://cefasfese.4pu.com/2731735730735730/Christianity-Social-Tolerance-and-Homosexuality-Gay-People-in-Western-Europe-from-the-Beginning-of-the-Christian-Era-to-the-Fourteenth-Century-by-John-Boswell.pdf
    • http://cefasfese.4pu.com/2732730731739/Christianity-Social-Tolerance-and-Homosexuality-Gay-People-in-Western-Europe-from-the-Beginning-of-the-Christian-Era-to-the-Fourteenth-Century-by-John-Boswell.pdf