Malicious PDF — malware analysis report

Static analysis result for SHA-256 5496ed28b6e469c3…

MALICIOUS

PDF

16.3 KB Created: 2019-05-06 16:53:41 +01:00 Authoring application: mPDF 5.7
MD5: 4e28f585811203d75b79652839aa76e7 SHA-1: 2f471fd95722c1c001eb40724ea44a7aa6b8dffe SHA-256: 5496ed28b6e469c39b958e99d10b12b9765e2800572abea6b8de15925da612bf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links, forming a link farm. The primary heuristic indicates this is a 'PDF_SEO_LINK_FARM' attack pattern, designed to drive traffic to external sites. While the document body is unreadable, the structure and the numerous URLs strongly suggest a malicious intent to redirect users. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a08a07a08a09a08/-quot-Nackt-Sexbilder-Xxx-Nackt-Bilder-F-r-Sie-by-Ester-Haas.pdf
    • http://muicuiu.dumb1.com/9a02a00a08a01a00/-quot-Lesbische-Junge-Erwachsenen-Sexbilder-Erotische-Bilder-Von-Nackten-M-dchen-Unzensiert-by-Ralf-Moser.pdf
    • http://muicuiu.dumb1.com/9a08a08a00a04a05/Niedlich-und-nackt-by-Red-Digital.pdf
    • http://muicuiu.dumb1.com/9a08a07a09a06a02/Nackt-Duschen-by-M-C-Hanlon.pdf
    • http://muicuiu.dumb1.com/9a08a08a01a04a04/Nackt-im-Park-by-Red-Digital.pdf
    • http://muicuiu.dumb1.com/9a08a08a01a04a06/Nackt-jung-und-verheiratet-by-Models18.pdf
    • http://muicuiu.dumb1.com/9a08a07a09a06a04/Nackt-amp-Ausgeliefert-by-Anita-Rosenbach.pdf
    • http://muicuiu.dumb1.com/9a08a08a00a05a00/NACKT-PERFEKTE-M-DCHEN-13-by-Key-Nudo.pdf
    • http://muicuiu.dumb1.com/1a00a04a09a03a00a00/Wundersch-n-nackt-und-verspielt-by-SunImage21.pdf
    • http://muicuiu.dumb1.com/9a08a08a01a08a02/NACKT-PERFEKTE-M-DCHEN-4-by-Key-Nudo.pdf
    • http://muicuiu.dumb1.com/9a08a08a00a05a03/NACKT-PERFEKTE-M-DCHEN-3-by-Key-Nudo.pdf
    • http://muicuiu.dumb1.com/9a08a08a01a03a04/Male-mich-nackt-by-Alun.pdf
    • http://muicuiu.dumb1.com/9a08a07a09a05a09/Nackt-in-Turnschuhen-by-Tommi-Horwath.pdf
    • http://muicuiu.dumb1.com/9a02a00a07a04a03/Die-besten-Bilder-von-nackten-M-dchen-3-200-sexbilder-by-Tomas-Butter.pdf
    • http://muicuiu.dumb1.com/9a08a08a00a05a02/Nackt-und-Schamlos-Sexgeschichten-by-Hans-Albers.pdf
    • http://muicuiu.dumb1.com/9a08a07a09a06a08/Ganz-nackt-Erotische-Storys-by-Luna.pdf
    • http://muicuiu.dumb1.com/9a08a08a00a04a07/Amanda-nackt-in-ihrem-Schlafzimmer-by-Red-Digital.pdf
    • http://muicuiu.dumb1.com/9a08a08a00a04a08/Molly-nackt-in-ihrem-Bett-by-RedSkye-Digital.pdf
    • http://muicuiu.dumb1.com/9a08a07a09a07a02/Nackt-Am-Grillein-Mann-Geht-An-Seine-Grenzen-by-Titus-Arnu.pdf
    • http://muicuiu.dumb1.com/8a08a06a07a04a08/Flotter-Dreier-Erwachsener-Bilderbuch-Nackt-Und-Unzensierte-X-Bewertet-Girls-by-Claudia-Aigner.pdf