Malicious PDF — malware analysis report

Static analysis result for SHA-256 5a85d572e2a5931c…

MALICIOUS

PDF

20.7 KB Created: 2019-04-30 09:37:08 +01:00 Authoring application: mPDF 5.7
MD5: 9e8bef26ce59737b2967e7da6d6f7826 SHA-1: 5794d965142f91220430023417312f8eedf7f442 SHA-256: 5a85d572e2a5931cd01a1f3d8d9f5d8d71b6aa68da947701d84933aebf78f9fe
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external websites, identified by the PDF_SEO_LINK_FARM heuristic. While the extracted URLs are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9805

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731732733733732731/Kostenlose-XXL-Leseprobe-Das-Geheimnis-der-Karawane-Roman-by-Rolf-Ackermann.pdf
    • http://cefasfese.4pu.com/1731735739730730738/Das-Geheimnis-des-Ketzers-Roman-by-Mattias-Gerwald.pdf
    • http://cefasfese.4pu.com/8739731734731739/XXL-Leseprobe-Unter-dem-Zwillingsstern-Roman-by-Tanja-Kinkel.pdf
    • http://cefasfese.4pu.com/1731735739731730732/Das-Geheimnis-des-Ketzers---Teil-8-Roman-by-Mattias-Gerwald.pdf
    • http://cefasfese.4pu.com/1731732733739730739/XXL-Leseprobe-Der-Tag-an-dem-ich-Papa-im-Auto-verga-Roman-by-Antonia-H-Jacob.pdf
    • http://cefasfese.4pu.com/1730737731739732738/Ein-sinnliches-Geheimnis-Roman-Bastion-Club-7-by-Stephanie-Laurens.pdf
    • http://cefasfese.4pu.com/1730731733730737730/XXL-Leseprobe-Der-Tod-und-andere-H-hepunkte-meines-Lebens-Roman-by-Sebastian-Niedlich.pdf
    • http://cefasfese.4pu.com/1731736735733737733/XXL-Leseprobe-Das-Buch-Haithabu-Der-M-nch-un-die-Wikinger-Roman-by-Claus-Peter-Lieckfeld.pdf
    • http://cefasfese.4pu.com/9734733732731736/Emma---Mit-einem-Dackel-nach-Afrika-Roman-by-Rolf-St-ver.pdf
    • http://cefasfese.4pu.com/1731732733732734734/Karawane-in-Gefahr-by-A-R-Channel.pdf
    • http://cefasfese.4pu.com/1730736732737739736/Rolf-Torring---Neue-Abenteuer-03-Professor-Dark-Sammelband-mit-den-Rolf-Torring-Romanen-452-454-by-Hans-Holm.pdf
    • http://cefasfese.4pu.com/1735739732735730/Batting-Cage-by-Joan-Ackermann.pdf
    • http://cefasfese.4pu.com/9737737738738736/Einer-Flog-Uber-Das-Kuckucksnest-Inszenierungen-Des-Regisseurs-Rolf-Winkelgrund-by-Rolf-Winkelgrund.pdf
    • http://cefasfese.4pu.com/1731732733733731730/Hugo-Balls-Karawane-als-Unterrichtsgegenstand-by-Bettina-Einhellig.pdf
    • http://cefasfese.4pu.com/8739735732732732/Rolf-on-Art-by-Rolf-Harris.pdf
    • http://cefasfese.4pu.com/1731736732739732736/Eine-Liebe-in-Mexiko-Un-amore-en-Mexiko-by-Hans-Peter-Ackermann.pdf
    • http://cefasfese.4pu.com/9734739736733731/Das-Steinerne-Tor-Die-R-ckkehr-Leseprobe-by-Pia-Guttenson.pdf
    • http://cefasfese.4pu.com/1731731732731737732/Man-ver-um-Feuerland-Historischer-Roman-Ein-Jack-Aubrey-Roman-10-by-Patrick-O-39-Brian.pdf
    • http://cefasfese.4pu.com/1731735738736738736/Jack-Deveraux-Der-D-monenj-ger---Zweiter-Roman-Nachtalb-Roman-by-Xenia-Jungwirth.pdf
    • http://cefasfese.4pu.com/1731735738737732732/Jack-Deveraux-Der-D-monenj-ger---Sechster-Roman-D-monend-mmerung-Roman-by-Xenia-Jungwirth.pdf