Malicious PDF — malware analysis report

Static analysis result for SHA-256 62522c3c9d81b151…

MALICIOUS

PDF

18.7 KB Created: 2019-05-02 06:49:05 +01:00 Authoring application: mPDF 5.7
MD5: a3bb32608e3a53fd4b652909b4387b18 SHA-1: 2eeb924313e2bf11a527aaad32dec4c867b569ab SHA-256: 62522c3c9d81b151ce19a3cb9ea1068548cb120770a39f3a55240f30b2f62e56
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links, identified as a link farm, likely for SEO manipulation or to distribute further malicious content. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest a malicious intent to redirect users to potentially harmful sites. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731733738731733739/The-Life-Of-Vasilii-Kandinsky-In-Russian-Art-A-Study-Of-quot-On-The-Spiritual-In-Art-quot-by-Wassily-Kandinsky.pdf
    • http://cefasfese.4pu.com/8731732739732/Concerning-the-Spiritual-in-Art-by-Wassily-Kandinsky.pdf
    • http://cefasfese.4pu.com/1731733738733735735/Kandinsky-Album-de-l-exposition-grande-galerie-1er-novembre-1984-28-janvier-1985-by-Wassily-Kandinsky.pdf
    • http://cefasfese.4pu.com/1731733738733735737/Homage-To-Kandinsky-Special-Issue-Of-The-X-Xe-Si-cle-by-Wassily-Kandinsky.pdf
    • http://cefasfese.4pu.com/1731733738731733735/Wassily-Kandinsky-Ronbunsyu-by-Wassily-Kandinsky.pdf
    • http://cefasfese.4pu.com/1731733738732733733/Kandinsky-in-Munich-1896-1914-by-Wassily-Kandinsky.pdf
    • http://cefasfese.4pu.com/1731733738732735730/Kandinsky-The-Munich-Years-1900-14-by-Wassily-Kandinsky.pdf
    • http://cefasfese.4pu.com/1731733738732730735/Kandinsky-at-the-Guggenheim-Museum-by-Wassily-Kandinsky.pdf
    • http://cefasfese.4pu.com/1731733738732730732/Watercolors-by-Kandinsky-at-the-Guggenheim-Museum-A-Selection-from-the-Solomon-R-Guggenheim-Museum-and-the-Hilla-Von-Rebay-Foundation-by-Wassily-Kandinsky.pdf
    • http://cefasfese.4pu.com/1731733738730738735/Wassily-Kandinsky-by-Wassily-Kandinsky.pdf
    • http://cefasfese.4pu.com/1731733738730738739/Wassily-Kandinsky-by-Cornelius-Doelman.pdf
    • http://cefasfese.4pu.com/1731733738732734731/Mnogogrannyi-Mir-Kandinskogo-by-Wassily-Kandinsky.pdf
    • http://cefasfese.4pu.com/1731733738730739738/Art-Masterclass-with-Wassily-Kandinsky-by-Hanna-Konola.pdf
    • http://cefasfese.4pu.com/5739738736738739/-ber-Das-Geistige-In-Der-Kunst-by-Wassily-Kandinsky.pdf
    • http://cefasfese.4pu.com/1731733738731739737/Wassily-Kandinsky-198-Master-Drawings-by-Blagoy-Kiroff.pdf
    • http://cefasfese.4pu.com/1731733738731739736/Wassily-Kandinsky-Paintings-That-Changed-the-World-by-Stanley-Cesar.pdf
    • http://cefasfese.4pu.com/1731733738733736733/Wassily-Kandinsky-Briefe-an-Will-Grohmann-1923-1943-by-Barbara-Worwag.pdf
    • http://cefasfese.4pu.com/1731733738732733735/Wassily-Kandinsky-and-Gabiele-Munter-Letters-and-Reminiscences-1902-1914-by-Annegret-Hoberg.pdf
    • http://cefasfese.4pu.com/9732732737736/The-World-Peace-Diet-Eating-for-Spiritual-Health-and-Social-Harmony-by-Will-Tuttle.pdf
    • http://cefasfese.4pu.com/4731732734731731/The-Harmony-Series-Boxset-Harmony-1-3-by-Angela-Graham.pdf