Malicious PDF — malware analysis report

Static analysis result for SHA-256 720564dc13fd6dcc…

MALICIOUS

PDF

22.6 KB Created: 2020-03-18 21:57:45 +00:00 Authoring application: mPDF 5.7
MD5: 3d498c8d4c0660ce46b539f6d12fb29e SHA-1: f5688b9cc224d29d93bbc93366b34e13dcb2522b SHA-256: 720564dc13fd6dcc616d1c0f74da5c479a421431b588b8237b1e62d3ecc30e61
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The critical PDF_SEO_LINK_FARM heuristic indicates the presence of a large number of external links within the PDF, pointing to a link farm strategy. The ML classifier also flagged the PDF as malicious with high confidence. The document body contains numerous URLs, reinforcing the link farm finding and suggesting a potential distribution mechanism for further malicious content or SEO manipulation. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ujcsiniio.myhome.cx/9cd9cd0cd3cd8cd1/Geburtstagsansprachen-der-besonderen-Art-in-einem-besonderen-Freundeskreis-by-David-Friedrich-Braun.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd0cd2cd2cd5cd8/Erinnerungen-an-Die-Schlacht-Bei-Wimpfen-Und-Den-Tod-Der-Vierhundert-Pforzheimer-Enthaltend-Die-Geschichte-Der-Schlacht-Von-Ernst-M-nch-Und-Die-Ged-chtni-rede-Auf-Die-Gefallenen-Von-Ernst-Ludwig-Posselt-by-Ernst-Munch.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd9cd4cd6cd7cd8/Eine-Jugend-in-Deutschland-Autobiographie-eines-Revolution-rs---Vollst-ndige-Ausgabe-Der-Weg-Ernst-Tollers-vom-deutschen-B-rgerlichen-zum-revolution-ren-Sozialisten-by-Ernst-Toller.pdf
    • http://ujcsiniio.myhome.cx/6cd7cd6cd1cd8cd2/Experimentelle-Untersuchungen-Zur-Nahrstoffabhangigkeit-Des-Schilfrohrs-Phragmites-Australis-Cav-Trin-Ex-Steud-Implikationen-Fur-Rohricht-Sani-by-Priska-Krumscheid-Plankert.pdf
    • http://ujcsiniio.myhome.cx/9cd9cd0cd3cd9cd3/Nachbarschaftshilfen-der-besonderen-Art-by-Didier-Ome.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd2cd2cd1cd2cd4/Ernst-Ulrich-Von-Weizsacker-A-Pioneer-on-Environmental-Climate-and-Energy-Policies-by-Ernst-Ulrich-Weizsacker.pdf
    • http://ujcsiniio.myhome.cx/9cd9cd0cd3cd8cd6/ZBV---Band-1-Zur-besonderen-Verwendung-by-K-H-Scheer.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd2cd1cd8cd5cd0/Memoirs-of-Ernst-von-Weizsacker-by-Ernst-Ulrich-von-Weizsacker.pdf
    • http://ujcsiniio.myhome.cx/9cd9cd0cd6cd1cd0/Benutzt-f-r-den-besonderen-Service-BDSM-by-Lolita-Domingo.pdf
    • http://ujcsiniio.myhome.cx/9cd9cd0cd4cd9cd0/Robby-Schule-der-besonderen-Kinder-by-Christina-Manz.pdf
    • http://ujcsiniio.myhome.cx/9cd9cd0cd7cd4cd7/Sie-suchte-den-besonderen-Kick-BDSM-by-Lola-Hammerfeld.pdf
    • http://ujcsiniio.myhome.cx/9cd9cd0cd8cd3cd3/Inklusion-II-Der-Umgang-mit-besonderen-Merkmalen-by-Matthias-Von-Saldern.pdf
    • http://ujcsiniio.myhome.cx/9cd9cd0cd4cd9cd3/Rhetorik-sich-in-besonderen-Situationen-pr-sentieren-by-Michael-Henrich.pdf
    • http://ujcsiniio.myhome.cx/9cd9cd0cd3cd8cd7/Grabr-uber-gesucht-Keine-besonderen-Kenntnisse-erforderlich-by-Jeff-Strand.pdf
    • http://ujcsiniio.myhome.cx/9cd9cd0cd6cd0cd3/Liebe-Lilly-Briefe-an-einen-ganz-besonderen-Hund-by-Iris-Elsner.pdf
    • http://ujcsiniio.myhome.cx/9cd9cd0cd8cd4cd2/Story-Telling---Warum-Geschichten-einen-ganz-besonderen-Reiz-aus-ben-by-Klaus-Martach.pdf
    • http://ujcsiniio.myhome.cx/2cd8cd2cd9cd2cd6/Better-Off-Without-Him-by-Dee-Ernst.pdf
    • http://ujcsiniio.myhome.cx/3cd3cd3cd8cd5cd9/Better-Off-Without-Him-by-Dee-Ernst.pdf
    • http://ujcsiniio.myhome.cx/1cd9cd3cd8cd3cd3/What-Evolution-Is-by-Ernst-W-Mayr.pdf
    • http://ujcsiniio.myhome.cx/6cd2cd7cd8cd2cd7/The-Outlaws-by-Ernst-von-Salomon.pdf