Malicious PDF — malware analysis report

Static analysis result for SHA-256 776aa1e2c92629e2…

MALICIOUS

PDF

19.1 KB Created: 2019-05-02 04:53:42 +01:00 Authoring application: mPDF 5.7
MD5: 398f0c68baf2c56ce243871958d7a991 SHA-1: e8060ed08efb93acbb3d8f8182c960f3b15a8df2 SHA-256: 776aa1e2c92629e2300df4a05a7af0a49202dfd1952f18e3e5f957199b25aace
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM' heuristic. These links point to external PDF files, suggesting a tactic to drive traffic or distribute further content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9738732738737739/Deutsche-Kulturgeschichte-by-H-W-Kelling.pdf
    • http://cefasfese.4pu.com/1731737736736734731/Kunstler-Im-Klassenkampf-Sonderausstellung-Des-Museums-Fur-Deutsche-Geschichte-April-Bis-Juni-1988-by-Museum-F-Ur-Deutsche-Geschichte.pdf
    • http://cefasfese.4pu.com/1730730734735732736/Plan-F-r-Deutsche-Auswanderung-Und-Ansiedelung-Beziehungsweise-Einer-Reihe-Von-Ansiedelungen-in-Den-Vereinigten-Staaten-Von-Nordamerika-Auf-Ansuchen-Des-W-rttembergischen-Zweigvereins-Des-Nationalvereins-F-r-Deutsche-Auswanderung-Und-Ansiedelung-Zu-by-C-L-Fleischmann.pdf
    • http://cefasfese.4pu.com/1730736736733736734/Die-Kulturgeschichte-des-Weihnachtsessens-by-Claudia-Felsch.pdf
    • http://cefasfese.4pu.com/2739739734734733/Cursed-Blessings-by-Lynn-Kelling.pdf
    • http://cefasfese.4pu.com/3734737731736736/Forgive-Us-Deliver-Us-3-by-Lynn-Kelling.pdf
    • http://cefasfese.4pu.com/9738733730736734/Kulturgeschichte-Des-Alten-Vorderasien-by-Horst-Klengel.pdf
    • http://cefasfese.4pu.com/4739735732733733/Song-of-the-Lonesome-Cowboy-by-Lynn-Kelling.pdf
    • http://cefasfese.4pu.com/2736731739732733/Song-of-the-Lonesome-Cowboy-by-Lynn-Kelling.pdf
    • http://cefasfese.4pu.com/1730736737734739734/Andere-Umstande-Eine-Kulturgeschichte-Der-Geburt-by-Eva-Labouvie.pdf
    • http://cefasfese.4pu.com/9738733732735730/Die-Zeit-Welt-Und-Kulturgeschichte-In-20-B-nden-01-by-Juliane-Schlegel.pdf
    • http://cefasfese.4pu.com/3737730739735731/Threshold---A-Society-of-Masters-Anthology-by-Lynn-Kelling.pdf
    • http://cefasfese.4pu.com/4739731738737739/The-Convivial-Codfish-Kelling-amp-Bittersohn-5-by-Charlotte-MacLeod.pdf
    • http://cefasfese.4pu.com/3734737735733731/Caged-Jaye-Arctic-Absolution-50-by-Lynn-Kelling.pdf
    • http://cefasfese.4pu.com/1734737731735739/The-Palace-Guard-Kelling-amp-Bittersohn-3-by-Charlotte-MacLeod.pdf
    • http://cefasfese.4pu.com/3737738732731735/Blind-Mazes-A-Study-Of-Love-by-George-W-Kelling.pdf
    • http://cefasfese.4pu.com/2733734732733734/Double-Heat-Twin-Ties-3-by-Lynn-Kelling.pdf
    • http://cefasfese.4pu.com/3737735730735735/The-Family-Vault-Kelling-amp-Bittersohn-1-by-Charlotte-MacLeod.pdf
    • http://cefasfese.4pu.com/1731738737731739732/Oldenburg-Kulturgeschichte-Einer-Historischen-Landschaft-by-Siglinde-Killisch.pdf
    • http://cefasfese.4pu.com/9738733733732732/Redebegleitende-Gesten-Kulturgeschichte-Theorie-Sprachvergleich-by-Cornelia-M-ller.pdf