Malicious PDF — malware analysis report

Static analysis result for SHA-256 786290adad55550a…

MALICIOUS

PDF

18.7 KB Created: 2019-05-03 05:58:52 +01:00 Authoring application: mPDF 5.7
MD5: 55dd82888366c8c49772dcd7703ad442 SHA-1: 36e7db6c68ba07ff352bb827d3c435f315601aae SHA-256: 786290adad55550aa5c358f108f287d8b1401398e7ea69bf6333718f158ea790
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm. The ML classifier also flagged the document as malicious. The primary attack pattern involves directing users to a high volume of external PDF documents, likely for SEO manipulation or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9739733731730732/Was-hast-DU-zu-verlieren-by-John-Valcone.pdf
    • http://cefasfese.4pu.com/1731737737733733732/7-M-glichkeiten-7-Pfund-in-14-Tagen-zu-verlieren-7-Pfund-in-14-Tagen-verlieren-by-Dominik-Hauke.pdf
    • http://cefasfese.4pu.com/9739733730731733/Exploring-the-World-of-Music-CD-Set-by-Efc-Hast-.pdf
    • http://cefasfese.4pu.com/9739732739734738/Bryllup-i-all-hast-by-Cathy-Maxwell.pdf
    • http://cefasfese.4pu.com/9739733731730733/What-Hast-Thou-to-Say-by-Bruce-T-Hudson.pdf
    • http://cefasfese.4pu.com/9736739737739738/In-den-Schuhen-die-Du-mir-geschenkt-hast-by-Cara-Roth.pdf
    • http://cefasfese.4pu.com/9739732738737737/Infant-and-Toddler-Experiences-by-Fran-Hast.pdf
    • http://cefasfese.4pu.com/9739733731730735/Welche-Gedanken-hast-du-by-Rosa-Hackl.pdf
    • http://cefasfese.4pu.com/1731737737733738730/Mit-Nebenjobs-im-Internet-Geld-verlieren-by-Rainer-Innreiter.pdf
    • http://cefasfese.4pu.com/1731737737732734734/Jugendliche-verlieren-Gewicht-F-hrer-by-Yseult-Ebersbach.pdf
    • http://cefasfese.4pu.com/9739732738737734/The-Potter-and-the-Clay-Why-Hast-Thou-Made-Me-Thus-by-Reed-Moss.pdf
    • http://cefasfese.4pu.com/2732731736731732/That-Leviathan-Whom-Thou-Hast-Made-by-Eric-James-Stone.pdf
    • http://cefasfese.4pu.com/9730730731736733/Den-Frieden-verlieren-Star-Trek-The-Next-Generation-6-by-William-Leisner.pdf
    • http://cefasfese.4pu.com/1731737737733738737/Verlieren-um-zu-gewinnen-Schlussstrich-eines-SPIELS-CHTIGEN-by-Sebastian-Gerhardt.pdf
    • http://cefasfese.4pu.com/9739732738730731/SLEEP---Ich-wei-was-du-letzte-Nacht-getr-umt-hast-by-Lisa-McMann.pdf
    • http://cefasfese.4pu.com/1731737737733733734/Nichts-Zu-Verlieren-A-Wie-Alibi-Zwei-Romane-In-Einem-Band-by-Sue-Grafton.pdf
    • http://cefasfese.4pu.com/1731737737733738738/Schicksalhafter-Gewinn-Wer-wagt-kann-viel-verlieren-by-Ercan-Aydin.pdf
    • http://cefasfese.4pu.com/1731737737733739732/Stark-sein-in-Beziehungskrisen-wie-man-Partnerprobleme-l-st-ohne-zu-verlieren-by-Peter-Lauster.pdf
    • http://cefasfese.4pu.com/9736739730734736/Haydn-muss-den-Kopf-verlieren-Intrigen-und-Verwirrungen-in-Metternichs-sterreich-by-Philipp-Tenta.pdf
    • http://cefasfese.4pu.com/9736739738737739/F-r-immer-an-deiner-Seite-ergreifender-Roman-um-die-Sehnsucht-im-Fr-hling-Du-hast-mir-das-Gl-ck-geschenkt-by-Daniela-Buchholz.pdf