Malicious PDF — malware analysis report

Static analysis result for SHA-256 7f23df84e1213131…

MALICIOUS

PDF

22.2 KB Created: 2019-05-02 07:49:38 +01:00 Authoring application: mPDF 5.7
MD5: 042055209b828b43e33b0639a8a23c98 SHA-1: 061acc59c11a176ceb237449e18aa47ad8b38f1f SHA-256: 7f23df84e1213131f3e5d62cfd9431908fd02150e8c66d206f3b283ab37912a8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious. While the document body is unreadable, the presence of a link farm suggests a tactic to distribute malicious content or redirect users to phishing sites. The primary IOCs are the URLs forming the link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9437

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9738730739736739/Traumberuf-T-nzer-Ausbildung-Einstieg-Praxis-by-Wibke-Hartewig.pdf
    • http://cefasfese.4pu.com/9736730730731738/Aktivierende-Soziale-Arbeit-mit-nicht-motivierten-Klienten-Mit-Arbeitshilfen-f-r-Ausbildung-und-Praxis-by-Gerd-Gehrmann.pdf
    • http://cefasfese.4pu.com/9734733734733736/Bibliothekarische-Ausbildung-in-Theorie-Und-Praxis-Beitrage-Zum-25jahrigen-Bestehen-Des-Bibliothekar-Lehrinstituts-Des-Landes-Nordrhein-Westfalen-Am-by-Rudolf-Jung.pdf
    • http://cefasfese.4pu.com/1731733730732733730/Der-Schl-ssel-zum-Erfolg-LR---Aus-der-Praxis-f-r-die-Praxis-by-Berthold-G-ntner.pdf
    • http://cefasfese.4pu.com/9738731731735738/Therapy-of-Viral-Infections-by-Wibke-E-Diederich.pdf
    • http://cefasfese.4pu.com/9738730739737735/Frauen-Liebe-Frauenliebe-by-Wibke-Flohr.pdf
    • http://cefasfese.4pu.com/1730732734731735738/Ausbildung-zur-Hure-by-Viola-Kinlay.pdf
    • http://cefasfese.4pu.com/2736734739737736/My-Father-s-Country-Story-of-a-German-Family-by-Wibke-Bruhns.pdf
    • http://cefasfese.4pu.com/9738731730734731/Emanzipationsversuche-Der-Frauenfiguren-in-Odon-Von-Horvaths-Werken-by-Wibke-Oppermann.pdf
    • http://cefasfese.4pu.com/9733739737739738/Lightroom-5-Der-Einstieg-f-r-Fotografen-by-Michael-Gradias.pdf
    • http://cefasfese.4pu.com/9738730739736735/Demokratie-Und-Verein-Potenziale-Demokratischer-Bildung-in-Der-Jugendarbeit-by-Wibke-Riekmann.pdf
    • http://cefasfese.4pu.com/1731731730736731735/Malen-mit-Acrylfarben-Leichter-Einstieg-by-J-rg-Langhans.pdf
    • http://cefasfese.4pu.com/8736731738734733/Neuland-Einstieg-in-Einen-Politikwechsel-by-Guido-Westerwelle.pdf
    • http://cefasfese.4pu.com/9738731731736731/Wanda-Richter-Forgach-Bilder-und-Zeichnungen-Paintings-and-Drawings-by-Wibke-von-Bonin.pdf
    • http://cefasfese.4pu.com/1730738739730734730/Anforderungsprofile-in-Der-Ausbildung-Von-Maschinenbau-Ingenieuren-by-Erich-Mohl.pdf
    • http://cefasfese.4pu.com/1730734737736738734/Trainerassistent-Schwimmen-Handbuch-zur-Ausbildung-by-Cornelia-Glatz.pdf
    • http://cefasfese.4pu.com/1731733733732734733/Einstieg-in-Python-Ideal-f-r-Programmieranf-nger-geeignet-by-Thomas-Theis.pdf
    • http://cefasfese.4pu.com/1731732736732733734/Inklusion-auf-Raten-Zur-Teilhabe-von-Fl-chtlingen-an-Ausbildung-und-Arbeit-by-Maren-Gag.pdf
    • http://cefasfese.4pu.com/1730731735736734737/Elementare-Zahlentheorie-Ein-Sanfter-Einstieg-in-Die-Hohere-Mathematik-by-Nicola-Oswald.pdf
    • http://cefasfese.4pu.com/1731738732738733734/Trainieren-an-der-Stange-vom-Stiefvater-Eine-fundierte-Ausbildung-by-Carmen-Dias.pdf
    • http://cefasfese.4pu.com/1731733730732733730/Der-Schl-ssel-zum-Erfolg-LR---Aus-der-Prax