Malicious PDF — malware analysis report

Static analysis result for SHA-256 887969cf8e37f5f4…

MALICIOUS

PDF

25.9 KB Created: 2019-05-02 05:27:08 +01:00 Authoring application: mPDF 5.7
MD5: 5aded7bacc135084bcbf457139f321bf SHA-1: 39fe13dc4d3d2143661b7cf3a93be98c41afe143 SHA-256: 887969cf8e37f5f4948f4b7d14cc836b7b516dd431b746e44b4e2766316bdb15
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves appear benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content disguised as academic papers. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5738734730739731/Principles-of-Anticancer-Drug-Development-by-Springer.pdf
    • http://cefasfese.4pu.com/5738734732733733/Human-Tumour-Xenografts-in-Anticancer-Drug-Development-by-Benjamin-Winograd.pdf
    • http://cefasfese.4pu.com/5738734732732732/Genomics-and-Pharmacogenomics-in-Anticancer-Drug-Development-and-Clinical-Response-by-Federico-Innocenti.pdf
    • http://cefasfese.4pu.com/5738734732730737/Drug-Transport-in-Antimicrobial-and-Anticancer-Chemotherapy-by-N-Georgopapadakou.pdf
    • http://cefasfese.4pu.com/5738734732731736/Pharmacokinetic-and-Pharmacodynamic-Principles-of-Anticancer-Therapy-by-Roy-B-Jones.pdf
    • http://cefasfese.4pu.com/7731732737732736/Development-of-Techniques-and-Methods-for-Drug-Analysis-by-Packed-Capillary-Liquid-Chromatography-by-Pernilla-Koivisto.pdf
    • http://cefasfese.4pu.com/8738737735735737/Principles-of-Cultivar-Development-by-W-R-Fehr.pdf
    • http://cefasfese.4pu.com/9732732736738736/Guiding-Principles-for-Spatial-Development-in-Germany-by-Wendelin-Strubelt.pdf
    • http://cefasfese.4pu.com/2738734739732736/Walking-with-the-Poor-Principles-and-Practice-of-Transformational-Development-by-Bryant-L-Myers.pdf
    • http://cefasfese.4pu.com/6731739738733732/Breakthrough-Nonprofit-Branding-Seven-Principles-to-Power-Extraordinary-Results-The-AFP-Wiley-Fund-Development-Series-by-Jocelyne-Daw.pdf
    • http://cefasfese.4pu.com/8738732738731739/Polymeric-Drug-Delivery-II-Polymeric-Matrices-and-Drug-Particle-Engineering-by-Sonke-Svenson.pdf
    • http://cefasfese.4pu.com/5731733732734734/Prehistoric-Textiles-The-Development-of-Cloth-in-the-Neolithic-and-Bronze-Ages-with-Special-Reference-to-the-Aegean-by-Elizabeth-Wayland-Barber.pdf
    • http://cefasfese.4pu.com/5736735738730739/The-Church-and-Development-in-Africa-Aid-and-Development-from-the-Perspective-of-Catholic-Social-Ethics-by-Stan-Chu-Ilo.pdf
    • http://cefasfese.4pu.com/5731731739732735/The-Developing-Teacher-Practical-Activities-for-Professional-Development-Delta-Teacher-Development-Series-by-Duncan-Foord.pdf
    • http://cefasfese.4pu.com/9730738738736739/Complete-Training-of-Horse-and-Rider-in-the-Principles-of-Classical-Horsemanship-In-the-Principles-of-Classical-Horsemanship-by-Alois-Podhajsky.pdf
    • http://cefasfese.4pu.com/1730733738734736731/AI-Game-Engine-Programming-Game-Development-Series-Charles-River-Media-Game-Development-by-Brian-Schwab.pdf
    • http://cefasfese.4pu.com/5738734731735731/Anthracycline-Anticancer-Agts-by-Lown.pdf
    • http://cefasfese.4pu.com/5738734730739733/The-Search-for-New-Anticancer-Drugs-by-M-J-Waring.pdf
    • http://cefasfese.4pu.com/5738734730738736/Camptothecins-New-Anticancer-Agents-by-Milan-Potmesil.pdf
    • http://cefasfese.4pu.com/5738734731734739/Pharmacokinetics-of-Anticancer-Agents-by-Matthew-M-Ames.pdf