Malicious PDF — malware analysis report

Static analysis result for SHA-256 a7887920c7ab1a33…

MALICIOUS

PDF

24.4 KB Created: 2019-05-03 09:18:16 +01:00 Authoring application: mPDF 5.7
MD5: c83da783c427e5347f7d4055ebabd09c SHA-1: 6d03cdaa44e7e890351d9dbd7185b7e248cb1c2f SHA-256: a7887920c7ab1a339ef47790c8bc4be4129f31831acd70ae19039bf518d2b9f9
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious. The embedded links, such as http://cefasfese.4pu.com/1730736738730738733/Vom-blauen-Dunst-Rauchen-in-alten-Photographien-by-Melissa-M-ller.pdf, are likely intended to direct users to malicious websites or download further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9716

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730736738730738733/Vom-blauen-Dunst-Rauchen-in-alten-Photographien-by-Melissa-M-ller.pdf
    • http://cefasfese.4pu.com/1730736738732738737/Tabak-die-bittere-Wahrheit-ber-den-blauen-Dunst-by-M-J-Weedman.pdf
    • http://cefasfese.4pu.com/1730736738730737737/The-Kirsten-Dunst-Handbook---Everything-You-Need-to-Know-about-Kirsten-Dunst-by-Emily-Smith.pdf
    • http://cefasfese.4pu.com/9731731739734735/Zartliche-Betrachtung-Schoner-Damen-Photographien-Aus-Der-Sammlung-Gruber-by-Reinhold-Mi-elbeck.pdf
    • http://cefasfese.4pu.com/1731737737739734736/Am-blauen-See-by-Franziska-G-bke.pdf
    • http://cefasfese.4pu.com/8734730734739733/The-Baronian-Halls-and-Ancient-Picturesque-Edifices-of-England-Vol-2-of-2-From-Drawings-by-J-D-Harding-G-Cattermole-S-Prout-W-M-ller-J-Holland-and-Other-Eminent-Artists-by-Mrs-S-C-Hall.pdf
    • http://cefasfese.4pu.com/8737737734735730/Sitzen-ist-das-neue-Rauchen-Das-Trainingsprogramm-um-lebensstilbedingten-Haltungssch-den-vorzubeugen-und-unsere-nat-rliche-Mobilit-t-zur-ckzugewinnen-by-Kelly-Starrett.pdf
    • http://cefasfese.4pu.com/1731738738732739732/Achtundvierzig-Briefe-Sr-Kaiserlichen-Hoheit-Des-Herrn-Erzherzogs-Johann-Von-Oesterreich-an-Johann-Von-M-ller-by-Johann-Von-Osterreich.pdf
    • http://cefasfese.4pu.com/9733735735731730/Folge-dem-blauen-Vogel---Die-Twitter-Story-Bekenntnisse-eines-Kreativen-by-Biz-Stone.pdf
    • http://cefasfese.4pu.com/8738730732733738/Hei-er-Sex-in-blauen-Zelten-Teil-4-Campingplatz-vom-Winde-verweht-by-Heinz-Peter-Tjaden.pdf
    • http://cefasfese.4pu.com/8737734739736731/Club-der-blauen-Welt-An-was-glaubst-du-wenn-morgen-dein-letzter-Tag-w-re-by-Albert-Espinosa.pdf
    • http://cefasfese.4pu.com/1730736738731737735/Enchanted-by-Jen-Dunst.pdf
    • http://cefasfese.4pu.com/1730736738732737731/My-First-Train-Book-by-Chris-Dunst.pdf
    • http://cefasfese.4pu.com/1730736738730738730/Dunst-ber-Dorten-by-Kira-Silberstern.pdf
    • http://cefasfese.4pu.com/1730736738732737733/Madness-in-Cold-War-America-by-Alexander-Dunst.pdf
    • http://cefasfese.4pu.com/1730736738731736737/My-First-Fire-Truck-Book-by-Chris-Dunst.pdf
    • http://cefasfese.4pu.com/1730731732731731736/Creampie-Bilder-Sexy-Creampie-Bilder-Rauchen-Hei-e-Frauen-Offen-Und-Nass-Adult-Picture-Books-by-Wilfried-Kunze.pdf
    • http://cefasfese.4pu.com/1730736738730737736/The-Stygian-Kiss-Annwn-Unveiled-2-by-Kyra-Dunst.pdf
    • http://cefasfese.4pu.com/1730736738732737735/Mi-Primer-Libro-de-Camiones-de-Bomberos-by-Chris-Dunst.pdf
    • http://cefasfese.4pu.com/1730736738731738730/Psychopolitics-and-Cold-War-Culture-Mad-America-by-Alexander-Dunst.pdf