Malicious PDF — malware analysis report

Static analysis result for SHA-256 a817d0a94d206158…

MALICIOUS

PDF

26.4 KB Created: 2019-06-04 14:52:47 +01:00 Authoring application: mPDF 5.7
MD5: a0e0ad44a3233af37c9ad47acfa9cbdc SHA-1: 4eaac31b5599c05e69d9a556de79114e14da4350 SHA-256: a817d0a94d2061581a2e281f24f654227fd4ff028774ea704a7fa9417c0d4519
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign content, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO manipulation or to redirect users to harmful sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9742

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731734733735735736/Ludwig-Van-Beethoven---8-Variations-on-t-Ndeln-Und-Scherzen-Woo76---A-Score-for-Solo-Piano-by-Ludwig-van-Beethoven.pdf
    • http://cefasfese.4pu.com/8735734732738730/Complete-Piano-Sonatas-Volume-1-Nos-1-15-by-Ludwig-van-Beethoven.pdf
    • http://cefasfese.4pu.com/1730738739731731732/Tanze-by-Ludwig-van-Beethoven.pdf
    • http://cefasfese.4pu.com/8731733737736732/Ludwig-Van-Beethoven-by-Mike-Venezia.pdf
    • http://cefasfese.4pu.com/8730730736735730/Symphony-No-6-in-F-Major-Op-68-quot-Pastorale-quot-by-Ludwig-van-Beethoven.pdf
    • http://cefasfese.4pu.com/1731734733735735737/Vorbild-Und-Vernunft-Die-Regelung-Von-Lachen-Und-Scherzen-Im-Mittelalterlichen-Islam-by-Ludwig-Ammann.pdf
    • http://cefasfese.4pu.com/4739736737736738/Beethoven-s-Piano-Sonatas-A-Short-Companion-by-Charles-Rosen.pdf
    • http://cefasfese.4pu.com/1730737734737736735/Ludwig-Ganghofers-Gesammelte-Schriften-Vol-1-of-10-Volksausgabe-Mit-Dem-Bildnis-Des-Dichters-Von-Franz-Von-Stuck-by-Ludwig-Ganghofer.pdf
    • http://cefasfese.4pu.com/1730737734737738736/Ludwig-Ganghofer-Die-beliebtesten-Heimatromane-9-Titel-in-einem-Buch---Vollst-ndige-Ausgaben-Das-Gotteslehen-Der-Herrgottschnitzer-von-Ammergau-Besondere-Der-Dorfapostel-by-Ludwig-Ganghofer.pdf
    • http://cefasfese.4pu.com/7739732733737735/Beethoven-Forum-Volume-6-by-Beethoven-Forum.pdf
    • http://cefasfese.4pu.com/3731739738730737/Planning-for-Freedom-and-Sixteen-Other-Essays-and-Addresses-Ludwig-Von-Mises-Also-the-Essential-Von-Mises-by-Ludwig-von-Mises.pdf
    • http://cefasfese.4pu.com/9738733739732730/Ludwig-Walrabe-s-Chronologie-Sammtlicher-Hamburger-Buhnen-Nebst-Angabe-Der-Meisten-Schauspieler-Sanger-Tanzer-Und-Musiker-Welche-Seit-1230-Bis-1846-an-Denselben-Engagirt-Gewesen-Und-Gastirt-Haben-Mit-Zwei-Stahlstichen-by-Ludwig-1808-1872-Wollrabe.pdf
    • http://cefasfese.4pu.com/8731733738730734/When-You-Lunch-with-the-Emperor-The-Adventures-of-Ludwig-Bemelmans-by-Ludwig-Bemelmans.pdf
    • http://cefasfese.4pu.com/1730735734734737733/10-Variations-on-Unser-Dummer-P-Bel-Meint-by-Wolfgang-Amadeus-Mozart-for-Solo-Piano-1784-K-455-by-Wolfgang-Amadeus-Mozart.pdf
    • http://cefasfese.4pu.com/8735734732737734/Beethoven-s-Cat-by-Elisabet-McHugh.pdf
    • http://cefasfese.4pu.com/2733738731735733/The-Beethoven-Medal-Pennington-2-by-K-M-Peyton.pdf
    • http://cefasfese.4pu.com/8735734731734731/Beethoven-s-Shadow-by-Jonathan-Biss.pdf
    • http://cefasfese.4pu.com/8735734732732734/Beethoven-s-Tenth-by-Brian-Harvey.pdf
    • http://cefasfese.4pu.com/8735734732739731/Beethoven-Symphony-No-9-by-Nicholas-Cook.pdf
    • http://cefasfese.4pu.com/8735734732739730/Beethoven-and-the-French-Revolution-by-Fan-S-Noli.pdf
    • http://cefasfese.4pu.com/1731734733735735737/Vorbild-Und-V