Malicious PDF — malware analysis report

Static analysis result for SHA-256 ad4c27a0dc7c229e…

MALICIOUS

PDF

19.7 KB Created: 2019-05-02 06:17:11 +01:00 Authoring application: mPDF 5.7
MD5: 172c55aeeddde97c9fd77c8cbe3599c7 SHA-1: 7f6d9e8971d0a1242da6a1da45f19d24b3e6abcc SHA-256: ad4c27a0dc7c229e9de1a3a4683cb7253b7d4b72ab23d2b3e323f3d06665a1ca
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged as malicious by an ML classifier and contains a large number of embedded external links. The heuristic 'PDF_SEO_LINK_FARM' indicates that the primary purpose of this document is to host a mass of external links, likely for SEO manipulation or to serve as a landing page for malicious content. While no scripts were extracted, the structure and link farm suggest a delivery mechanism for further compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731737731732733732/The-Occult-Arts-by-J-W-Frings.pdf
    • http://cefasfese.4pu.com/1730735736738738733/Weiser-Book-of-Horror-and-the-Occult-Hidden-Magic-Occult-Truths-and-the-Stories-That-Started-It-All-by-Lon-Milo-DuQuette.pdf
    • http://cefasfese.4pu.com/1731737731732730733/The-Excellence-of-the-Rosary-by-M-J-Frings.pdf
    • http://cefasfese.4pu.com/1731737730739738737/Animal-Communication-by-Hubert-Frings.pdf
    • http://cefasfese.4pu.com/1731737731731730739/Israel-Pal-stina-Ein-Reisebuch-In-Den-Alltag-by-Ute-Frings.pdf
    • http://cefasfese.4pu.com/1731737730739737732/Fashion-From-Concept-to-Consumer-by-Gini-S-Frings.pdf
    • http://cefasfese.4pu.com/1731737730739737733/Fashion-From-Concept-to-Consumer-by-Gini-Stephens-Frings.pdf
    • http://cefasfese.4pu.com/1731737731731732733/Totholz-Kriminalroman-aus-der-Eifel-Jo-Frings-2-by-Ralf-Kramp.pdf
    • http://cefasfese.4pu.com/1731737731731739738/Gesprach-Und-Handlung-in-Der-Thebais-Des-Statius-by-Irene-Frings.pdf
    • http://cefasfese.4pu.com/1731737731731732730/The-Enneagram-Cats-of-Muir-Beach-by-Margaret-Frings-Keyes.pdf
    • http://cefasfese.4pu.com/1731737731732735730/Finanzierungsformen-Fur-Den-Vertrieb-Regenerativer-Energien-in-Deutschland-by-Marion-Frings.pdf
    • http://cefasfese.4pu.com/1731737731732732737/Understanding-and-Managing-Stress-PsychologyItBetter-Book-3-by-Daniel-Frings.pdf
    • http://cefasfese.4pu.com/1731730739731731730/Gehirn-und-Moral-Ethische-Fragen-in-Neurologie-und-Hirnforschung-by-Markus-Frings.pdf
    • http://cefasfese.4pu.com/1731737731732734735/Aus-Amen-Ende-So-kann-ich-nicht-mehr-Pfarrer-sein-by-Thomas-Frings.pdf
    • http://cefasfese.4pu.com/1731737731731731739/Molly-s-Daughter-A-Three-Generation-Story-Exploring-What-Do-Women-Really-Want-by-Margaret-Frings-Keyes.pdf
    • http://cefasfese.4pu.com/1731737731732730736/Grundlagen-der-Kriminaltechnik-I-Lehr--und-Studienbriefe-Kriminalistik-Kriminologie-Band-16-by-Christoph-Frings.pdf
    • http://cefasfese.4pu.com/8737735735733/The-Occult-by-Colin-Wilson.pdf
    • http://cefasfese.4pu.com/5738735736738732/Consult-the-Occult-by-S-E-Batt.pdf
    • http://cefasfese.4pu.com/2731738737731738/Vampires-The-Occult-Truth-by-Konstantinos.pdf
    • http://cefasfese.4pu.com/1731737731732735736/Giorgiones-Landliches-Konzert-Darstellung-Der-Musik-ALS-Kunstlerisches-Programm-in-Der-Venezianischen-Malerei-Der-Renaissance-by-Gabriele-Frings.pdf
    • http://cefasfese.4pu.com