Malicious PDF — malware analysis report

Static analysis result for SHA-256 c11c6a7ec3e99887…

MALICIOUS

PDF

18.5 KB Created: 2019-04-16 23:49:02 +01:00 Authoring application: mPDF 5.7
MD5: 9eb2c6c174ffafdf80a80522aa154d9a SHA-1: 09047865518d241c9f58aa7321aaa1e6ac5fa093 SHA-256: c11c6a7ec3e9988745ddcfd27adb98ce51163f7b0e7f9255348df4e0f0c2e3d5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links, indicative of a link farm. While most of the extracted URLs were labeled as confirmed benign, the sheer volume and the heuristic firing suggest a malicious intent to lure users to potentially harmful sites. The document body was heavily obfuscated, preventing a deeper analysis of its specific content or purpose.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9734733732738731/Wie-die-Dackel-in-die-Welt-kamen-die-ganz-besondere-kurze-Geschichte-von-einem-ganz-besonderen-langen-Hund-by-Kizzie-Elizabeth-Jones.pdf
    • http://cefasfese.4pu.com/8730731737731739/Selected-Poems-Eugenio-Montale-by-Eugenio-Montale.pdf
    • http://cefasfese.4pu.com/9735737734730731/Darstellungen-Normaler-Und-Krankhaft-Ver-nderter-K-rperteile-an-Antiken-Weihgaben-by-Theodor-Meyer-Steineg.pdf
    • http://cefasfese.4pu.com/6736735733739737/Revue-by-Eugenio-Recuenco.pdf
    • http://cefasfese.4pu.com/8730731735731739/Eugenio-Montale-by-Jared-Becker.pdf
    • http://cefasfese.4pu.com/8730731735732735/The-Butterfly-of-Dinard-by-Eugenio-Montale.pdf
    • http://cefasfese.4pu.com/6735731731736733/Journal-of-Christopher-Columbus-by-Eugenio-Cassin.pdf
    • http://cefasfese.4pu.com/1731733736736735736/Schilddr-senunterfunktion-und-Hashimoto-anders-behandeln-Wenn-Sie-sich-trotz-normaler-Blutwerte-schlecht-f-hlen-Die-22-Muster-der-Schilddr-senunterfunktion-by-Datis-Kharrazian.pdf
    • http://cefasfese.4pu.com/8730731737731737/Eugenio-Montale-Life-and-Work-by-Luca-Sereni.pdf
    • http://cefasfese.4pu.com/8730731735732732/Poetic-Diaries-1971-and-1972-by-Eugenio-Montale.pdf
    • http://cefasfese.4pu.com/8738733730733738/At-Close-Quarters-Ricardo-Cupido-5-by-Eugenio-Fuentes.pdf
    • http://cefasfese.4pu.com/1730730733738737736/Seeing-Things-by-Kater-Cheek.pdf
    • http://cefasfese.4pu.com/7737734737739739/Respuestas-b-blicas-y-doctrinales-a-los-Testigos-de-Jehov-by-Eugenio-Danyans-De-La-Cinna.pdf
    • http://cefasfese.4pu.com/9732737730739735/Der-namenlose-Kater-by-Hartmut-Schronz.pdf
    • http://cefasfese.4pu.com/2739734738734733/The-Devil-s-Diary-by-Paul-Kater.pdf
    • http://cefasfese.4pu.com/2739734739738738/Hilda-and-Zelda-by-Paul-Kater.pdf
    • http://cefasfese.4pu.com/1730730734731738738/Hilda---Aiaia-by-Paul-Kater.pdf
    • http://cefasfese.4pu.com/1730730733738738733/Hawthorn-Hex-Kit-Melbourne-6-by-Kater-Cheek.pdf
    • http://cefasfese.4pu.com/5730738738739737/O-Qu-Que-Quem---Notas-de-rodap-e-de-corrim-o-Who-s-Who-amp-What-s-What---Footnotes-amp-Grace-Notes-by-Eug-nio-Roda.pdf
    • http://cefasfese.4pu.com/1730730733739737736/Hilda---Back-to-school-by-Paul-Kater.pdf
    • http://cefasfese.4pu.com/673573173173