Malicious PDF — malware analysis report

Static analysis result for SHA-256 ddf0bfe51a995614…

MALICIOUS

PDF

20.4 KB Created: 2019-05-04 10:44:40 +01:00 Authoring application: mPDF 5.7
MD5: d2322f7f331fcadbabf7bf565756a257 SHA-1: 5bc7cb5d63ba8aa5fa8d7204a98234587d5698f7 SHA-256: ddf0bfe51a995614375ed88f7a0784397e761c44eb9f5bf04c49b657866461ab
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, forming a link farm. This is indicative of a SEO poisoning or spamming campaign designed to drive traffic to potentially malicious or unwanted content. The ML classifier also flagged this PDF as malicious, supporting this assessment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9472

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4
    • http://cefasfese.4pu.com/1730732735734739734/Das-Wahrnehmungsproblem-Und-Seine-Verwandlung-In-Ph-nomenologischer-Einstellung-by-U-Melle.pdf
    • http://cefasfese.4pu.com/8730736739737737/Rembrandt-and-His-Influence-on-Eighteenth-Century-German-and-Austrian-Printmakers-Rembrandt-Seine-Verwandlung-in-Der-Deutschen-Und-Osterreichische-by-Liesbeth-Heenk.pdf
    • http://cefasfese.4pu.com/1730732735734738731/Mes-Bons-Petits-Plats-de-Printemps-18-recettes-vegan-sans-gluten-La-Cuisine-Bio-V-g-tale-de-Melle-Pigut-t-2-by-Melle-Pigut.pdf
    • http://cefasfese.4pu.com/1731736731733736737/LEIPZIG-und-seine-ZONE-bzw-Leipzig-und-seine-Gesund-h-Umweltzone-by-G-Recht.pdf
    • http://cefasfese.4pu.com/1730732735736730733/In-the-Essence-of-Blood-by-Melle-Amade.pdf
    • http://cefasfese.4pu.com/1730732735734739731/The-Relevancy-of-Hyperreality-in-Art-by-Melle-Nieling.pdf
    • http://cefasfese.4pu.com/1730732735734738736/Laboratoires-Cccp-Dr-Leche-Melle-Rose-by-Jianping-He.pdf
    • http://cefasfese.4pu.com/9734736731734733/Die-Verwandlung-BDSM-by-Luisa-Degard.pdf
    • http://cefasfese.4pu.com/9734736730736732/T-dliche-Verwandlung-by-Matthias-Fischer.pdf
    • http://cefasfese.4pu.com/1730738732730733733/The-Metamorphosis-Die-Verwandlung-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/9734736731735734/Drachenblut-Die-Verwandlung-by-Sven-L-ffler.pdf
    • http://cefasfese.4pu.com/1730732735736738739/Nog-Tien-Seconden-Over-de-Modeltekenlessen-van-Albert-Bouhuis-by-Melle-Nieling.pdf
    • http://cefasfese.4pu.com/1730732735736738731/Mes-Petits-Plats-des-4-saisons-75-recettes-v-ganes-by-Melle-Pigut.pdf
    • http://cefasfese.4pu.com/9730730737730732/Die-Verwandlung-Vollst-ndige-Ausgabe-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/1730732735736730736/K-ln-Bonn-Airport---Wie-geht-das-Bachems-Wissenswelt-by-Melle-Siegfried.pdf
    • http://cefasfese.4pu.com/8738735731736732/Die-Verwandlung-Reclam-XL---Text-und-Kontext-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/1730735733738733734/H2O-Band-1---Magische-Verwandlung-Pl-tzlich-Meerjungfrau-by-Rachel-Elliot.pdf
    • http://cefasfese.4pu.com/5739736730734736/Die-Verwandlung-Metamorphosis-Bilingual-Parallel-Text-in-Deutsch-English-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/9734736732735730/Das-Wort-in-Feiner-Organischen-Verwandlung-by-Karl-Ferdinand-1775-1849-Becker.pdf
    • http://cefasfese.4pu.com/6738736731737733/Nachts-an-der-Seine-by-Jojo-Moyes.pdf