Malicious PDF — malware analysis report

Static analysis result for SHA-256 ed2223401b1edc39…

MALICIOUS

PDF

17.5 KB Created: 2019-08-02 07:37:12 +01:00 Authoring application: mPDF 5.7
MD5: c82a66dcbef381bd4e83bde7f9ca7d30 SHA-1: 23b151b7fd7105d0ab80cdf83854b2bb1676dc7b SHA-256: ed2223401b1edc39133f1ace8ec98336d158b423150cbfd8f79e447ed80cdea2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs extracted were labeled as benign, the sheer volume and structure suggest a malicious intent, likely for SEO poisoning or to redirect users to harmful sites. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731732737734734730/Unzeitgem-e-Betrachtungen-Die-aphoristischen-Schriften-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/7738733732730733/La-G-n-alogie-de-la-morale-uvres-compl-tes-de-Fr-d-ric-Nietzsche-t-11-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/7730733733736732/The-Gay-Science---Nietzsche-s-Forging-Metaphysical-Thought-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/8738739730735/Basic-Writings-of-Nietzsche-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/1731737739732733732/Thus-Spoke-Zarathustra-Translated-by-Thomas-Common-with-Introductions-by-Willard-Huntington-Wright-and-Elizabeth-Forster-Nietzsche-and-Notes-by-Anthony-M-Ludovici-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/1731734733733735736/Gesammelte-Schriften-In-Deutscher-Sprache-by-Friedrich-A-Hayek.pdf
    • http://cefasfese.4pu.com/5736736730738736/Aurore-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/1739733735732735/Why-I-Am-So-Wise-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/8731739735737733/The-Antichrist-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/1730733731730730730/Al-m-do-bem-e-do-mal-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/3737730732735/The-Gay-Science-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/8737737733730737/Der-Mecklenburger-Volksmund-in-Fritz-Reuters-Schriften-by-Carl-Friedrich-Muller.pdf
    • http://cefasfese.4pu.com/3734737731737/Thus-Spake-Zarathustra-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/6731733736734734/Beyond-Good-and-Evil-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/4732737735733734/Twilight-of-the-Idols-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/3732739733738/Thus-Spoke-Zarathustra-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/4736735734731/On-the-Genealogy-of-Morals-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/1730735739733732731/Thus-Spake-Zarathustra-Vol-1-of-2-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/9730738736734737/Beyond-Good-and-Evil-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/3739736737732737/Twilight-of-the-Idols-by-Friedrich-Nietzsche.pdf