Malicious PDF — malware analysis report

Static analysis result for SHA-256 f527827a7bcb0b7a…

MALICIOUS

PDF

20.4 KB Created: 2019-05-03 05:14:43 +01:00 Authoring application: mPDF 5.7
MD5: bb82e5763c4f00f40dea717db963d3cb SHA-1: 926c787b3900aec46fe6779423d2e309fb40d72d SHA-256: f527827a7bcb0b7a5a01eac3be41a6b705ea645dc3e2a1d9c017a054fbec6bd5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links point to benign content, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO poisoning or to distribute further malware. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cmeinasaoo.du
    • http://cmeinasaoo.duckdns.org/5b24b22b22b28b26/PHOBIE-DI-DANIELE-CATTANEO-by-DANIELE-CATTANEO.pdf
    • http://cmeinasaoo.duckdns.org/7b25b28b23b20b24/Mauvaise-graine-by-BEATRICE-DEPARPE.pdf
    • http://cmeinasaoo.duckdns.org/6b20b24b23b22b26/La-mauvaise-heure-by-Denise-Mina.pdf
    • http://cmeinasaoo.duckdns.org/7b25b28b24b24b26/The-Zad-and-NoTAV-Territorial-Struggles-and-the-Making-of-a-New-Political-Intelligence-by-Mauvaise-Troupe-Collective.pdf
    • http://cmeinasaoo.duckdns.org/1b20b27b25b20b27b27/Begattung-und-Herrschaft-by-Daniele-Georges.pdf
    • http://cmeinasaoo.duckdns.org/5b27b26b21b24b26/Thierry-Mugler-by-Daniele-Bott.pdf
    • http://cmeinasaoo.duckdns.org/6b24b22b28b23b29/Eclats-d-Oc-ans-by-Dani-le-Romatet.pdf
    • http://cmeinasaoo.duckdns.org/8b29b21b22b25b25/Il-rituale-Emulation-by-Daniele-Mansuino.pdf
    • http://cmeinasaoo.duckdns.org/5b27b26b26b25b22/Le-Pharaon-Maudit-by-Dani-le-Calvo-Platero.pdf
    • http://cmeinasaoo.duckdns.org/4b28b22b23b23b27/Fated-A-Mermaid-s-Curse-2-by-Daniele-Lanzarotta.pdf
    • http://cmeinasaoo.duckdns.org/5b28b28b25b20b27/Gods-and-Goddesses-in-Ancient-Italy-by-Daniele-Miano.pdf
    • http://cmeinasaoo.duckdns.org/9b21b21b28b22b20/Die-anal-geile-W-chterin-auf-der-Bank-by-Daniele-Arian.pdf
    • http://cmeinasaoo.duckdns.org/4b20b27b25b27b26/Wide-Awake-Academy-of-the-Fallen-1-by-Daniele-Lanzarotta.pdf
    • http://cmeinasaoo.duckdns.org/7b28b28b21b29b28/Jean-Marie-Straub-and-Daniele-Huillet-by-Ted-Fendt.pdf
    • http://cmeinasaoo.duckdns.org/2b22b21b23b25b24/Divine-Ashes-Imprinted-Souls-3-by-Daniele-Lanzarotta.pdf
    • http://cmeinasaoo.duckdns.org/1b21b21b28b26b25b27/Le-coming-out-des-h-t-ros-L-amour-de-toutes-les-mani-res-by-Dani-le-Couture.pdf
    • http://cmeinasaoo.duckdns.org/5b25b27b21b29b24/The-Sentences-of-Sextus-and-the-Origins-of-Christian-Ascetiscism-by-Daniele-Pevarello.pdf
    • http://cmeinasaoo.duckdns.org/7b28b28b22b26b22/Landscapes-of-Resistance-The-German-Films-of-Dani-le-Huillet-and-Jean-Marie-Straub-by-Barton-Byg.pdf
    • http://cmeinasaoo.duckdns.org/8b20b22b26b28b24/Ingressive-and-Egressive-Verbs-in-English-A-Cognitive-Pragmatic-Approach-to-Meaning-by-Daniele-Franceschi.pdf
    • http://cmeinasaoo.duckdns.org/7b25b27b20b26b21/R-futation-de-la-Pr-tendue-Lettre-Pastorale-de-M-Bertier-v-que-Constitutionnel-Du-D-partement-de-l-Aveiron-Dans-Laquelle-on-Montre-La-Mauvaise-Foi-Ou-l-Ignorance-Du-Faiseur-de-M-Bertier-Dans-La-Citation-Ou-Application-Des-Faits-Historiques-Dont-by-Unknown.pdf