Malicious PDF — malware analysis report

Static analysis result for SHA-256 04a09ffd97bd2aae…

MALICIOUS

PDF

15.9 KB Created: 2019-05-02 18:41:57 +01:00 Authoring application: mPDF 5.7
MD5: 6883a6bcdaa1f104c217d5c22cf095d6 SHA-1: b4951be209862e7d1319aa9d393241e02e3c1f7a SHA-256: 04a09ffd97bd2aae9b4ec996b0a9bfc63ed81bfbb0055a6676ba4509c3335665
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, suggesting a link farm or redirection scheme. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be social engineering through a large number of links, likely intended to deceive users into downloading potentially malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5097091095094091/Ce-jour-l-Au-coeur-du-commando-qui-a-tu-Ben-Laden-Essais-by-Mark-Owen.pdf
    • http://loaminoo.linkpc.net/4091094095093092/This-Time-Around-by-Mark-A-Roeder.pdf
    • http://loaminoo.linkpc.net/2094095096098090/Child-Of-My-Time-by-Mark-Frankland.pdf
    • http://loaminoo.linkpc.net/2096099096094094/The-Curious-Incident-of-the-Dog-In-the-Night-time-by-Mark-Haddon.pdf
    • http://loaminoo.linkpc.net/3098093092095094/The-Curious-Incident-of-the-Dog-in-the-Night-Time-by-Mark-Haddon.pdf
    • http://loaminoo.linkpc.net/6090097095093099/The-Curious-Incident-of-the-Dog-in-the-Night-Time-by-Mark-Haddon.pdf
    • http://loaminoo.linkpc.net/2099095095093099/The-Curious-Incident-of-the-Dog-in-the-Night-time-by-Mark-Haddon.pdf
    • http://loaminoo.linkpc.net/5090093097093095/The-Curious-Incident-of-the-Dog-in-the-Night-Time-by-Mark-Haddon.pdf
    • http://loaminoo.linkpc.net/4091094090091093/Do-It-Tomorrow-and-Other-Secrets-of-Time-Management-by-Mark-Forster.pdf
    • http://loaminoo.linkpc.net/7094094098096092/3-Commando-Brigade-by-Ewen-Southby-Tailyour.pdf
    • http://loaminoo.linkpc.net/2091092091090096/Commando-Morgan-s-Mercenaries-3-by-Lindsay-McKenna.pdf
    • http://loaminoo.linkpc.net/2093098095091095/The-Wastewater-Gardener-Preserving-the-Planet-One-Flush-at-a-Time-by-Mark-Nelson.pdf
    • http://loaminoo.linkpc.net/8090091099092099/Peti-Tango-amp-Blip---Time-Travelers-A-New-Friend-by-Mark-Lemar.pdf
    • http://loaminoo.linkpc.net/4092093095093093/Bonnie-Raitt-Updated-Edition-Still-in-the-Nick-of-Time-by-Mark-Bego.pdf
    • http://loaminoo.linkpc.net/4094096094095/Order-66-Star-Wars-Republic-Commando-4-by-Karen-Traviss.pdf
    • http://loaminoo.linkpc.net/9093094095094/Lofty-Pursuits-Repairing-the-World-One-Building-at-a-Time-by-Mark-Richard-Schuster.pdf
    • http://loaminoo.linkpc.net/4090090092096098/K9-Commando-Police-and-Army-Dogs-from-New-York-to-Berlin-by-Violetta-Kovacs.pdf
    • http://loaminoo.linkpc.net/7090096090098/True-Colors-Star-Wars-Republic-Commando-3-by-Karen-Traviss.pdf
    • http://loaminoo.linkpc.net/4099099099098093/Time-Trip-A-Time-After-Time-Reincarnation-Novella-Time-After-Time-Reincarnation-Lives-Book-1-by-Wendy-Godding.pdf
    • http://loaminoo.linkpc.net/7098097093098095/Commando-Kieffer-The-Free-French-Landings-in-Normandy-by-Jean-Charles-Stasi.pdf