Malicious PDF — malware analysis report

Static analysis result for SHA-256 0c394a72a4a72d36…

MALICIOUS

PDF

20.2 KB Created: 2019-04-30 04:00:07 +01:00 Authoring application: mPDF 5.7
MD5: 1b998c73377d6ea5c15d825708106fb6 SHA-1: b3ff12368f755df72e68d94d88bbb2b74686ec60 SHA-256: 0c394a72a4a72d365652a056b88387039ac85d1cc6b11d0da97a32a925463a30
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document was flagged by a machine learning classifier as malicious and contains a large number of embedded external links, characteristic of a link farm. The primary heuristic indicates a 'PDF_SEO_LINK_FARM' with 32 numeric slug links, suggesting an attempt to drive traffic to external resources. While the document body is heavily obfuscated, the presence of numerous URLs points towards a social engineering tactic to redirect users to potentially malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9090093095093093/In-Hitler-s-Germany-Everyday-Life-in-the-Third-Reich-by-Bernt-Engelmann.pdf
    • http://loaminoo.linkpc.net/5091095096097096/Seeing-Hitler-s-Germany-Tourism-in-the-Third-Reich-by-Kristin-Semmens.pdf
    • http://loaminoo.linkpc.net/1090099095090098096/Bis-alles-in-Scherben-f-llt-Wie-wir-die-Nazizeit-erlebten-1939-1945-by-Bernt-Engelmann.pdf
    • http://loaminoo.linkpc.net/4098096094096091/Inside-Nazi-Germany-Conformity-Opposition-and-Racism-in-Everyday-Life-by-Detlev-J-K-Peukert.pdf
    • http://loaminoo.linkpc.net/4095091099094098/What-We-Knew-Terror-Mass-Murder-and-Everyday-Life-in-Nazi-Germany-by-Eric-A-Johnson.pdf
    • http://loaminoo.linkpc.net/1090099092099097093/Qualitative-Inquiry-in-Everyday-Life-Working-with-Everyday-Life-Materials-by-Svend-Brinkmann.pdf
    • http://loaminoo.linkpc.net/8093096092093091/The-Cause-of-Hitler-s-Germany-by-Leonard-Peikoff.pdf
    • http://loaminoo.linkpc.net/9099091098092093/Wolfgang-Borchert-s-Germany-Reflections-of-the-Third-Reich-by-James-L-Stark.pdf
    • http://loaminoo.linkpc.net/1096098092090091/The-Hitler-Myth-Image-and-Reality-in-the-Third-Reich-by-Ian-Kershaw.pdf
    • http://loaminoo.linkpc.net/1090093090093098094/Germans-Against-Hitler-The-Stauffenberg-Plot-and-Resistance-Under-the-Third-Reich-by-Hans-Mommsen.pdf
    • http://loaminoo.linkpc.net/9093099099097091/Adolf-Hitler-and-the-Third-Reich-1933-1945-by-Robert-Edwin-Herzstein.pdf
    • http://loaminoo.linkpc.net/1094090095091096/Serving-the-Reich-The-Struggle-for-the-Soul-of-Physics-under-Hitler-by-Philip-Ball.pdf
    • http://loaminoo.linkpc.net/1095094097099099/Hitler-s-Traitor-Martin-Bormann-and-the-Defeat-of-the-Reich-by-Louis-Kilzer.pdf
    • http://loaminoo.linkpc.net/3096098097097093/Everyday-Life-in-Early-America-The-Everyday-Life-in-America-series-by-David-Freeman-Hawke.pdf
    • http://loaminoo.linkpc.net/4098096092099090/The-Coming-of-the-Third-Reich-How-the-Nazis-Destroyed-Democracy-and-Seized-Power-in-Germany-by-Richard-J-Evans.pdf
    • http://loaminoo.linkpc.net/8096098091093094/At-the-Heart-of-the-Reich-The-Secret-Diary-of-Hitler-s-Army-Adjutant-by-Gerhard-Engel.pdf
    • http://loaminoo.linkpc.net/8098094091091099/A-Child-of-Hitler-Germany-in-the-Days-When-God-Wore-a-Swastika-by-Alfons-Heck.pdf
    • http://loaminoo.linkpc.net/5091092090095094/Hitler-s-Prisons-Legal-Terror-in-Nazi-Germany-by-Nikolaus-Wachsmann.pdf
    • http://loaminoo.linkpc.net/8097093090097090/Post-War-Lies-Germany-and-Hitler-s-long-shadow-by-Malte-Herwig.pdf
    • http://loaminoo.linkpc.net/9092098093091090/The-Trial-of-Adolf-Hitler-The-Beer-Hall-Putsch-and-the-Rise-of-Nazi-Germany-by-David-King.pdf