Malicious PDF — malware analysis report

Static analysis result for SHA-256 15626b577e570e6a…

MALICIOUS

PDF

13.0 KB Created: 2019-05-03 07:14:25 +01:00 Authoring application: mPDF 5.7
MD5: dddd734ff99042389762982902c683b6 SHA-1: 001c507db90020a29a416d5e4553b4ac35d05e34 SHA-256: 15626b577e570e6a6de63f21c4d948d29634c0bc40cb3352ffd7d88ecdb33fff
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified as a link farm, which is a common tactic for SEO manipulation or distributing malicious payloads. While the document body is unreadable, the heuristic firings and embedded URLs strongly suggest a malicious intent to redirect users. No scripts were extracted from this sample, limiting further analysis of specific execution methods.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9006

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9095096094090091/The-Only-Son-by-David-Helwig.pdf
    • http://loaminoo.linkpc.net/9095096096098093/93-Best-Canadian-Stories-by-David-Helwig.pdf
    • http://loaminoo.linkpc.net/9095096093096097/Smuggling-Donkeys-by-David-Helwig.pdf
    • http://loaminoo.linkpc.net/9095096095095091/A-Postcard-from-Rome-by-David-Helwig.pdf
    • http://loaminoo.linkpc.net/9095096095098098/The-King-s-Evil-by-David-Helwig.pdf
    • http://loaminoo.linkpc.net/9095096095096094/90-Best-Canadian-Stories-by-David-Helwig.pdf
    • http://loaminoo.linkpc.net/9095096095095096/A-Sound-Like-Laughter-A-Novel-by-David-Helwig.pdf
    • http://loaminoo.linkpc.net/9095096096097094/91-Best-Canadian-Stories-by-David-Helwig.pdf
    • http://loaminoo.linkpc.net/9095096094091092/The-Names-of-Things-by-David-Helwig.pdf
    • http://loaminoo.linkpc.net/9095096094091090/Frederike-Helwig-Kriegskinder-Portraits-of-a-Forgotten-Generation-by-Frederike-Helwig.pdf
    • http://loaminoo.linkpc.net/2095093099094/Beloved-Stranger-Beloved-Trilogy-2-by-Patricia-Potter.pdf
    • http://loaminoo.linkpc.net/3097090098095090/The-Well-Beloved-with-The-Pursuit-of-the-Well-Beloved-by-Thomas-Hardy.pdf
    • http://loaminoo.linkpc.net/9095096095095098/Wonder-Of-Wire-by-Marjorie-Helwig.pdf
    • http://loaminoo.linkpc.net/9095096094090097/Eating-Glass-by-Maggie-Helwig.pdf
    • http://loaminoo.linkpc.net/4090095094095091/Girls-Fall-Down-by-Maggie-Helwig.pdf
    • http://loaminoo.linkpc.net/9095096093095098/On-Helwig-Street-by-Richard-Russo.pdf
    • http://loaminoo.linkpc.net/9095096094091093/Raubfischer-in-Hellas-by-Werner-Helwig.pdf
    • http://loaminoo.linkpc.net/9095096093099097/42-Indian-Mandalas-Coloring-Book-by-Monika-Helwig.pdf
    • http://loaminoo.linkpc.net/8095091091096/RauschGiftEngel-13-Krimis-aus-Franken-zur-Weihnachtszeit-by-Helwig-Arenz.pdf
    • http://loaminoo.linkpc.net/9095096096098095/Topology-based-Methods-in-Visualization-by-Helwig-Hauser.pdf