Malicious PDF — malware analysis report

Static analysis result for SHA-256 16c5202854ca4b55…

MALICIOUS

PDF

19.0 KB Created: 2019-05-07 03:54:26 +01:00 Authoring application: mPDF 5.7
MD5: 3da237b557e773b02c40fbdedfa8ec57 SHA-1: d1f10ee9bf55afa35b6c9b6d111f17bb0b784e5c SHA-256: 16c5202854ca4b553dd26d6824d96edc7b8d1b2d08f6e65da44fd07d5eebe125
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic, which is a common tactic for SEO spam or to redirect users to malicious sites. While the URLs themselves are marked as benign, the sheer volume and structure suggest a malicious intent to manipulate search results or distribute further payloads. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090092096091096092/End-of-Art---Endings-in-Art-La-Fin-de-L-Art---Les-Fins-Dans-Les-Arts-Ende-Der-Kunst---Enden-in-Der-Kunst-by-Gerhard-Seel.pdf
    • http://loaminoo.linkpc.net/9095096090090095/Der-Spaziergang-in-Der-Kunst-Eine-Untersuchung-Des-Motives-in-Der-Kunst-Des-18-Und-19-Jahrhunderts-by-Sabine-Krebber.pdf
    • http://loaminoo.linkpc.net/1090093099091098094/Fruhere-Verhaltnisse-Kunst-in-Wien-Nach-45-by-Gerhard-Habarta.pdf
    • http://loaminoo.linkpc.net/9091099093092094/Pablo-Picasso-Guernica-Und-Die-Kunst-Das-Bild-Zum-Ende-Der-Barbarei-by-Siegfried-P-Neumann.pdf
    • http://loaminoo.linkpc.net/1090094090093091099/The-Book-of-all-Forbidden-Arts-Das-puch-aller-verpoten-kunst-ungelaubens-und-der-zaubrey-by-Johannes-Hartlieb.pdf
    • http://loaminoo.linkpc.net/1090092096092092093/The-Arts-of-Cinema-by-Martin-Seel.pdf
    • http://loaminoo.linkpc.net/9092097098095099/Denken-over-Kunst-by-A-A-Van-den-Braembussche.pdf
    • http://loaminoo.linkpc.net/8097098094090091/Kunst-und-Handwerk-by-Benno-R-ttenauer.pdf
    • http://loaminoo.linkpc.net/1091098096091090093/Enden-Wars-of-Enden-1-by-David-Duane-Kummer.pdf
    • http://loaminoo.linkpc.net/8097098094097095/Kunst-Und-Handwerk-in-Japan-by-Justus-Brinckmann.pdf
    • http://loaminoo.linkpc.net/1091098099090097094/Zen-in-der-Kunst-des-kampflosen-Kampfes-by-Takuan-Soho.pdf
    • http://loaminoo.linkpc.net/6094093094091099/De-Kunst-Van-Het-Geluk-Over-de-zin-van-het-leven-by-Dalai-Lama-XIV.pdf
    • http://loaminoo.linkpc.net/1091096099097099098/Kunst-In-Der-Postmoderne-Dan-Graham-by-Rainer-Metzger.pdf
    • http://loaminoo.linkpc.net/5099098096098099/-ber-Das-Geistige-In-Der-Kunst-by-Wassily-Kandinsky.pdf
    • http://loaminoo.linkpc.net/1090093092091097095/Het-Gemurmel-Van-de-Muze-Over-Kunst-En-Werkelijkheid-by-Els-Baeten.pdf
    • http://loaminoo.linkpc.net/1097096098094099/De-kunst-van-het-rijden-in-de-regen-by-Garth-Stein.pdf
    • http://loaminoo.linkpc.net/1091097092097098098/Sport-in-de-Belgische-kunst-by-L-on-Lewillie.pdf
    • http://loaminoo.linkpc.net/9092097094090097/De-edele-kunst-van-not-giving-a-f-ck-by-Mark-Manson.pdf
    • http://loaminoo.linkpc.net/1091099091093090095/The-Message-Kunst-Und-Okkultismus-Art-And-Occultism-by-Claudia-Dichter.pdf
    • http://loaminoo.linkpc.net/1090092097097091098/Erkennen-Und-Erinnern-in-Kunst-Und-Literatur-by-Wolfgang-Fr-hwald.pdf