Malicious PDF — malware analysis report

Static analysis result for SHA-256 1fef73a494038125…

MALICIOUS

PDF

23.1 KB Created: 2019-05-04 14:20:37 +01:00 Authoring application: mPDF 5.7
MD5: 09606a75b5a9cbbf9180f881b908665d SHA-1: cdf2486879cab1d7f589502904dae883e23d84f7 SHA-256: 1fef73a4940381252e4ae9b4b0acdcfee5d773512be35e9e202bea86476f3aa6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO abuse or to obscure malicious activity. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic identified this link farm. While the specific URLs themselves are currently marked as benign, the sheer volume and structure suggest a deceptive pattern. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7097094090095091/Eastern-Europe-in-the-Twentieth-Century---And-After-by-Richard-Crampton.pdf
    • http://loaminoo.linkpc.net/9092093095095/In-Europe-Travels-Through-the-Twentieth-Century-by-Geert-Mak.pdf
    • http://loaminoo.linkpc.net/7091094095097095/Dark-Continent-Europe-s-Twentieth-Century-by-Mark-Mazower.pdf
    • http://loaminoo.linkpc.net/9091098098096092/Female-Exiles-in-Twentieth-and-Twenty-first-Century-Europe-by-Gesa-Zinn.pdf
    • http://loaminoo.linkpc.net/2093098098090099/The-German-Genius-Europe-s-Third-Renaissance-the-Second-Scientific-Revolution-and-the-Twentieth-Century-by-Peter-Watson.pdf
    • http://loaminoo.linkpc.net/3099090092094097/The-Broadview-Anthology-of-British-Literature-Volume-6a-The-Twentieth-Century-and-Beyond-From-1900-to-Mid-Century-Volume-6a-The-Twentieth-Century-and-Beyond-From-1900-to-Mid-Century-by-Joseph-Laurence-Black.pdf
    • http://loaminoo.linkpc.net/3098095096098099/The-Oxford-History-of-the-British-Empire-Volume-IV-The-Twentieth-Century-Twentieth-Century-Vol-4-by-Judith-M-Brown.pdf
    • http://loaminoo.linkpc.net/2097092090096/Twentieth-Century-Crime-And-Mystery-Writers-Twentieth-Century-Writers-Series-by-Lesley-Henderson.pdf
    • http://loaminoo.linkpc.net/5090098094090099/The-Alternative-in-Eastern-Europe-by-Rudolf-Bahro.pdf
    • http://loaminoo.linkpc.net/4097091098096093/A-History-of-Eastern-Europe-by-Vejas-Gabriel-Liulevicius.pdf
    • http://loaminoo.linkpc.net/1095097094093/Judenrat-The-Jewish-Councils-in-Eastern-Europe-under-Nazi-Occupation-by-Isaiah-Trunk.pdf
    • http://loaminoo.linkpc.net/4098093096093091/Poetry-of-Survival-Post-War-Poets-of-Central-and-Eastern-Europe-by-Daniel-Weissbort.pdf
    • http://loaminoo.linkpc.net/7097094092091092/The-Geographical-Reading-Book-by-T-Crampton-and-T-Turner-by-Thomas-Crampton.pdf
    • http://loaminoo.linkpc.net/4093097092094096/Batting-on-the-Bosphorus-A-Skoda-Powered-Cricket-Tour-Through-Eastern-Europe-by-Angus-Bell.pdf
    • http://loaminoo.linkpc.net/6090091090099091/Zalmoxis-the-Vanishing-God-Comparative-Studies-in-the-Religions-and-Folklore-of-Dacia-and-Eastern-Europe-by-Mircea-Eliade.pdf
    • http://loaminoo.linkpc.net/2095096090098091/Best-Recipes-from-Eastern-Europe-Dainty-Dishes-Delicious-Drinks-Edible-Excellence-5-by-Sahara-Sanders.pdf
    • http://loaminoo.linkpc.net/4095097091095/From-the-End-of-the-Twentieth-Century-by-John-M-Ford.pdf
    • http://loaminoo.linkpc.net/5091091090093091/Science-in-the-Twentieth-Century-and-Beyond-by-Jon-Agar.pdf
    • http://loaminoo.linkpc.net/5091098093091092/Alabama-in-the-Twentieth-Century-by-Wayne-Flynt.pdf
    • http://loaminoo.linkpc.net/1095094096098098/Paris-in-the-Twentieth-Century-by-Jules-Verne.pdf