Malicious PDF — malware analysis report

Static analysis result for SHA-256 3ef1de2ef57cf8b5…

MALICIOUS

PDF

17.2 KB Created: 2019-04-30 04:12:44 +01:00 Authoring application: mPDF 5.7
MD5: 174caad868dd1358d82c577fe9b2fe12 SHA-1: 67775591540f186ba44a3a7dc9d92fbbb570cdaa SHA-256: 3ef1de2ef57cf8b5db97a82df7bc15ee9e470cfcb35550cdabf343bdd2da16bb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded URLs, forming a link farm. The primary heuristic identified this as a PDF_SEO_LINK_FARM, indicating a likely attempt to manipulate search results or distribute content via numerous links. While no scripts were extracted, the sheer volume of links suggests a distribution or SEO-based attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6090096093091096/Alphonse-Maria-Mucha-by-Jiri-Mucha.pdf
    • http://loaminoo.linkpc.net/6090096091098099/Drawings-of-Mucha-by-Alphonse-Mucha.pdf
    • http://loaminoo.linkpc.net/7094094094092094/Herr-Wolke-und-sein-Freund-Alfons-Vanille-Nudeln-amp-ein-Geistesblitz-Ein-Abenteuer-Kochbuch-Herr-Wolke-amp-sein-Freund-Alfons-Schuhbeck-3-by-Rolf-Barth.pdf
    • http://loaminoo.linkpc.net/8091099094096091/Josef-Albers-Formulation-Articulation-by-Josef-Albers.pdf
    • http://loaminoo.linkpc.net/3097094094094097/Get-Over-It-by-Corinne-Mucha.pdf
    • http://loaminoo.linkpc.net/3097094094094099/My-Alaskan-Summer-by-Corinne-Mucha.pdf
    • http://loaminoo.linkpc.net/6090096091098095/Alphonse-Mucha-An-American-Collection-by-Don-Kurtz.pdf
    • http://loaminoo.linkpc.net/6090096091097090/Alphonse-Mucha-Masterworks-by-Rosalind-Ormiston.pdf
    • http://loaminoo.linkpc.net/1091097095093099099/Verliebte-Jungs-by-Alfons-Th-Seeboth.pdf
    • http://loaminoo.linkpc.net/1090090091094095091/Jagd-Vorbei-by-Alfons-Wunschheim.pdf
    • http://loaminoo.linkpc.net/9090097099099091/Der-st-hlerne-Schrei-by-Alfons-Petzold.pdf
    • http://loaminoo.linkpc.net/1098095090095096/Bookee-and-Keeboo-search-for-a-chicken-by-Alfons-Freire.pdf
    • http://loaminoo.linkpc.net/1091092092099095099/Resilienzf-rderung-mit-Kindern-Kinderpsychodrama-Band-2-Volume-2-by-Alfons-Aichinger.pdf
    • http://loaminoo.linkpc.net/9094093098091099/Fach--Und-Gemeinsprache-in-Der-Kraftfahrzeugtechnik-Studien-Zum-Wortschatz-by-Alfons-Schrader.pdf
    • http://loaminoo.linkpc.net/6099092099090095/The-3-most-powerful-presentation-techniques-of-Seth-Godin-by-Alfons-Grabher.pdf
    • http://loaminoo.linkpc.net/8098094091091099/A-Child-of-Hitler-Germany-in-the-Days-When-God-Wore-a-Swastika-by-Alfons-Heck.pdf
    • http://loaminoo.linkpc.net/1091094099091095095/Die-Volkslieder-Des-Engadin-Nebst-Einem-Anhange-Engadinischer-Volkslieder-Im-Original-Und-in-Deutscher-bersetzung-by-Alfons-Flugi.pdf
    • http://loaminoo.linkpc.net/2098090096093091/The-Cowards-by-Josef-kvoreck-.pdf
    • http://loaminoo.linkpc.net/8091099092090097/Interaction-of-Color-by-Josef-Albers.pdf
    • http://loaminoo.linkpc.net/2093096092097099/The-Miracle-Game-by-Josef-kvoreck-.pdf