Malicious PDF — malware analysis report

Static analysis result for SHA-256 5fb431643bd470fa…

MALICIOUS

PDF

15.5 KB Created: 2019-04-30 03:49:36 +01:00 Authoring application: mPDF 5.7
MD5: afb77455a0bf39dfabe1ad3aedef78e2 SHA-1: 9538c422ec601a99cb2c6569d23ba7668793a564 SHA-256: 5fb431643bd470fa5f78af3d3156280a0a5353016680b3e99b6bc0d2d9aa1033
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. While the document body is heavily obfuscated, the heuristic firings strongly indicate a malicious intent to redirect users to a link farm. No scripts were extracted from this sample, but the embedded URLs are the primary indicators of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8097090099096092/Grendel-s-Game-Walther-Ekman-1-by-Erik-Mauritzson.pdf
    • http://loaminoo.linkpc.net/8090090096090091/Walther-s-Pastorale-That-is-American-Lutheran-Pastoral-Theology-by-C-F-W-Walther.pdf
    • http://loaminoo.linkpc.net/8097091091092090/Blood-And-Soil-Richard-Walther-Darr-And-Hitler-s-quot-Green-Party-quot-by-Walther-Darr-.pdf
    • http://loaminoo.linkpc.net/9097098094092091/Selected-Poems-of-Walther-von-der-Vogelweide-by-Walther-von-der-Vogelweide.pdf
    • http://loaminoo.linkpc.net/2094092097090099/The-Dog-by-Kerstin-Ekman.pdf
    • http://loaminoo.linkpc.net/5091092092092091/The-Spring-by-Kerstin-Ekman.pdf
    • http://loaminoo.linkpc.net/3095094090098094/Witches-Rings-by-Kerstin-Ekman.pdf
    • http://loaminoo.linkpc.net/1090098090090097091/Rotes-Meer-Der-achte-Fall-f-r-Erik-Winter-Ein-Erik-Winter-Krimi-by-ke-Edwardson.pdf
    • http://loaminoo.linkpc.net/1091090093093091090/Clarence-Goes-Out-West-amp-Meets-a-Purple-Horse-by-Jean-Ekman-Adams.pdf
    • http://loaminoo.linkpc.net/3093090092098/Grendel-by-John-Gardner.pdf
    • http://loaminoo.linkpc.net/6091095095092095/A-Mammal-s-Notebook-Collected-Writings-of-Erik-Satie-by-Erik-Satie.pdf
    • http://loaminoo.linkpc.net/6094097099094096/Buddhism-in-China-Collected-Papers-of-Erik-Zurcher-by-Erik-Z-rcher.pdf
    • http://loaminoo.linkpc.net/8097094090094096/Erik-Lundberg-Studies-in-Economic-Instability-and-Change-by-Erik-Lundberg.pdf
    • http://loaminoo.linkpc.net/2091099092097096/Grendel-s-Guide-to-Love-and-War-by-A-E-Kaplan.pdf
    • http://loaminoo.linkpc.net/2093099095098/Grendel-Warchild-by-Matt-Wagner.pdf
    • http://loaminoo.linkpc.net/1090092099090090094/Der-Grendel-verbannt-in-alle-Ewigkeit-by-Robin-Li.pdf
    • http://loaminoo.linkpc.net/6096098091096/The-Grendel-Affair-SPI-Files-1-by-Lisa-Shearin.pdf
    • http://loaminoo.linkpc.net/1090093098094096091/AI-Game-Engine-Programming-Game-Development-Series-Charles-River-Media-Game-Development-by-Brian-Schwab.pdf
    • http://loaminoo.linkpc.net/7099099094093/Grendel-s-Curse-Rogue-Angel-48-by-Alex-Archer.pdf
    • http://loaminoo.linkpc.net/5098093096095091/Grendel-Batman-Devil-s-Masque-by-Matt-Wagner.pdf