Malicious PDF — malware analysis report

Static analysis result for SHA-256 79410dee4dd382af…

MALICIOUS

PDF

21.7 KB Created: 2019-05-03 06:02:21 +01:00 Authoring application: mPDF 5.7
MD5: 6aab0702c1544b71cd9e7bc837e15930 SHA-1: 5ff677cca4f3d105d27bf98f98b456688a83951a SHA-256: 79410dee4dd382aff06ebb41868f00da1793ae5d5e028ba7f6786888cd5b9343
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to a dynamic DNS domain, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML classifier also flagged this PDF with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9098099096096098/Heimliche-Liebschaft---Teil-2-by-Mandy-Hammer.pdf
    • http://loaminoo.linkpc.net/9096090099097097/Tanzen-im-Sitzen-Teil-1-2-Teil-1-Tanzformen-einsetzen-und-selbst-entwickeln-Teil-2-46-Mustert-nze-by-Sandra-K-hnlein.pdf
    • http://loaminoo.linkpc.net/6092093095093097/Teil-1-Konflikte-in-Der-Triade-Teil-2-Spielregeln-in-Der-Psychotherapie-Teil-3-Weiterbildungsforschung-Und-Evaluation-by-Peter-Buchheim.pdf
    • http://loaminoo.linkpc.net/1099090092092/Hammer-Making-Movies-Out-of-Life-and-Sex-by-Barbara-Hammer.pdf
    • http://loaminoo.linkpc.net/7091097092094/The-Hammer-and-the-Cross-Hammer-and-the-Cross-1-by-Harry-Harrison.pdf
    • http://loaminoo.linkpc.net/9098099095099096/Schattenfrauen---Die-heimliche-Geliebte-by-Katrin-Seidler.pdf
    • http://loaminoo.linkpc.net/1091093094094096095/Tell-El-Daba-XX-Die-Chronologie-Der-Siedlungskeramik-Der-Zweiten-Zwischenzeit-Aus-Tell-El-Daba-Teil-I-Text-Teil-II-Abbilldungen-Und-Tabellen-by-Karin-Kopetzky.pdf
    • http://loaminoo.linkpc.net/9098099096096096/Heimliche-Liebe-Julia-1582-by-Catherine-Spencer.pdf
    • http://loaminoo.linkpc.net/8096099099095098/Heimliche-Sex-Treffen-mit-der-Schw-gerin-Erotik-by-Chris-L-rfert.pdf
    • http://loaminoo.linkpc.net/1090092098092093090/Heimliche-Begierde-Gest-ndnis-einer-Unbekannten-by-Daniela-M-ller.pdf
    • http://loaminoo.linkpc.net/8097096093090097/Hugo-der-Heimliche-Von-M-usen-und-Helden-by-Marco-Andreas-Zimmer.pdf
    • http://loaminoo.linkpc.net/1090099097094093090/Wir-Berliner-Prominente-ber-Prominente-33-x-Bewunderung-Staunen-heimliche-Liebe-by-Peter-Raue.pdf
    • http://loaminoo.linkpc.net/1090093093090094095/Hammer-Come-Down-by-Kae-Cheatham.pdf
    • http://loaminoo.linkpc.net/1090092099090091097/Baiae-Das-Erste-Luxusbad-Der-R-mer-I-Teil-Programm-Zum-Jahresberichte-Des-K-Neuen-Gymnasiums-in-Regensburg-F-r-Das-Studienjahr-1904-05-II-Teil-Programm-Zum-Jahresberichte-Des-K-Neuen-Gymnasiums-in-Regensburg-F-r-Das-Studienjahr-1905-06-by-Joseph-Schmatz.pdf
    • http://loaminoo.linkpc.net/1097090097099099/You-Don-t-Know-Me-You-Don-t-Know-Me-1-by-Mandy-Lee.pdf
    • http://loaminoo.linkpc.net/3092095092099092/The-Hammer-Of-God-by-Arthur-C-Clarke.pdf
    • http://loaminoo.linkpc.net/1095099097095097/The-Hammer-of-God-by-Arthur-C-Clarke.pdf
    • http://loaminoo.linkpc.net/4093095090092092/The-Hammer-The-General-2-by-S-M-Stirling.pdf
    • http://loaminoo.linkpc.net/9094091097096/The-Hammer-of-God-by-Arthur-C-Clarke.pdf
    • http://loaminoo.linkpc.net/4090092099099090/Deeper-Hammer-21-by-Sean-Michael.pdf