Malicious PDF — malware analysis report

Static analysis result for SHA-256 7cd5eb9bb919e6e3…

MALICIOUS

PDF

26.0 KB Created: 2019-05-02 14:48:58 +01:00 Authoring application: mPDF 5.7
MD5: e36f38a254bbf41a84fd98e4adffedd9 SHA-1: db34ad7bf0938d17804899fb17c3316c2a9e15ca SHA-256: 7cd5eb9bb919e6e3838fc8e2071c023499c9dbfff723c4134936c82658e04daf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a malicious intent to manipulate search engine results or distribute further content. While the specific URLs appear benign, the sheer volume and the ML classifier's high confidence indicate a suspicious pattern. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9908

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3098094099092091/Eva-s-Story-A-Survivor-s-Tale-by-the-Step-Sister-of-Anne-Frank-by-Eva-Schloss.pdf
    • http://loaminoo.linkpc.net/1090091091096094092/Schloss-in-Schweden-Schloss-Gripsholm-Schloss-Venngarn-Stockholmer-Schloss-Schloss-Drottningholm-Schloss-Svartsjo-Schloss-Lacko-by-Quelle-Wikipedia.pdf
    • http://loaminoo.linkpc.net/1090098092092098096/Schloss-in-Wien-Schloss-Schonbrunn-Hofburg-Schloss-Neugebaude-Schloss-Belvedere-Schloss-Hetzendorf-Schloss-Laudon-Schloss-Rodaun-by-Books-LLC.pdf
    • http://loaminoo.linkpc.net/1091093095099094093/Romana-Gold-Band-11-Das-verwunschene-Schloss-Sommertage-in-Schottland-Ein-Schloss-nur-f-r-uns-by-Anne-Mather.pdf
    • http://loaminoo.linkpc.net/6094098094094097/Anne-Frank-The-Story-of-a-Young-Girl-Simplified-Characters-by-Anne-Frank.pdf
    • http://loaminoo.linkpc.net/3095099090096094/Holocaust-Memoirs-by-a-Bergen-Belsen-survivor-amp-Classmate-of-Anne-Frank-by-Nanette-Blitz-Konig.pdf
    • http://loaminoo.linkpc.net/4090099090092/Anne-Frank-Remembered-The-Story-of-the-Woman-Who-Helped-to-Hide-the-Frank-Family-by-Miep-Gies.pdf
    • http://loaminoo.linkpc.net/3099091092091093/Anne-Frank-Remembered-The-Story-of-the-Woman-Who-Helped-to-Hide-the-Frank-Family-by-Miep-Gies.pdf
    • http://loaminoo.linkpc.net/6092092092099097/One-Survivor-s-Guide-for-Beating-Depression-and-Thriving-Thereafter-Simple-Practical-Step-by-Step-Remedies-for-the-Illness-of-Depression-by-Nima-Fard.pdf
    • http://loaminoo.linkpc.net/1091091092094094096/Anne-Frank-s-Tales-from-the-Secret-Annex-A-Collection-of-Her-Short-Stories-Fables-and-Lesser-Known-Writings-by-Anne-Frank.pdf
    • http://loaminoo.linkpc.net/2092099093093097/Anne-Frank-s-Story-by-Carol-Ann-Lee.pdf
    • http://loaminoo.linkpc.net/2092099090095094/Anne-Frank-Her-life-in-words-and-pictures-from-the-archives-of-The-Anne-Frank-House-by-Menno-Metselaar.pdf
    • http://loaminoo.linkpc.net/4094094095090099/Anne-Frank-The-Anne-Frank-House-Authorized-Graphic-Biography-by-Sid-Jacobson.pdf
    • http://loaminoo.linkpc.net/3097091091096091/Anne-Frank-The-Diary-of-a-Young-Girl-The-Definitive-Edition-by-Anne-Frank.pdf
    • http://loaminoo.linkpc.net/2092099095099092/Anne-Frank-House-A-Museum-With-A-Story-by-Hansje-Galesloot.pdf
    • http://loaminoo.linkpc.net/2092093091094094/Inside-Anne-Frank-s-House-An-Illustrated-Journey-Through-Anne-s-World-by-Anne-Frank-House.pdf
    • http://loaminoo.linkpc.net/9092097090092095/Diary-of-Anne-Frank-in-Dari-Persian-or-Farsi-by-Anne-Frank.pdf
    • http://loaminoo.linkpc.net/1091094090094099098/The-True-Story-of-Pocahontas-Step-Into-Reading-Step-3-by-Lucille-Recht-Penner.pdf
    • http://loaminoo.linkpc.net/1090090097095099098/Evas-Geschichte-Anne-Franks-Stiefschwester-und-berlebende-von-Auschwitz-erz-hlt-by-Eva-Schloss.pdf
    • http://loaminoo.linkpc.net/9091090098093099/Schloss-in-Brandenburg-Schloss-in-Potsdam-Sanssouci-Orangerieschloss-Stadtschloss-Jagdschloss-Stern-Neues-Palais-by-Quelle-Wikipedia.pdf
    • http://loaminoo.linkpc.net/6094098094094097/Anne-Frank-The-Story-