Malicious PDF — malware analysis report

Static analysis result for SHA-256 7f0f4a8375fa2af2…

MALICIOUS

PDF

16.3 KB Created: 2019-05-02 18:57:46 +01:00 Authoring application: mPDF 5.7
MD5: 97452e63b27413132430f419d10f27e0 SHA-1: b653a78c06a0850ad0c41482c82b2a2b7367cdd4 SHA-256: 7f0f4a8375fa2af2edbca18d9cc2c056e5de610a1019a480c790c57b7488f79e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While most linked PDFs are marked as benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, possibly for SEO spam or to distribute further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6095096091096091/The-Port-Royal-grammar-General-and-rational-grammar-by-Claude-Lancelot.pdf
    • http://loaminoo.linkpc.net/9095091092093096/A-Royal-Compleat-Grammar-English-and-High-German-Das-Ist-Eine-K-nigliche-Vollkommene-Grammatica-in-Englisch-Und-Hochte-tscher-Sprach-Durch-John-King-by-Johann-Konig.pdf
    • http://loaminoo.linkpc.net/6092094095095092/Grammar-for-All-by-S-Kamel.pdf
    • http://loaminoo.linkpc.net/7098096099095092/A-New-Grammar-of-the-French-Language-by-E-Dubuc.pdf
    • http://loaminoo.linkpc.net/8095090094096098/The-Grammar-of-Ornament-by-Owen-Jones.pdf
    • http://loaminoo.linkpc.net/6099090096092096/German-Grammar-by-Liliane-Arnet.pdf
    • http://loaminoo.linkpc.net/6096099093092093/Grammar-Program-Communication-Workbook-by-Cle.pdf
    • http://loaminoo.linkpc.net/6096099093092098/Grammar-Text-Advanced-Level-by-Cle.pdf
    • http://loaminoo.linkpc.net/1091098094090094093/A-Sanskrit-Grammar-by-Maaike-Mulder.pdf
    • http://loaminoo.linkpc.net/6096099093093095/Grammar-Text-Introductory-Level-by-Cle.pdf
    • http://loaminoo.linkpc.net/8095093091097097/Grammar-Sense-2-With-Workbook-by-Cheryl-Pavlik.pdf
    • http://loaminoo.linkpc.net/1091098094090099094/A-Grammar-of-Epic-Sanskrit-by-Thomas-Oberlies.pdf
    • http://loaminoo.linkpc.net/2095092091090097/My-Grammar-and-I-Or-Should-That-Be-Me-How-to-Speak-and-Write-It-Right-by-Caroline-Taggart.pdf
    • http://loaminoo.linkpc.net/8091091091099096/Mastering-French-Grammar-by-Michael-Deneux.pdf
    • http://loaminoo.linkpc.net/1091092090094092092/Punjabi-Language-A-Descriptive-Grammar-by-N-I-Tolstaya.pdf
    • http://loaminoo.linkpc.net/4094099095090092/Essential-English-Grammar-by-Philip-Gucker.pdf
    • http://loaminoo.linkpc.net/1090093095095091090/Grammar-One-One-Pupil-s-Book-by-Jennifer-Seidl.pdf
    • http://loaminoo.linkpc.net/2097095097094090/The-Elements-of-Grammar-for-Writers-by-Robert-Funk.pdf
    • http://loaminoo.linkpc.net/7094097098093098/Spaces-Worlds-and-Grammar-by-Gilles-Fauconnier.pdf
    • http://loaminoo.linkpc.net/6093093096097090/Grammar-Express-with-Answer-Key-by-Marjorie-Fuchs.pdf
    • http://loaminoo.linkpc.net/60