Malicious PDF — malware analysis report

Static analysis result for SHA-256 82c7d89b2d8119fa…

MALICIOUS

PDF

25.8 KB Created: 2019-05-04 14:10:57 +01:00 Authoring application: mPDF 5.7
MD5: 9c46bb43e40724588815bb9137619e0c SHA-1: 2a5b970ea61bb6907c4751db379d8774d225221b SHA-256: 82c7d89b2d8119fa992946f9681a58a5021b30c50cf7cbc9b2ef0dd4748233cf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily corrupted, the presence of numerous links suggests a malicious intent, possibly for SEO manipulation or to distribute further malware. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091097092094093092/Paul-Ehrlich-Scientist-for-Life-by-Ernst-B-umler.pdf
    • http://loaminoo.linkpc.net/2092095099098096/The-Population-Bomb-by-Paul-R-Ehrlich.pdf
    • http://loaminoo.linkpc.net/9097096099091090/The-Dominant-Animal-Human-Evolution-and-the-Environment-by-Paul-R-Ehrlich.pdf
    • http://loaminoo.linkpc.net/1091090092092095098/Erinnerungen-an-Die-Schlacht-Bei-Wimpfen-Und-Den-Tod-Der-Vierhundert-Pforzheimer-Enthaltend-Die-Geschichte-Der-Schlacht-Von-Ernst-M-nch-Und-Die-Ged-chtni-rede-Auf-Die-Gefallenen-Von-Ernst-Ludwig-Posselt-by-Ernst-Munch.pdf
    • http://loaminoo.linkpc.net/9097097090096094/A-Life-Less-Stressed-the-five-pillars-of-health-and-wellness-by-Ron-Ehrlich.pdf
    • http://loaminoo.linkpc.net/1091090095092092098/What-is-Death-A-Scientist-Looks-at-the-Cycle-of-Life-by-Tyler-Volk.pdf
    • http://loaminoo.linkpc.net/6092096097092096/Ritter-Lanval-Lustspiel-in-Drei-Aufz-gen-by-Paul-Ernst.pdf
    • http://loaminoo.linkpc.net/6092091093095096/Jos-Rizal-Life-Works-and-Writings-of-a-Genius-Writer-Scientist-and-National-Hero-by-Gregorio-F-Zaide.pdf
    • http://loaminoo.linkpc.net/8098092090094092/The-Labyrinth-of-Exile-A-Life-of-Theodor-Herzl-by-Ernst-Pawel.pdf
    • http://loaminoo.linkpc.net/4092090091093094/The-Sundance-Kid-The-Life-of-Harry-Alonzo-Longabaugh-by-Donna-B-Ernst.pdf
    • http://loaminoo.linkpc.net/8094091096091091/Pauli-Ernesti-Iablonski-de-Memnone-Graecorum-Et-Aegyptiorum-Huiusque-Celeberrima-in-Thebaide-Statua-Syntagmata-III-Cum-Figuris-Aeneis-by-Paul-Ernst-Jablonski.pdf
    • http://loaminoo.linkpc.net/8096097096099091/Max-Ernst-Skulpturen-Hauser-Landschaften-by-Max-Ernst.pdf
    • http://loaminoo.linkpc.net/1090096091090091095/Members-Only-The-Life-and-Times-of-Paul-Raymond-Soho-s-Billionaire-King-of-Burlesque-by-Paul-Willetts.pdf
    • http://loaminoo.linkpc.net/9093093090097090/Humanistische-Paedagogik-Anspruch-Moeglichkeiten-Und-Gefaehrdungen-Am-Ausgang-Des-20-Jahrhunderts-Festschrift-Zum-68-Geburtstag-Von-Ernst-Hojer-by-Ernst-Hojer.pdf
    • http://loaminoo.linkpc.net/9097097090095098/Steven-Ehrlich-Houses-by-Steven-Ehrlich.pdf
    • http://loaminoo.linkpc.net/4095097091099/John-Quincy-Adams-A-Public-Life-a-Private-Life-by-Paul-C-Nagel.pdf
    • http://loaminoo.linkpc.net/7099092092092/Mormon-Scientist-The-Life-and-Faith-of-Henry-Eyring-by-Henry-J-Eyring.pdf
    • http://loaminoo.linkpc.net/8097095090099094/Paul-Klee-Life-and-Work-by-Bern-Zentrum-Paul-Klee.pdf
    • http://loaminoo.linkpc.net/1091092092091092094/Ernst-Ulrich-Von-Weizsacker-A-Pioneer-on-Environmental-Climate-and-Energy-Policies-by-Ernst-Ulrich-Weizsacker.pdf
    • http://loaminoo.linkpc.net/6096095099098095/The-Moon-and-Sixpence-One-Man-s-Journey-Across-the-Field-of-Art-and-into-Its-Depths-Based-on-the-Life-of-Paul-Gauguin-Biographical-Novel-based-on-the-of-the-famous-French-painter-Paul-Gauguin-by-W-Somerset-Maugham.pdf
    • http://loaminoo.linkpc.net/60920960970920