Malicious PDF — malware analysis report

Static analysis result for SHA-256 841201cbffbaf13a…

MALICIOUS

PDF

21.3 KB Created: 2019-05-02 18:32:33 +01:00 Authoring application: mPDF 5.7
MD5: d5e0a952d6baaf886738daaaa0463c5d SHA-1: c8a0a9d94d195a8b430e02975752dc9dfbae38d4 SHA-256: 841201cbffbaf13a137ec09aec1ede077aa6d695177c0aa25da03645a9859581
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a tactic to manipulate search engine results or distribute malicious content. While no scripts were extracted, the embedded URLs themselves are the primary indicators of malicious intent, likely serving as a lure or a distribution mechanism. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9900

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090091096092093095/Ein-Jahr-in-der-Toskana-Reise-in-den-Alltag-by-Andrea-Thiele.pdf
    • http://loaminoo.linkpc.net/9099096092095095/Ein-Jahr-in-Wien-Reise-in-den-Alltag-by-Tonja-P-litz.pdf
    • http://loaminoo.linkpc.net/1090090094094091092/Ein-Jahr-in-Amsterdam-Reise-in-den-Alltag-by-Bettina-Baltschev.pdf
    • http://loaminoo.linkpc.net/1090090094096090098/Ein-Jahr-in-Tel-Aviv-Reise-in-den-Alltag-by-Christiane-Wirtz.pdf
    • http://loaminoo.linkpc.net/1090091096091093099/Ein-Jahr-in-Norwegen-Reise-in-den-Alltag-by-Julia-Fellinger.pdf
    • http://loaminoo.linkpc.net/1090090094094092091/Ein-Jahr-in-Istanbul-Reise-in-den-Alltag-by-Cornelia-Tomerius.pdf
    • http://loaminoo.linkpc.net/1090090094094096099/Ein-Jahr-in-Peking-Reise-in-den-Alltag-by-Katharina-Rutz.pdf
    • http://loaminoo.linkpc.net/1090090094094096091/Ein-Jahr-in-Tokio---Reise-in-den-Alltag-by-Julia-Berger.pdf
    • http://loaminoo.linkpc.net/1090090094094096093/Ein-Jahr-in-Neuseeland-Reise-in-den-Alltag-by-Anja-Sch-nborn.pdf
    • http://loaminoo.linkpc.net/1090091096091094095/Ein-Jahr-in-S-dafrika-Reise-in-den-Alltag-HERDER-spektrum-by-Kristina-Maroldt.pdf
    • http://loaminoo.linkpc.net/1090091097095093094/Reise-in-die-Toskana-Kulturkompass-f-rs-Handgep-ck-by-Manfred-G-rgens.pdf
    • http://loaminoo.linkpc.net/1091095092099092091/Liebesreise-in-die-Toskana-Verzaubert-in-Florenz-Verwechslungsspiel-in-der-Toskana-Eine-italienische-Hochzeit-by-Lucy-Gordon.pdf
    • http://loaminoo.linkpc.net/1090098096090098096/Golos-Reise-by-Andrea-Brockmeyer.pdf
    • http://loaminoo.linkpc.net/8097098092095090/Reise-Der-Russisch-Kaiserlichen-Ausserordentlichen-Gesandtschaft-an-Die-Othomanische-Pforte-Im-Jahr-1793-Vol-1-of-3-Vertrauter-Briefe-Eines-Ehstl-nders-an-Einen-Seiner-Freunde-in-Reval-by-Heinrich-Christoph-Von-Reimers.pdf
    • http://loaminoo.linkpc.net/8096092098098098/Gullivers-Reisen-Reise-nach-Lilliput-Reise-nach-Brobdingnag-Reise-nach-Laputa-Reise-in-das-Land-der-Hauyhnhnms---Vollst-ndige-deutsche-Ausgabe-von-Jonathan-Swift-by-Jonathan-Swift.pdf
    • http://loaminoo.linkpc.net/8099096093099097/Ein-Garten-in-der-Toskana-by-Teresa-Crane.pdf
    • http://loaminoo.linkpc.net/1091096092097092094/Kalenderblatt-zum-Jahr-1932-Der-quot-Br-ningtaler-quot-von-1932-dem-letzten-Jahr-vor-der-faschistischen-Diktatur-Der-Vatikanstaat-vorgestellt-durch-5-Lire-von-1932-by-Joachim-Bonatz.pdf
    • http://loaminoo.linkpc.net/4098097092096090/Storm-Boy-by-Colin-Thiele.pdf
    • http://loaminoo.linkpc.net/2092093093094093/Danny-s-Egg-by-Colin-Thiele.pdf
    • http://loaminoo.linkpc.net/1091098097093097099/Playing-a-Blinder-by-Steve-Thiele.pdf