Malicious PDF — malware analysis report

Static analysis result for SHA-256 9ed5aaae262f6953…

MALICIOUS

PDF

23.5 KB Created: 2019-04-30 02:37:36 +01:00 Authoring application: mPDF 5.7
MD5: 10a0329532ddb49d96fbe0c5a1f1d163 SHA-1: 6dadae487d1f4c15994a982848fd041b25c43754 SHA-256: 9ed5aaae262f69531eec663316f3e29b50d8c68243f3671985328c42aff6567e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded URLs, forming a link farm. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of numerous external links, suggesting a potential SEO poisoning or traffic redirection scheme. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091092099099099099/LEGO-Galaxy-Build-Your-Own-Universe-by-Joachim-Klang.pdf
    • http://loaminoo.linkpc.net/4097099090092093/legomath-box-3-in-1-set-lego-fractions---lego-addition-and-subtraction-and-lego-multiplcation-lego-math-Book-4-by-ZACH-ABRAHAM.pdf
    • http://loaminoo.linkpc.net/6098096099097092/Collection-of-five-4--and-8-Wheel-Reefer-Wagons-Lego-MOC-building-instructions-Lego-Train-MOC-plans-Book-6-by-E-Chaton.pdf
    • http://loaminoo.linkpc.net/6098097090090092/Collection-of-six-4--and-8-Wheel-Stake-Wagons-Lego-MOC-building-instructions-Lego-Train-MOC-Plans-Book-2-by-E-Chaton.pdf
    • http://loaminoo.linkpc.net/6098096099099095/4-Wheel-and-8-Wheel-Tank-Wagons-Lego-MOC-building-instructions-Lego-Train-MOC-Plans-Book-1-by-E-Chaton.pdf
    • http://loaminoo.linkpc.net/5094097097095/How-To-Build-a-Pallet-and-Plastic-Bottle-Greenhouse-from-Junk-A-Self-Build-Project-by-Eco-T-.pdf
    • http://loaminoo.linkpc.net/9098094095093095/Smart-People-Should-Build-Things-How-to-Restore-Our-Culture-of-Achievement-Build-a-Path-for-Entrepreneurs-and-Create-New-Jobs-in-America-by-Andrew-Yang.pdf
    • http://loaminoo.linkpc.net/8091091091099091/TouchThinkLearn-Vehicles-by-Xavier-Deneux.pdf
    • http://loaminoo.linkpc.net/1091094093092098097/Deutsche-Passagier-Luftfahrt-Von-1955-Bis-Heute-Joachim-Wolfer-by-Joachim-Wolfer.pdf
    • http://loaminoo.linkpc.net/9091095094093098/Time-Critical-Cooperative-Control-of-Autonomous-Air-Vehicles-by-Isaac-Kaminer.pdf
    • http://loaminoo.linkpc.net/5091097096090098/The-Carriage-Trade-Making-Horse-Drawn-Vehicles-in-America-by-Thomas-A-Kinney.pdf
    • http://loaminoo.linkpc.net/7093093098/The-Sky-Is-Yours-by-Chandler-Klang-Smith.pdf
    • http://loaminoo.linkpc.net/1091093090091092095/Klang-der-Finsternis---Into-the-dusk-2-by-Ela-van-de-Maan.pdf
    • http://loaminoo.linkpc.net/1091093090092090093/Dick-Master-Leatherland-Under-Attack-by-Roy-Klang.pdf
    • http://loaminoo.linkpc.net/7094092097098095/Joachim-Du-Bellay-The-Regrets-quot-with-quot-the-Antiquities-of-Rome-quot-Three-Latin-Elegies-and-quot-the-Defense-and-Enrichment-of-the-French-Language-quot-a-Bilingual-Edition-university-of-Pennsylvania-Press-bb-09-12-2006-lco003000-12-75-00-ip-short-01-01-by-Joachim-Du-Bellay.pdf
    • http://loaminoo.linkpc.net/8096099097092096/Der-Klang-von-Regen-Seasons-of-Love-2-by-Petra-R-der.pdf
    • http://loaminoo.linkpc.net/4095095096090091/Goldenland-Past-Dark-by-Chandler-Klang-Smith.pdf
    • http://loaminoo.linkpc.net/8093093090093093/Unendlicher-Klang-Das-Mysterium-der-Obert-ne-by-Michael-Reimann.pdf
    • http://loaminoo.linkpc.net/1090099099093091095/I-Lego-N-Y-by-Christoph-Niemann.pdf
    • http://loaminoo.linkpc.net/1091093090095094097/Klang-Twenty-Centuries-of-Eventful-Existence-by-Mubin-Sheppard.pdf
    • http://loaminoo.linkpc.net/6098096099099095/4-Wheel-and-8-Wheel-Tank-Wagons-Lego-MOC-building-instructions-Lego-Train-MOC-Plans-Book-1-by-E-