Malicious PDF — malware analysis report

Static analysis result for SHA-256 a2e5e662035f1f99…

MALICIOUS

PDF

19.5 KB Created: 2019-04-30 04:07:44 +01:00 Authoring application: mPDF 5.7
MD5: 2bdcc464c75d6acdcca2c3983a6ba73f SHA-1: 9499801ca5ac40993fc404df45111f908ebefe4d SHA-256: a2e5e662035f1f99b3b0bdf51cc759a4f78745bdded9d8a9bd27b90182ead69e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing:Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the PDF structure and embedded URLs suggest a phishing or content distribution attack. The primary attack pattern involves a link farm designed to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3097091091096091/Anne-Frank-The-Diary-of-a-Young-Girl-The-Definitive-Edition-by-Anne-Frank.pdf
    • http://loaminoo.linkpc.net/2092099093092095/Anne-Frank-the-Diary-of-a-Young-Girl-by-M-E-Blau.pdf
    • http://loaminoo.linkpc.net/2092099095096096/Anne-Frank-The-Diary-of-a-Young-Girl-by-Marcia-Tretler.pdf
    • http://loaminoo.linkpc.net/2092099094095096/Anne-Frank-Diary-of-a-Young-Girl-by-Myrna-Warren.pdf
    • http://loaminoo.linkpc.net/2092099094093095/Anne-Frank-s-The-Diary-of-a-Young-Girl-Monarch-Notes-by-Eugenie-Harris.pdf
    • http://loaminoo.linkpc.net/6094098094094097/Anne-Frank-The-Story-of-a-Young-Girl-Simplified-Characters-by-Anne-Frank.pdf
    • http://loaminoo.linkpc.net/9092097090092095/Diary-of-Anne-Frank-in-Dari-Persian-or-Farsi-by-Anne-Frank.pdf
    • http://loaminoo.linkpc.net/6093096094094091/The-Diary-of-Anne-Frank-by-Anne-Frank.pdf
    • http://loaminoo.linkpc.net/4094092097091096/Anne-Frank-s-Diary-The-Graphic-Novel-by-Ari-Folman.pdf
    • http://loaminoo.linkpc.net/9090093097095099/Reading-the-Diary-of-Anne-Frank-by-Neil-Heims.pdf
    • http://loaminoo.linkpc.net/2093092090098/The-Diary-of-Anne-Frank-And-Related-Readings-by-Frances-Goodrich.pdf
    • http://loaminoo.linkpc.net/6093097098099094/There-We-ll-Meet-Again-Young-German-Girl-s-Diary-of-the-First-World-War-by-Piete-Kuhr.pdf
    • http://loaminoo.linkpc.net/2095092092091098/Young-Nanny-A-Victorian-Girl-s-Diary-1850-by-Frances-Mary-Hendry.pdf
    • http://loaminoo.linkpc.net/1091091092094094096/Anne-Frank-s-Tales-from-the-Secret-Annex-A-Collection-of-Her-Short-Stories-Fables-and-Lesser-Known-Writings-by-Anne-Frank.pdf
    • http://loaminoo.linkpc.net/2092099090095094/Anne-Frank-Her-life-in-words-and-pictures-from-the-archives-of-The-Anne-Frank-House-by-Menno-Metselaar.pdf
    • http://loaminoo.linkpc.net/4094094095090099/Anne-Frank-The-Anne-Frank-House-Authorized-Graphic-Biography-by-Sid-Jacobson.pdf
    • http://loaminoo.linkpc.net/9094097097092/Coming-of-Age-in-Mississippi-The-Classic-Autobiography-of-a-Young-Black-Girl-in-the-Rural-South-by-Anne-Moody.pdf
    • http://loaminoo.linkpc.net/2092099096094097/The-Stolen-Legacy-of-Anne-Frank-Meyer-Levin-Lillian-Hellman-amp-the-Shaping-of-the-quot-Diary-quot-by-Ralph-Melnick.pdf
    • http://loaminoo.linkpc.net/2092093091094094/Inside-Anne-Frank-s-House-An-Illustrated-Journey-Through-Anne-s-World-by-Anne-Frank-House.pdf
    • http://loaminoo.linkpc.net/4094090092092090/Anne-Frank-In-The-World-1929-1945-De-Wereld-Van-Anne-Frank-1929-1945-by-Joke-Kniesmeyer.pdf