Malicious PDF — malware analysis report

Static analysis result for SHA-256 a38b0f3121f2a0d3…

MALICIOUS

PDF

16.5 KB Created: 2019-05-02 17:29:51 +01:00 Authoring application: mPDF 5.7
MD5: 1a8bdb8bd860588563daca0d96e7ff21 SHA-1: dfbac559c6d22e5430f7f163f183939aa48d33f4 SHA-256: a38b0f3121f2a0d38fc87b5da4b63b911fafec86e058ce84658e313392672c9e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly flagged this PDF as malicious. The embedded URLs point to a domain that appears to be hosting a link farm, suggesting a coordinated effort to direct traffic or deliver payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090098094091093091/The-Siege-of-Leningrad-900-Days-of-Terror-by-David-M-Glantz.pdf
    • http://loaminoo.linkpc.net/6095098092097/The-900-Days-The-Siege-of-Leningrad-by-Harrison-E-Salisbury.pdf
    • http://loaminoo.linkpc.net/2092099097099090/Leningrad-State-of-Siege-by-Michael-Jones.pdf
    • http://loaminoo.linkpc.net/1097091096/Symphony-for-the-City-of-the-Dead-Dmitri-Shostakovich-and-the-Siege-of-Leningrad-by-M-T-Anderson.pdf
    • http://loaminoo.linkpc.net/5091099099091096/When-Titans-Clashed-How-the-Red-Army-Stopped-Hitler-by-David-M-Glantz.pdf
    • http://loaminoo.linkpc.net/1092097091092092/Dying-Days-Siege-1-And-2-Set-by-Armand-Rosamilia.pdf
    • http://loaminoo.linkpc.net/3097095095090090/Drinking-the-Sea-at-Gaza-Days-and-Nights-in-a-Land-Under-Siege-by-Amira-Hass.pdf
    • http://loaminoo.linkpc.net/1091091090096097096/Meine-Kindheit-im-zweiten-Weltkrieg-Nazi-Terror-Bomben-Terror-Todes-ngste-Wohnungsnot-Hungersnot-Alliierten-Terror-by-Dieter-Schulz.pdf
    • http://loaminoo.linkpc.net/1090091098094095096/Terror-Tantchen-by-David-Walliams.pdf
    • http://loaminoo.linkpc.net/4098093099095090/Fecal-Terror-by-David-Bernstein.pdf
    • http://loaminoo.linkpc.net/1093093092099092/Get-Your-War-On-The-Definitive-Account-of-the-War-on-Terror-2001-2008-by-David-Rees.pdf
    • http://loaminoo.linkpc.net/1090098094091092095/All-My-Friends-Are-Engaged-by-Jen-Glantz.pdf
    • http://loaminoo.linkpc.net/2093098096098097/Tobacco-War-Inside-the-California-Battles-by-Stanton-A-Glantz.pdf
    • http://loaminoo.linkpc.net/1097096097091095/Six-Earlier-Days-Every-Day-0-5-by-David-Levithan.pdf
    • http://loaminoo.linkpc.net/5093090095095/The-Madonnas-of-Leningrad-by-Debra-Dean.pdf
    • http://loaminoo.linkpc.net/8099095098090097/Moscow-and-Leningrad-by-Martin-H-rlimann.pdf
    • http://loaminoo.linkpc.net/7094094093098/The-Madonnas-of-Leningrad-by-Debra-Dean.pdf
    • http://loaminoo.linkpc.net/6096096098090098/David-Schubert-Works-amp-Days-by-John-Ashbery.pdf
    • http://loaminoo.linkpc.net/2091098091095/Lenin-s-Tomb-The-Last-Days-of-the-Soviet-Empire-by-David-Remnick.pdf
    • http://loaminoo.linkpc.net/7099090091090097/Leningrad-Mathematical-Olympiads-1987-1991-by-Dmitri-Fomin.pdf
    • http://loaminoo.linkpc.net/1091091090096097096/Meine-Kindheit-im-zweiten-Weltkrieg-Nazi-Terror-Bomben-Terror-Todes-n