Malicious PDF — malware analysis report

Static analysis result for SHA-256 a78f73a8fe901fbf…

MALICIOUS

PDF

13.5 KB Created: 2019-05-01 13:03:27 +01:00 Authoring application: mPDF 5.7
MD5: a655d1c3255298773e23907d83d40c5b SHA-1: d0b6a1619976d67ddd454d9151395045e86a9a31 SHA-256: a78f73a8fe901fbff2c28fe807e0f3d22909b29f764d0dc84abb5e1ae6a445a8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, forming a link farm. The ML classifier flagged this PDF as malicious with a high probability. The primary attack pattern involves directing users to external content, likely for further exploitation or to host malicious payloads. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8721

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8097090095094098/Tilman-Riemenschneider-Master-Sculptor-Of-The-Late-Middle-Ages-by-Tilman-Riemenschneider.pdf
    • http://loaminoo.linkpc.net/8097090095095092/Triumph-and-Tribulation-by-H-W-Tilman.pdf
    • http://loaminoo.linkpc.net/8097090094099091/Nepal-Himalaya-by-H-W-Tilman.pdf
    • http://loaminoo.linkpc.net/8097090094092091/Tilman-Riemenschneider-by-Art-Stock.pdf
    • http://loaminoo.linkpc.net/8097090093093096/Lenin-s-Brain-by-Tilman-Spengler.pdf
    • http://loaminoo.linkpc.net/8097090094099093/Beethoven-the-Pianist-by-Tilman-Skowroneck.pdf
    • http://loaminoo.linkpc.net/8097090095094093/Fourier-Transformation-for-Pedestrians-by-Tilman-Butz.pdf
    • http://loaminoo.linkpc.net/9097096098098093/Gay-Hardcore-06-Schussbereite-Kerle-by-Tilman-Janus.pdf
    • http://loaminoo.linkpc.net/8097090094098099/An-Introduction-to-the-Theory-of-Mechanism-Design-by-Tilman-Borgers.pdf
    • http://loaminoo.linkpc.net/8097090093093095/The-Last-Hero-Bill-Tilman-a-Biography-of-the-Explorer-by-Tim-Madge.pdf
    • http://loaminoo.linkpc.net/8097090094098092/Southeast-Asian-Independent-Cinema-by-Tilman-Baumgartel.pdf
    • http://loaminoo.linkpc.net/9097097091090092/Klasse-Kerle-2-Sweet-Boys-5-by-Tilman-Janus.pdf
    • http://loaminoo.linkpc.net/8099092099099095/Die-K-nige-von-K-ln-Historischer-Roman-by-Tilman-R-hrig.pdf
    • http://loaminoo.linkpc.net/8097090094099094/Sharpshooter-The-Life-and-Times-of-Tilman-Manus-by-Keith-Pruitt-Ed-S.pdf
    • http://loaminoo.linkpc.net/9097097090091096/Klasse-Kerle-Sweet-Boys-3-German-Edition-by-Tilman-Janus.pdf
    • http://loaminoo.linkpc.net/6092096094094095/Chaos-im-Kinderzimmer-Drei-turbulente-Geschichten-in-einem-Band-by-Tilman-R-hrig.pdf
    • http://loaminoo.linkpc.net/1090095093096090091/Erik-der-Rote-oder-die-Suche-nach-dem-Gl-ck-Historischer-Roman-by-Tilman-R-hrig.pdf
    • http://loaminoo.linkpc.net/9097096095090092/Industrial-Policy-in-Developing-Countries-Failing-Markets-Weak-States-by-Tilman-Altenburg.pdf
    • http://loaminoo.linkpc.net/8097090094093094/-quot-Mischief-quot-in-Patagonia-by-H-W-Tilman.pdf