Malicious PDF — malware analysis report

Static analysis result for SHA-256 ac40378fb72f4dda…

MALICIOUS

PDF

26.1 KB Created: 2019-05-03 05:44:51 +01:00 Authoring application: mPDF 5.7
MD5: 159a712cfba2d87abcf2016f477319bd SHA-1: 927722fce2a52ff0285d304b9afeea938ee28e84 SHA-256: ac40378fb72f4dda4293d64ca13870ebaf37483fac7be88d8157a08847dbab0d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm, pointing to external PDF documents. While the URLs themselves are marked as benign, the sheer volume and the heuristic firing of PDF_SEO_LINK_FARM indicate a malicious intent to redirect users. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9908

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8099095096092097/From-Normandy-to-the-Ruhr-With-the-116th-Panzer-Division-in-World-War-II-by-Heinz-G-nther-Guderian.pdf
    • http://loaminoo.linkpc.net/8099095097096092/Panzer-Lightning-Heinz-Guderian-Hitler-s-Sword-by-James-Smithson.pdf
    • http://loaminoo.linkpc.net/8099095096092091/Heinz-Guderian-The-Life-and-Legacy-of-Nazi-Germany-s-Famous-Panzer-Commander-by-Charles-River-Editors.pdf
    • http://loaminoo.linkpc.net/9094090098095096/Panzer-Gunner-From-My-Native-Canada-to-the-German-Osfront-and-Back-In-Action-with-25th-Panzer-Regiment-7th-Panzer-Division-1944-45-by-Bruno-Friesen.pdf
    • http://loaminoo.linkpc.net/8099099091092092/Panzer-Wedge-Volume-Two-The-German-3rd-Panzer-Division-and-Barbarossa-s-Failure-at-the-Gates-of-Moscow-by-Fritz-Lucke.pdf
    • http://loaminoo.linkpc.net/9095091099095096/THE-EYES-OF-THE-DIVISION-THE-RECONNAISANCE-BATTALION-OF-THE-17-SS-PANZER-GRENADIER-DIVISION-GOTZ-VON-BERLICHINGEN-by-Helmut-Gunther.pdf
    • http://loaminoo.linkpc.net/8099095096091095/Guderian-Panzer-General-by-Kenneth-John-Macksey.pdf
    • http://loaminoo.linkpc.net/8098090097092094/Panzer-Lehr-Division-1944-45-by-Fred-Steinhardt.pdf
    • http://loaminoo.linkpc.net/8099095098091092/Flank-Defense-In-Far-Reaching-Operations-Illustrated-Edition-by-Heinz-Guderian.pdf
    • http://loaminoo.linkpc.net/9094090099090099/Death-Of-The-Leaping-Horseman-24th-Panzer-Division-In-Stalingrad-by-Jason-D-Mark.pdf
    • http://loaminoo.linkpc.net/8099096090092095/Operational-Tenets-Of-Generals-Heinz-Guderian-And-George-S-Patton-Jr-by-Major-George-A-Higgins.pdf
    • http://loaminoo.linkpc.net/9094090098099099/Panzer-Operations-Germany-s-Panzer-Group-3-During-the-Invasion-of-Russia-1941-by-Hermann-Hoth.pdf
    • http://loaminoo.linkpc.net/9094091091098092/Germany-s-Panzer-Arm-in-World-War-II-by-Richard-L-DiNardo.pdf
    • http://loaminoo.linkpc.net/1090092097096091/If-You-Survive-From-Normandy-to-the-Battle-of-the-Bulge-to-the-End-of-World-War-II-One-American-Officer-s-Riveting-True-Story-by-George-Wilson.pdf
    • http://loaminoo.linkpc.net/8091091091091099/Relationship-Between-Cohesion-and-Casualty-Rates-The-1st-Marine-Division-and-the-7th-Infantry-Division-at-Inchon-and-the-Chosin-Reservoir-by-Donald-K-Wols.pdf
    • http://loaminoo.linkpc.net/3098095096098098/Follow-Me-And-Die-The-Destruction-Of-An-American-Division-In-World-War-Ii-by-Cecil-B-Currey.pdf
    • http://loaminoo.linkpc.net/7099097090092090/St-Vith-Lion-in-the-Way-106th-Infantry-Division-in-World-War-II-by-R-Ernest-Dupuy.pdf
    • http://loaminoo.linkpc.net/4097090093097097/Patriarchy-and-Accumulation-on-a-World-Scale-Women-in-the-International-Division-of-Labour-by-Maria-Mies.pdf
    • http://loaminoo.linkpc.net/9094091090097093/Panzer-Tactics-German-Small-Unit-Armor-Tactics-in-World-War-II-by-Wolfgang-Schneider.pdf
    • http://loaminoo.linkpc.net/5094093098090099/Die-H-lle-An-Der-Ruhr-Rouletabille-Bei-Krupp-by-Gaston-Leroux.pdf
    • http://loaminoo.linkpc.net/8099099091092092/Panzer-Wedge-Volume-Two-The-German-3rd-Pa