Malicious PDF — malware analysis report

Static analysis result for SHA-256 aee981d4e4a91a23…

MALICIOUS

PDF

24.3 KB Created: 2019-05-02 06:48:46 +01:00 Authoring application: mPDF 5.7
MD5: 2fe670510904c1ba7cb49a128e6842b3 SHA-1: a258b297ce3acca66fa98284e983be8f84c170d1 SHA-256: aee981d4e4a91a23f91b0e2e4c2199a858fb32998b06b449077edbd74b2131a2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links appear benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO manipulation or to redirect users to malicious sites. No scripts were extracted, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7092098090096091/The-Future-of-Australian-Multiculturalism-Reflections-on-the-Twentieth-Anniversary-of-Jean-Martin-s-the-Migrant-Presence-by-Ghassan-Hage.pdf
    • http://loaminoo.linkpc.net/1098096094098099/Coo-ee-Tales-of-Australian-Life-by-Australian-Ladies-by-Harriet-Anne-Patchett-Martin.pdf
    • http://loaminoo.linkpc.net/9099097094098095/Aussie-Migrant-Jobs-A-Migrant-s-Essential-Guide-to-Employment-in-Australia-Migrant-Ninja-Series-Book-2-by-Jason-Rebello.pdf
    • http://loaminoo.linkpc.net/4097094097098097/The-Passions-and-the-Interests-Political-Arguments-for-Capitalism-Before-Its-Triumph---Twentieth-Anniversary-Edition-by-Albert-O-Hirschman.pdf
    • http://loaminoo.linkpc.net/1093092099090093/Reappraisals-Reflections-on-the-Forgotten-Twentieth-Century-by-Tony-Judt.pdf
    • http://loaminoo.linkpc.net/6092095096093099/Jean-Our-Little-Australian-Cousin-by-Mary-F-Nixon-Roulet.pdf
    • http://loaminoo.linkpc.net/7091097098096091/Practicing-the-Presence-of-the-Living-God-A-Retreat-with-Brother-Lawrence-of-the-Resurrection-by-Jean-Maalouf.pdf
    • http://loaminoo.linkpc.net/7092093094099096/The-Future-of-a-Negation-Reflections-on-the-Question-of-Genocide-by-Alain-Finkielkraut.pdf
    • http://loaminoo.linkpc.net/5095094098098/Twentieth-Centuries-by-Jean-Marc-Desgent.pdf
    • http://loaminoo.linkpc.net/2092092096099092/Rediscovering-God-in-America-Reflections-on-the-Role-of-Faith-in-Our-Nation-s-History-and-Future-by-Newt-Gingrich.pdf
    • http://loaminoo.linkpc.net/7091097098097093/Jesus-Laughed-And-Other-Reflections-on-Being-Human-by-Jean-Maalouf.pdf
    • http://loaminoo.linkpc.net/5092090090090/Who-Are-We-Critical-Reflections-and-Hopeful-Possibilities-by-Jean-Bethke-Elshtain.pdf
    • http://loaminoo.linkpc.net/9093095099096099/Reflections-on-American-Music-The-Twentieth-Century-and-the-New-Millennium-A-Collection-of-Essays-Presented-in-Honor-of-the-College-Music-Society-Cms-Bibliographies-in-American-Music-No-16-by-Michael-Benton-Saffle.pdf
    • http://loaminoo.linkpc.net/6096092094094093/Humanly-possible-a-biologist-s-notes-on-the-future-of-mankind-by-Jean-Rostand.pdf
    • http://loaminoo.linkpc.net/1096090099090098/The-Shifts-and-the-Shocks-How-the-Financial-Crisis-Has-Changed-Our-Future-by-Martin-Wolf.pdf
    • http://loaminoo.linkpc.net/7092092094094097/Europe-s-Orphan-The-Future-of-the-Euro-and-the-Politics-of-Debt-by-Martin-Sandbu.pdf
    • http://loaminoo.linkpc.net/9091096099098099/M-nner-in-der-Sonne-by-Ghassan-Kanafani.pdf
    • http://loaminoo.linkpc.net/7092097099096095/Bukhari-by-Ghassan-Abdul-Jabbar.pdf
    • http://loaminoo.linkpc.net/3098095096098099/The-Oxford-History-of-the-British-Empire-Volume-IV-The-Twentieth-Century-Twentieth-Century-Vol-4-by-Judith-M-Brown.pdf
    • http://loaminoo.linkpc.net/4092095090091097/Welcome-Home-by-William-Hage.pdf
    • http://loaminoo.linkpc.net/4097094097098097/The-Passions-and-the-Interests-Political-Arguments-for-Capitalism-Before-It