Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca9c2af692bff3d6…

MALICIOUS

PDF

24.3 KB Created: 2019-05-01 19:17:34 +01:00 Authoring application: mPDF 5.7
MD5: 1b540c91416d4b3ad84421de5f25cd36 SHA-1: 9f4f1a40f4a25753b6469378a3144d2e0520389f SHA-256: ca9c2af692bff3d65a57b65176efeb6a795f1706111473fcb74bd816ed8ad182
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the PDF structure and link farm heuristic suggest a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090099099095091093/Das-Einsteigerseminar-Objektorientierte-Programmierung-In-Java-Der-Methodische-Und-Ausf-hrliche-Einstieg-400-Seiten-Einsteiger-Know-How-by-Alexander-Niemann.pdf
    • http://loaminoo.linkpc.net/4095092093096094/Das-Einsteigerseminar-Internet-Information-Server-5-Der-Methodische-Und-Ausfu-hrliche-Einstieg-U-ber-300-Seiten-Einsteiger-Know-How-by-G-nther-Karl.pdf
    • http://loaminoo.linkpc.net/7096098095094099/Java-kompakt-Eine-Einf-hrung-in-die-Software-Entwicklung-mit-Java-by-Matthias-H-lzl.pdf
    • http://loaminoo.linkpc.net/6099094095094099/PROGRAMMER-EN-JAVA-6E-DITION-JAVA-5-ET-6-by-Claude-Delannoy.pdf
    • http://loaminoo.linkpc.net/9093094098095099/seiten-1-souseiki-youreisyou-seiten-youreisyou-by-nenashigusa-nora.pdf
    • http://loaminoo.linkpc.net/9098091096094097/Ausf-hrliches-Lehrbuch-Der-Stereometrie-Und-Sph-rischen-Trigonometrie-Vol-1-of-2-Zum-Gebrauch-an-H-heren-Lehranstalten-Und-Zum-Selbststudium-Von-Der-Lage-Der-Linien-Und-Ebenen-Im-Raume-Von-Den-K-rperlichen-Ecken-by-H-Servus.pdf
    • http://loaminoo.linkpc.net/1091098098096098097/Gute-Bucher-Auswahlkriterien-Fur-Problemorientierte-Kinderliteratur-Didaktische-Und-Methodische-Hinweise-Fur-Die-Arbeit-in-Der-Gr-by-Doro-Hoffmann.pdf
    • http://loaminoo.linkpc.net/1091092097096090099/Der-leichte-Einstieg-in-die-Elektronik-by-Bo-Hanus.pdf
    • http://loaminoo.linkpc.net/9093099097099098/Lightroom-5-Der-Einstieg-f-r-Fotografen-by-Michael-Gradias.pdf
    • http://loaminoo.linkpc.net/6097096096094097/Raspberry-Pi-Einstieg-Optimierung-Projekte-by-Maik-Schmidt.pdf
    • http://loaminoo.linkpc.net/1090090097098094098/Perfekte-Fotos-mit-System-Der-Praxisleitfaden-f-r-Einsteiger-und-Fortgeschrittene-by-Roberto-Valenzuela.pdf
    • http://loaminoo.linkpc.net/1091093093092094093/Einstieg-in-Python-Ideal-f-r-Programmieranf-nger-geeignet-by-Thomas-Theis.pdf
    • http://loaminoo.linkpc.net/1091099095099099093/Excel-2016---Basiswissen-F-r-Einsteiger-Leicht-verst-ndlich---komplett-in-Farbe-by-Inge-Baumeister.pdf
    • http://loaminoo.linkpc.net/1091099096090090093/Word-2016---Basiswissen-F-r-Einsteiger-Leicht-verst-ndlich---komplett-in-Farbe-by-Inge-Baumeister.pdf
    • http://loaminoo.linkpc.net/1091093093094093099/Einstieg-in-C-mit-Visual-Studio-2015-Ideal-f-r-Programmieranf-nger-geeignet-by-Thomas-Theis.pdf
    • http://loaminoo.linkpc.net/9093095090091092/The-Populist-88-fiese-Seiten-by-Pit-Vogt.pdf
    • http://loaminoo.linkpc.net/8098097093093099/The-Pet-Dragon-by-Christoph-Niemann.pdf
    • http://loaminoo.linkpc.net/1090099099093091095/I-Lego-N-Y-by-Christoph-Niemann.pdf
    • http://loaminoo.linkpc.net/9093094099093092/Abnehmen-in-zehn-Seiten-by-Thomas-Klytta.pdf
    • http://loaminoo.linkpc.net/9093094099093093/Dunkle-Seiten---Maxileseprobe-by-David-Pawn.pdf
    • http://loaminoo.linkpc.net/9093094098095099/seiten-1-souseiki-your