Malicious PDF — malware analysis report

Static analysis result for SHA-256 db1a0b209f1c424a…

MALICIOUS

PDF

18.1 KB Created: 2019-05-02 05:37:06 +01:00 Authoring application: mPDF 5.7
MD5: 0524cae527505878e908dc5008a91ac0 SHA-1: 349f1fe2e50a8f405936d207960303bd28aec861 SHA-256: db1a0b209f1c424aca03936c4af1f90a00de1c7c06b94a315bc1891f95369f03
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links point to benign-looking book titles, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091093093092094093/Einstieg-in-Python-Ideal-f-r-Programmieranf-nger-geeignet-by-Thomas-Theis.pdf
    • http://loaminoo.linkpc.net/1091093093094093099/Einstieg-in-C-mit-Visual-Studio-2015-Ideal-f-r-Programmieranf-nger-geeignet-by-Thomas-Theis.pdf
    • http://loaminoo.linkpc.net/1091097092095099093/Python-Data-Analytics-Data-Analysis-and-Science-Using-Pandas-Matplotlib-and-the-Python-Programming-Language-by-Fabio-Nelli.pdf
    • http://loaminoo.linkpc.net/2090099096095091/The-Eye-of-Argon-by-Jim-Theis.pdf
    • http://loaminoo.linkpc.net/1090095094095092096/Lichtblicke-Stillstand-1-by-David-Theis.pdf
    • http://loaminoo.linkpc.net/1091092097096090099/Der-leichte-Einstieg-in-die-Elektronik-by-Bo-Hanus.pdf
    • http://loaminoo.linkpc.net/3099097096092096/Confessions-of-a-Transylvanian-by-Kevin-Theis.pdf
    • http://loaminoo.linkpc.net/9093099097099098/Lightroom-5-Der-Einstieg-f-r-Fotografen-by-Michael-Gradias.pdf
    • http://loaminoo.linkpc.net/6099098094096/Mercedes-and-the-Chocolate-Pilot-by-Margot-Theis-Raven.pdf
    • http://loaminoo.linkpc.net/6097096096094097/Raspberry-Pi-Einstieg-Optimierung-Projekte-by-Maik-Schmidt.pdf
    • http://loaminoo.linkpc.net/1091092092093098/Rags-Hero-Dog-of-WWI-A-True-Story-by-Margot-Theis-Raven.pdf
    • http://loaminoo.linkpc.net/1090099099095091093/Das-Einsteigerseminar-Objektorientierte-Programmierung-In-Java-Der-Methodische-Und-Ausf-hrliche-Einstieg-400-Seiten-Einsteiger-Know-How-by-Alexander-Niemann.pdf
    • http://loaminoo.linkpc.net/4095092093096094/Das-Einsteigerseminar-Internet-Information-Server-5-Der-Methodische-Und-Ausfu-hrliche-Einstieg-U-ber-300-Seiten-Einsteiger-Know-How-by-G-nther-Karl.pdf
    • http://loaminoo.linkpc.net/5098093095098093/Dive-Into-Python-by-Mark-Pilgrim.pdf
    • http://loaminoo.linkpc.net/5093091097091/Learning-Python-by-Mark-Lutz.pdf
    • http://loaminoo.linkpc.net/9098096090099096/Programming-Python-by-Mark-Lutz.pdf
    • http://loaminoo.linkpc.net/1091093093092095099/Grillgenuss-Rezepte-geeignet-f-r-den-Thermomix-by-Marion-M-hrlein-Yilmaz.pdf
    • http://loaminoo.linkpc.net/9098096091090091/Python-Pocket-Reference-by-Mark-Lutz.pdf
    • http://loaminoo.linkpc.net/7095090095090095/Deep-learning-with-Python-by-Francois-Chollet.pdf
    • http://loaminoo.linkpc.net/1091093093093093093/Leckere-Muffins-Rezepte-geeignet-f-r-den-Thermomix-by-Marion-M-hrlein-Yilmaz.pdf
    • http://loaminoo.linkpc.net/6097096096094097/Raspberry-Pi-Einstieg-Optimierung-