Malicious PDF — malware analysis report

Static analysis result for SHA-256 e7a913477f6c937a…

MALICIOUS

PDF

16.9 KB Created: 2019-05-03 05:09:13 +01:00 Authoring application: mPDF 5.7
MD5: 9a029679af988794306d81308c349b96 SHA-1: a56f067aa46f78a3a22ee1730330992e46e0a8ff SHA-256: e7a913477f6c937adc188ad777636806aaa956dd661e8416f1d17767bcb6c326
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links. The heuristic 'PDF_SEO_LINK_FARM' indicates these links are likely part of a scheme to manipulate search engine results or distribute further malicious content. While no scripts were extracted, the sheer volume and nature of the embedded URLs suggest a malicious intent to redirect users to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9098090096092/12-Collections-amp-the-Teashop-by-Zoran-ivkovi-.pdf
    • http://loaminoo.linkpc.net/7095099093097092/Collections-of-Stained-Glass-and-Their-Histories-Glasmalerei-Sammlungen-Und-Ihre-Geschichte-Les-Collections-de-Vitraux-Et-Leur-Histoire-Transactions-of-the-25th-International-Colloquium-of-the-Corpus-Vitrearum-in-Saint-Petersburg-the-State-Hermit-by-Tim-Ayers.pdf
    • http://loaminoo.linkpc.net/1095099096097097/The-Cosy-Teashop-in-the-Castle-by-Caroline-Roberts.pdf
    • http://loaminoo.linkpc.net/4098091095096096/Tell-Me-What-You-See-by-Zoran-Drvenkar.pdf
    • http://loaminoo.linkpc.net/5091091099091090/Tell-Me-What-You-See-by-Zoran-Drvenkar.pdf
    • http://loaminoo.linkpc.net/4098091092092095/The-Library-by-Zoran-ivkovi-.pdf
    • http://loaminoo.linkpc.net/5094092095093096/The-Bridge-by-Zoran-ivkovi-.pdf
    • http://loaminoo.linkpc.net/5094092095092095/Impossible-Encounters-by-Zoran-ivkovi-.pdf
    • http://loaminoo.linkpc.net/5094092095098092/The-Book-The-Writer-by-Zoran-ivkovi-.pdf
    • http://loaminoo.linkpc.net/1098094096099/The-City-ABC-Book-by-Zoran-Milich.pdf
    • http://loaminoo.linkpc.net/1097095094096095/Impossible-Stories-II-by-Zoran-ivkovi-.pdf
    • http://loaminoo.linkpc.net/1090095094095091097/Republic-of-Georgia-by-Zoran-Pavlovic.pdf
    • http://loaminoo.linkpc.net/1097095094096093/Steps-Through-the-Mist-by-Zoran-ivkovi-.pdf
    • http://loaminoo.linkpc.net/9094095096091099/Der-letzte-Engel-Reihe-in-2-B-nden-by-Zoran-Drvenkar.pdf
    • http://loaminoo.linkpc.net/8097095090090097/The-Zoran-s-Touch-Barbarian-Brides-5-by-Luna-Hunter.pdf
    • http://loaminoo.linkpc.net/8097095090091090/The-Zoran-s-Chosen-Barbarian-Brides-8-by-Luna-Hunter.pdf
    • http://loaminoo.linkpc.net/9094095095098095/Die-Nacht-in-der-meine-Schwester-den-Weihnachtsmann-entf-hrte-by-Zoran-Drvenkar.pdf
    • http://loaminoo.linkpc.net/9097096098098092/Junge-Kerle-v-geln-geile-Grannys-by-Zoran-Zecke.pdf
    • http://loaminoo.linkpc.net/8093095092096090/The-Louvre-Collections-by-Oriental-Institute.pdf
    • http://loaminoo.linkpc.net/2093090093091091/Collections-of-Nothing-by-William-Davies-King.pdf
    • http://loaminoo.linkpc.net/1098094096099/The-City-