Malicious PDF — malware analysis report

Static analysis result for SHA-256 e7bf0441d2dd9fa5…

MALICIOUS

PDF

17.2 KB Created: 2019-04-30 04:11:43 +01:00 Authoring application: mPDF 5.7
MD5: ab73c85a5edfd3452885f531bc2137f1 SHA-1: 146ac519b54a4ad24fec7c3fb2f7557086e6a4d7 SHA-256: e7bf0441d2dd9fa590a902117a7b8380c75f48ff3f920490eb4685fb41199623
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While most of the linked URLs themselves are marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to act as a redirector to malicious sites. The ML classifier also flagged this PDF with high confidence. No scripts were extracted, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091096090095094093/Rose-Sommer-Leypold-Lebenswerk-Einer-Malerin-Die-Kunstlerin-in-Der-Nachfolge-Ihres-Lehrers-Anton-Kolig-by-Rose-Sommer-Leypold.pdf
    • http://loaminoo.linkpc.net/7099098091093099/Pro-Bono-by-Mikkel-Thorup.pdf
    • http://loaminoo.linkpc.net/9097092095090096/The-Total-Enemy-by-Mikkel-Thorup.pdf
    • http://loaminoo.linkpc.net/6093090095099092/Death-Sentence-by-Mikkel-Birkegaard.pdf
    • http://loaminoo.linkpc.net/7099098091094093/The-Freudian-Subject-by-Mikkel-Borch-Jacobsen.pdf
    • http://loaminoo.linkpc.net/7094092090097097/Frauen-in-Dessous-band-1-by-Lorrella-Mikkel.pdf
    • http://loaminoo.linkpc.net/9097092095090091/Intellectual-History-5-Questions-by-Mikkel-Thorup.pdf
    • http://loaminoo.linkpc.net/7099098091093098/Photoshop-Elements-3-Solutions-by-Mikkel-Aaland.pdf
    • http://loaminoo.linkpc.net/7099098090099093/How-to-Build-Your-Own-Sauna-amp-Sweat-by-Mikkel-Aaland.pdf
    • http://loaminoo.linkpc.net/9097092094092097/Intellectual-History-of-Economic-Normativities-by-Mikkel-Thorup.pdf
    • http://loaminoo.linkpc.net/7099097099098097/Mikkeller-s-Book-of-Beer-by-Mikkel-Borg-Bjergs-.pdf
    • http://loaminoo.linkpc.net/7099098090094097/Lacan-The-Absolute-Master-by-Mikkel-Borch-Jacobsen.pdf
    • http://loaminoo.linkpc.net/7099098090094095/Photoshop-Elements-2-Solutions-The-Art-of-Digital-Photography-by-Mikkel-Aaland.pdf
    • http://loaminoo.linkpc.net/7099098090098098/Cook-Natural-Flavours-from-a-Nordic-Kitchen-by-Mikkel-Karstad.pdf
    • http://loaminoo.linkpc.net/7099098090093094/The-Freud-Files-An-Inquiry-Into-the-History-of-Psychoanalysis-by-Mikkel-Borch-Jacobsen.pdf
    • http://loaminoo.linkpc.net/7099098091094096/Making-Minds-and-Madness-From-Hysteria-to-Depression-by-Mikkel-Borch-Jacobsen.pdf
    • http://loaminoo.linkpc.net/7099098091095091/Quantitative-Portfolio-Optimisation-Asset-Allocation-and-Risk-Management-by-Mikkel-Rasmussen.pdf
    • http://loaminoo.linkpc.net/7099098091094090/Britain-s-Victory-Denmark-s-Freedom-Danish-Volunteers-in-Allied-Air-Forces-During-the-Second-World-War-by-Mikkel-Plannthin.pdf
    • http://loaminoo.linkpc.net/1095094092092090/The-Next-American-Revolutionary-War-by-L-B-Sommer.pdf
    • http://loaminoo.linkpc.net/4094098093098094/Unexpected-by-Sommer-Marsden.pdf