Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1e91be7f3fd091b…

MALICIOUS

PDF

20.0 KB Created: 2019-04-30 02:19:19 +01:00 Authoring application: mPDF 5.7
MD5: dac2e06544412028c9dbae961c2cc4df SHA-1: e4edd075ac1e2ee1fc87dc7a8fa2c9fda1e24db6 SHA-256: f1e91be7f3fd091b40d347863543b4a3fb9c8426c00a009b49f6fa1078e9c30a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the sheer volume of links suggests a malicious intent, possibly for SEO manipulation or to distribute further malware. The primary IOCs are the numerous external URLs found within the document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090099096099093092/Feuerwerk-der-L-ste---Sammelband-3-by-Vivian-Gold.pdf
    • http://loaminoo.linkpc.net/1090099096099094093/Hei-es-Feuerwerk-1-erotisches-zur-Nacht---Sammelband-by-Kiara-Grey.pdf
    • http://loaminoo.linkpc.net/1090099096099094092/Hei-es-Feuerwerk-2-erotisches-zur-Nacht---Sammelband-by-Kiara-Grey.pdf
    • http://loaminoo.linkpc.net/3090098097095099/Vivian-Apple-Needs-a-Miracle-Vivian-Apple-2-by-Katie-Coyle.pdf
    • http://loaminoo.linkpc.net/1091096/Vivian-Apple-at-the-End-of-the-World-Vivian-Apple-1-by-Katie-Coyle.pdf
    • http://loaminoo.linkpc.net/1090099096098091093/Japanisches-Feuerwerk-by-Ruth-Gogoll.pdf
    • http://loaminoo.linkpc.net/1090099097090091090/Feuerwerk-in-meinem-Hafen-by-Gioconda-Belli.pdf
    • http://loaminoo.linkpc.net/1090099096098091099/Feuerwerk-Lesbian-Romance-by-Chris-P-Rolls.pdf
    • http://loaminoo.linkpc.net/7093091098098/Yukon-Gold-The-Story-of-the-Klondike-Gold-Rush-by-Charlotte-Foltz-Jones.pdf
    • http://loaminoo.linkpc.net/1090091096099091096/Gold-The-Story-of-the-1848-Gold-Rush-and-How-It-Shaped-a-Nation-by-Fred-Rosen.pdf
    • http://loaminoo.linkpc.net/1090099096099093091/PORN-JUNKIE-EPISODEN-2-Feuerwerk-by-Michael-Bantur.pdf
    • http://loaminoo.linkpc.net/3096097099097096/The-Age-of-Gold-The-California-Gold-Rush-and-the-New-American-Dream-by-H-W-Brands.pdf
    • http://loaminoo.linkpc.net/9096093097096099/Der-gro-e-Gold-Insider-Report-In-Gold-investiren-lohnt-immer-Edelmetalle-mit-System-by-Dennis-Nowak.pdf
    • http://loaminoo.linkpc.net/1090099097090090099/Blutrotes-Feuerwerk-Der-1-Fall-der-Soko-Berlin-by-Julia-Herne.pdf
    • http://loaminoo.linkpc.net/3097097098094095/Secrets-of-the-Nanny-Whisperer-A-Practical-Guide-for-Finding-and-Achieving-the-Gold-Standard-of-Care-for-Your-Child-by-Tammy-Gold.pdf
    • http://loaminoo.linkpc.net/3097097099099097/Criminal-Gold-Cantor-Gold-Crime-1-by-Ann-Aptaker.pdf
    • http://loaminoo.linkpc.net/1091099090090095090/Two-Years-in-the-Klondike-and-Alaskan-Gold-Fields-1896-1898-A-Thrilling-Narrative-of-Life-in-the-Gold-Mines-and-Camps-by-William-B-Haskell.pdf
    • http://loaminoo.linkpc.net/3090099096095094/Lost-Gold-Solid-Gold-1-by-Jae-Jordon.pdf
    • http://loaminoo.linkpc.net/1090099096099094094/Vergessen-Sie-alles-ber-Rhetorik-Mitrei-end-reden---ein-sprachliches-Feuerwerk-in-Bildern-by-Matthias-P-hm.pdf
    • http://loaminoo.linkpc.net/6091099098093095/Krieg-und-Frieden---Gold-Edition-f-r-Kindle-Zweisprachige-illustrierte-Gold-Edition-Deutsch-Englisch-21-by-Leo-Tolstoy.pdf
    • http://loaminoo.linkpc.net/3096097099097096/The-Age-of-Gold-The-