Malicious PDF — malware analysis report

Static analysis result for SHA-256 f5ea0bcfdd91e022…

MALICIOUS

PDF

25.2 KB Created: 2019-04-30 10:03:54 +01:00 Authoring application: mPDF 5.7
MD5: 35639ecc8ea98502982e752d958a2b8f SHA-1: e785b317b17b1724fc1cdff34d7debe71d5052ce SHA-256: f5ea0bcfdd91e0229aac4a5c6497a4ed64202f82d112a353740359f7e099ab4c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF was flagged by a critical heuristic for containing a mass external PDF link farm, with numerous links pointing to a domain that appears to be used for hosting these files. While the document body is heavily obfuscated, the presence of many URLs suggests a malicious intent to redirect users to potentially harmful content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091092099095094096/Lustige-Kindergeschichten-mit-Originalillustrationen-Die-Gnomen-und-das-Kartenhaus-Das-l-sterne-Wildschwein-Der-brave-Karo-Folgen-der-Zwietracht-eigensinnige-Schwein-by-Lothar-Meggendorfer.pdf
    • http://loaminoo.linkpc.net/9094091094098091/Lothar-Meggendorfer-s-International-circus-A-reproduction-of-the-antique-pop-up-book-by-Lothar-Meggendorfer.pdf
    • http://loaminoo.linkpc.net/1091092099095094093/The-City-Park-A-Reproduction-of-an-Antique-Stand-up-Book-by-Lothar-Meggendorfer.pdf
    • http://loaminoo.linkpc.net/9099096090092092/Die-brave-Bertha-und-die-b-se-Lina-Eine-lehrreiche-Kindergeschichte-in-Versen---Vollst-ndige-Ausgabe-mit-Originalillustrationen-by-Franz-Bonn.pdf
    • http://loaminoo.linkpc.net/9096095093097090/Lustige-Bilder-Sch-ne-Galerie-der-Majestic-H-hner-Huhn-seltsame-Comedy-Hintergrund-Fotos-kostenlos-Art-Fotos-Perfektion-freundliche-schattigen-sch-ne-lustige-Bilder-67-by-Marx-Gordo.pdf
    • http://loaminoo.linkpc.net/3095090098093092/Brave-Land-Brave-Love-Australian-Trilogy-3-by-Connie-Mason.pdf
    • http://loaminoo.linkpc.net/1098094093097092/Junior-Braves-of-the-Apocalypse-Volume-1-A-Brave-is-Brave-1-by-Greg-Smith.pdf
    • http://loaminoo.linkpc.net/1090097094090098094/Gespenst-Elfriede-Kindergeschichten-by-Brigitte-Hoffmann.pdf
    • http://loaminoo.linkpc.net/8095096095093094/Malala-a-Brave-Girl-from-Pakistan-Iqbal-a-Brave-Boy-from-Pakistan-Two-Stories-of-Bravery-by-Jeanette-Winter.pdf
    • http://loaminoo.linkpc.net/1099094099093096/Galgorithm-by-Aaron-Karo.pdf
    • http://loaminoo.linkpc.net/9093098097098099/Drei-Rauber-Mit-Schwein-by-Frauke-Nahrgang.pdf
    • http://loaminoo.linkpc.net/6093097095099090/Cruel-is-the-Night-by-Karo-H-m-l-inen.pdf
    • http://loaminoo.linkpc.net/1090095093098091092/Batman-in-The-Brave-amp-the-Bold-The-Bronze-Age-Vol-1-The-Brave-and-the-Bold-1955-1983-by-Bob-Haney.pdf
    • http://loaminoo.linkpc.net/1090092091097095090/Bibi-Blocksberg---Das-verhexte-Schwein-by-Doris-Riedl.pdf
    • http://loaminoo.linkpc.net/2099098090099091/Ruminations-on-Twentysomething-Life-by-Aaron-Karo.pdf
    • http://loaminoo.linkpc.net/1090099095098093099/Bauch--Traum-T-nzer-by-Karo-Stein.pdf
    • http://loaminoo.linkpc.net/7092092099094095/Kaunas-Karo-Su-Kryziuociais-Epochoje-by-Jurgis-Oksas.pdf
    • http://loaminoo.linkpc.net/1091095090097095097/Das-unwahrscheinlich-geheime-Tagebuch-vom-kleinen-Schwein-Band-1-by-Emer-Stamp.pdf
    • http://loaminoo.linkpc.net/9096094098096099/Nur-So-Geschichten---Das-Tierische-M-rchenbuch-Vollst-ndige-Deutsche-Ausgabe-Mit-Originalillustrationen-by-Rudyard-Kipling.pdf
    • http://loaminoo.linkpc.net/9095096090094091/365-Kindergeschichten-Geschichten-zum-Vorlesen-durchs-Jahr-Von-Prinzessinnen-Drachen-Astronauten-kleinen-B-ren-und-mehr-by-Ingrid-Annel.pdf
    • http://loaminoo.linkpc.net/1091092099095094093/The-City-Park-A-Reproduction-of-an-Antique-Stand-up-Book-by-Lothar-Meggendorf