Malicious PDF — malware analysis report

Static analysis result for SHA-256 19c87f1e5e5f3deb…

MALICIOUS

PDF

24.4 KB Created: 2019-04-30 04:13:29 +01:00 Authoring application: mPDF 5.7
MD5: b9cd1daa9bf2160cb3791079f58ccb41 SHA-1: 2f167bdab3c85dd01e2ba87d9b6e35d4dea07b31 SHA-256: 19c87f1e5e5f3debe6fc8582734b344eb78190c792a1767c14050169d67be755
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which point to various academic books. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a link-farming or redirection scheme. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.li
    • http://loaminoo.linkpc.net/9094099099091096/Image-Based-Research-A-Sourcebook-for-Qualitative-Researchers-by-Jon-Prosser.pdf
    • http://loaminoo.linkpc.net/8099091095092099/Becoming-Qualitative-Researchers-An-Introduction-by-Corrine-Glesne.pdf
    • http://loaminoo.linkpc.net/8099091097099096/e-Study-Guide-for-Becoming-Qualitative-Researchers-by-Corrine-Glesne-ISBN-9780137047970-by-Cram101-Textbook-Reviews.pdf
    • http://loaminoo.linkpc.net/1091092090091098095/Qualitative-Data-Analysis-An-Expanded-Sourcebook-by-Matthew-B-Miles.pdf
    • http://loaminoo.linkpc.net/8092098099097091/Qualitative-Music-Therapy-Research-Beginning-Dialogues-by-Mechtild-Langenberg.pdf
    • http://loaminoo.linkpc.net/1090099093090095097/Interviews-Learning-the-Craft-of-Qualitative-Research-Interviewing-by-Steinar-Kvale.pdf
    • http://loaminoo.linkpc.net/4096095099092092/Longitudinal-Qualitative-Research-Analyzing-Change-Through-Time-by-Johnny-Saldana.pdf
    • http://loaminoo.linkpc.net/1090093095091092090/Sean-O-Casey-A-Research-and-Production-Sourcebook-by-Bernice-Schrank.pdf
    • http://loaminoo.linkpc.net/1091092091090094096/The-Science-of-Mindfulness-A-Research-Based-Path-to-Well-Being-by-Ronald-D-Siegel.pdf
    • http://loaminoo.linkpc.net/9095090090094090/The-Echoed-Song-by-Mrs-Prosser-and-Weeping-Willowby-by-Sophie-Amelia-Prosser.pdf
    • http://loaminoo.linkpc.net/2097092094096098/Body-by-Science-A-Research-Based-Program-for-Strength-Training-Body-Building-and-Complete-Fitness-in-12-Minutes-a-Week-by-John-Little.pdf
    • http://loaminoo.linkpc.net/6095095091090095/Case-Based-Reasoning-Research-and-Development-22nd-International-Conference-Iccbr-2014-Cork-Ireland-September-29-2014---October-1-2014-Proceedings-by-Luc-Lamontagne.pdf
    • http://loaminoo.linkpc.net/9094099098095093/The-Life-of-David-A-Prosser---A-Brummie-by-David-A-Prosser.pdf
    • http://loaminoo.linkpc.net/9094099098095097/The-Life-of-David-A-Prosser---a-Brummie-by-David-A-Prosser.pdf
    • http://loaminoo.linkpc.net/1091097094091097097/Strengthen-School-Based-Management-by-Chartering-All-Schools-A-Three-Year-Policy-Based-Strategy-for-Creating-Autonomous-Public-Schools-Within-Restru-by-Ray-Budde.pdf
    • http://loaminoo.linkpc.net/6096095099098095/The-Moon-and-Sixpence-One-Man-s-Journey-Across-the-Field-of-Art-and-into-Its-Depths-Based-on-the-Life-of-Paul-Gauguin-Biographical-Novel-based-on-the-of-the-famous-French-painter-Paul-Gauguin-by-W-Somerset-Maugham.pdf
    • http://loaminoo.linkpc.net/1091093094098099091/Flavour-Research-of-Alcoholic-Beverages-Instrumental-and-Sensory-Analysis-Proceedings-of-the-Alko-Symposium-on-Flavour-Research-of-Alcoholic-Beverag-by-Lalli-Nykanen.pdf
    • http://loaminoo.linkpc.net/1091097093095092095/Gender-and-Qualitative-Methods-by-Helmi-Jarviluoma.pdf
    • http://loaminoo.linkpc.net/1090093099099091092/Writing-the-Qualitative-Dissertation-Understanding-by-Doing-by-Judith-M-Meloy.pdf
    • http://loaminoo.linkpc.net/9094099096091099/That-Prosser-Kid-by-Lloyd-Pye.pdf