Malicious PDF — malware analysis report

Static analysis result for SHA-256 24e1c4bbd200d607…

MALICIOUS

PDF

19.5 KB Created: 2019-05-02 17:06:51 +01:00 Authoring application: mPDF 5.7
MD5: 3782f26bd0564fcf4d92e6cf46837674 SHA-1: 1c71c439ee322827c59c0c0b3c3243fe6e1543ad SHA-256: 24e1c4bbd200d607c0446eb3ca2eea50555cc741550d8373d843dd94f481065f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While most individual links are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, likely for SEO manipulation or to distribute further malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6094091097097096/Kabbalah-The-Way-of-The-Jewish-Mystic-by-Perle-Besserman.pdf
    • http://loaminoo.linkpc.net/6094091099091099/Owning-It-Zen-and-the-Art-of-Facing-Life-by-Perle-Besserman.pdf
    • http://loaminoo.linkpc.net/1096095096091091/Money-A-Memoir-Women-Emotions-and-Cash-by-Liz-Perle.pdf
    • http://loaminoo.linkpc.net/7093092095090092/La-perle-et-le-feu-by-Jeannie-Lin.pdf
    • http://loaminoo.linkpc.net/9093091096095090/Kabbalah-and-Art-by-L-o-Bronstein.pdf
    • http://loaminoo.linkpc.net/8093095094094098/La-perle-by-John-Steinbeck.pdf
    • http://loaminoo.linkpc.net/6094091099092090/Hard-Line-by-Richard-Perle.pdf
    • http://loaminoo.linkpc.net/5094096095091093/La-Perle-et-la-coquille-by-Nadia-Hashimi.pdf
    • http://loaminoo.linkpc.net/1091095090094098/Kabbalah-in-Art-and-Architecture-by-Alexander-Gorlin.pdf
    • http://loaminoo.linkpc.net/1091099095094091091/Kabbalah-of-Prayer-by-Shulamit-Elson.pdf
    • http://loaminoo.linkpc.net/9097098093093095/Emmy-You-re-the-Greatest-by-Ruth-Lerner-Perle.pdf
    • http://loaminoo.linkpc.net/1097098090098097/Kabbalah-Key-to-Your-Inner-Power-by-Elizabeth-Clare-Prophet.pdf
    • http://loaminoo.linkpc.net/6091099096092/Studies-in-Ecstatic-Kabbalah-by-Moshe-Idel.pdf
    • http://loaminoo.linkpc.net/1090092092092091096/The-Kabbalah-A-Jewish-Mystical-Path-by-Franjo-Terhart.pdf
    • http://loaminoo.linkpc.net/5094091096090/Absorbing-Perfections-Kabbalah-and-Interpretation-by-Moshe-Idel.pdf
    • http://loaminoo.linkpc.net/4099092099096099/The-Way-Using-the-Wisdom-of-Kabbalah-for-Spiritual-Transformation-and-Fulfillment-by-Michael-Berg.pdf
    • http://loaminoo.linkpc.net/1091098098096095090/Gnosis-of-the-Cosmic-Christ-A-Gnostic-Christian-Kabbalah-by-Tau-Malachi.pdf
    • http://loaminoo.linkpc.net/1096091094096093/More-Women-of-Wonder-Science-Fiction-Novelettes-by-Women-About-Women-by-Pamela-Sargent.pdf
    • http://loaminoo.linkpc.net/1091098093097098093/M-rchen-amp-Sagen-vom-Meer-Die-rote-Perle-Der-fliehende-Holl-nder-Die-Seelen-der-Ertrunkenen-Scylla-Das-Abenteuer-mit-den-drei-Fischen-Meerlilie-Klabauterman-Der-Wetterbeschw-rer-by-Alexander-von-Ungern-Sternberg.pdf
    • http://loaminoo.linkpc.net/6095096091091093/For-Such-A-Time-As-This-Women-of-the-Bible-Who-Made-an-Impact-A-Study-for-Wise-Women-by-Kay-Daigle.pdf
    • http://loaminoo.linkpc.net/6091099096092/Studies-in-Ecstatic-K