Malicious PDF — malware analysis report

Static analysis result for SHA-256 3159be45f5d532f5…

MALICIOUS

PDF

18.5 KB Created: 2019-05-01 17:33:28 +01:00 Authoring application: mPDF 5.7
MD5: c54898eda8f1951d2cafc56dc1f835b2 SHA-1: f5002fef8b5f0ac2973446a53185fe85651374ff SHA-256: 3159be45f5d532f5c312c3eb9c793f08b4815dd6d23c9f15c15da7b66b39a218
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, constituting a link farm. This technique is often used to obscure malicious intent or to distribute further malware. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkp
    • http://loaminoo.linkpc.net/1090090092097092092/Perpetual-Angelus-As-the-Saints-Pray-the-Rosary-by-Romanus-Cessario.pdf
    • http://loaminoo.linkpc.net/3093093095099097/Pray-Pray-Pray-Poems-I-wrote-to-Prince-in-the-middle-of-the-night-by-E-Kristin-Anderson.pdf
    • http://loaminoo.linkpc.net/1090090092099091092/Time-Passes-On-Angelus-Demension-book-II-The-Angelus-Dimension-2-by-Kristin-Wilson.pdf
    • http://loaminoo.linkpc.net/1090090092097093098/ANGELUS-OMNIBUS-PART-ONE-The-Brothers-Angelus-by-Stephen-Anthony-Floro.pdf
    • http://loaminoo.linkpc.net/3096097095094097/Saints-Alive-New-Stories-of-Old-Saints-Saints-of-Empire-by-Andrew-M-Seddon.pdf
    • http://loaminoo.linkpc.net/1091097093095093093/Pray-A-Z-A-Practical-Guide-to-Pray-For-Your-Community-by-Amelia-Rhodes.pdf
    • http://loaminoo.linkpc.net/1090090092097098099/The-Book-of-Angelus-Silesius-I-E-Johann-Scheffler-with-Observations-by-the-Ancient-Zen-Masters-by-Angelus-Silesius.pdf
    • http://loaminoo.linkpc.net/1091097093095093091/Pray-The-Wolves-of-Pray-1-by-Christine-Bell.pdf
    • http://loaminoo.linkpc.net/1092093094094095/Act-III-by-Richard-Romanus.pdf
    • http://loaminoo.linkpc.net/3096096095094096/All-Saints-Daily-Reflections-on-Saints-Prophets-amp-Witnesses-for-Our-Time-by-Robert-Ellsberg.pdf
    • http://loaminoo.linkpc.net/4095093090098096/Saints-Alive-New-Stories-of-Old-Saints-Volume-II-Celtic-Paths-by-Andrew-M-Seddon.pdf
    • http://loaminoo.linkpc.net/1091097091092090093/The-Excellence-of-the-Rosary-by-M-J-Frings.pdf
    • http://loaminoo.linkpc.net/4096091092096094/Exo-Vaticana-Petrus-Romanus-Project-L-U-C-I-F-E-R-and-the-Vatican-s-Astonishing-Plan-for-the-Arrival-of-an-Alien-Savior-by-Cris-Putnam.pdf
    • http://loaminoo.linkpc.net/9094098094095091/The-Six-Chaplet-Rosary-by-Alan-Robinson.pdf
    • http://loaminoo.linkpc.net/6093091096092098/Saint-Dominic-and-the-Rosary-by-Catherine-Beebe.pdf
    • http://loaminoo.linkpc.net/8094099097094099/One-Hundred-Saints-Their-Lives-and-Likenesses-Drawn-from-Butler-s-Lives-of-the-Saints-and-Great-Works-of-Western-Art-by-Alban-Butler.pdf
    • http://loaminoo.linkpc.net/1095093099095/The-Rosary-Murders-Father-Koesler-1-by-William-X-Kienzle.pdf
    • http://loaminoo.linkpc.net/9099097094095098/A-Child-s-Treasure-Rosary-Meditations-for-Children-by-Derek-Rebello.pdf
    • http://loaminoo.linkpc.net/2097094094091093/Perpetual-Peace-by-Immanuel-Kant.pdf
    • http://loaminoo.linkpc.net/2098090090091/The-Age-of-Perpetual-Light-by-Josh-Weil.pdf