Malicious PDF — malware analysis report

Static analysis result for SHA-256 5001e7a98ac88eb7…

MALICIOUS

PDF

15.9 KB Created: 2019-05-04 13:45:22 +01:00 Authoring application: mPDF 5.7
MD5: a8e32a4408030b02d4ab45deaca78590 SHA-1: b4c5b24d6334b25811e44f0a3601c6549e042688 SHA-256: 5001e7a98ac88eb7976ed6fe10ed3d03cfccaafadae53922ac085c3cc633a9e3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier and contains a large number of embedded external links, indicative of a link farm or SEO abuse. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing suggest a malicious intent to redirect users to potentially harmful content. No scripts were extracted, and the document body was heavily corrupted, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5093099097098/The-Passion-of-Jesus-Christ-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/4095090095091092/Seeing-and-Savoring-Jesus-Christ-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/6094090097090/Seeing-and-Savoring-Jesus-Christ-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/6094090096094091/Sanctification-in-the-Everyday-Three-Sermons-by-John-Piper-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/4092098096092095/Who-Is-Jesus-Answers-to-Your-Questions-About-the-Historical-Jesus-by-John-Dominic-Crossan.pdf
    • http://loaminoo.linkpc.net/1090090090091097097/Lessons-from-a-Hospital-Bed-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/2096092097092093/Don-t-Waste-Your-Life-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/8092094096091/When-I-Don-t-Desire-God-How-to-Fight-for-Joy-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/4092093099091092/Think-The-Life-of-the-Mind-and-the-Love-of-God-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/4094091099093094/The-Piper-at-the-Gates-of-Dawn-by-John-Cavanagh.pdf
    • http://loaminoo.linkpc.net/7097093096091092/Preparing-for-Marriage-Help-for-Christian-Couples-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/6091097099098/God-Is-the-Gospel-Meditations-on-God-s-Love-as-the-Gift-of-Himself-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/6097092094092/Desiring-God-Meditations-of-a-Christian-Hedonist-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/6094092099094098/Five-Points-Towards-a-Deeper-Experience-of-God-s-Grace-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/7092098090090095/The-Pied-Piper-of-Hamelin-A-German-Folktale-by-Amanda-St-John.pdf
    • http://loaminoo.linkpc.net/4099099097092097/An-Introduction-to-What-s-the-Difference-Manhood-and-Womanhood-Defined-According-to-the-Bible-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/1091093097092090096/The-Dog-of-Jesus-The-dog-that-changed-the-world-by-Michael-P-Sakowski.pdf
    • http://loaminoo.linkpc.net/1091092092091090092/Jesus-in-the-Jewish-World-by-G-za-Verm-s.pdf
    • http://loaminoo.linkpc.net/7091090093098097/Glocalization-How-Followers-of-Jesus-Engage-a-Flat-World-by-Bob-Roberts-Jr-.pdf
    • http://loaminoo.linkpc.net/1090097097093094094/The-Light-of-the-World-The-Life-and-Teachings-of-Jesus-of-Nazareth-by-Tim-Spiess.pdf
    • http://loaminoo.linkpc.net/6091097099098/God-Is-the-Gospel-Meditations-on-God-s-Love-as-the-Gift