Malicious PDF — malware analysis report

Static analysis result for SHA-256 507b57a99a354af3…

MALICIOUS

PDF

21.9 KB Created: 2019-04-30 04:12:10 +01:00 Authoring application: mPDF 5.7
MD5: e3bdb9f728ac60de3964510bbb0dc3b3 SHA-1: d566644dfdb8aab032ff2392b955bc9e62a3458c SHA-256: 507b57a99a354af3891992b2b705bff2b0fafd138abd9a718290684e19ab0665
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8098092090099099/Shaykh-Ab-al-Hasan-Al-Nadw-His-Life-amp-Works-by-Muhammad-Akram-Nadwi.pdf
    • http://loaminoo.linkpc.net/8098092090091095/Abu-Hanifah-His-Life-Legal-Method-amp-Legacy-by-Muhammad-Akram-Nadwi.pdf
    • http://loaminoo.linkpc.net/8098092090092090/Madrasah-Life-A-Student-s-Day-At-Nadwat-Al-ulam-by-Muhammad-Akram-Nadwi.pdf
    • http://loaminoo.linkpc.net/8098091099097090/Al-Fiqh-Al-Islami-According-To-The-Hanafi-Madhab-by-Muhammad-Akram-Nadwi.pdf
    • http://loaminoo.linkpc.net/8098092090099096/Ibn-azm-on-the-lawfulness-of-women-attending-prayers-in-the-mosque-by-Muhammad-Akram-Nadwi.pdf
    • http://loaminoo.linkpc.net/1090092092090095094/The-Complete-Idiot-s-Guide-to-the-Koran-by-Muhammad-Shaykh-Sarwar.pdf
    • http://loaminoo.linkpc.net/8098092092095096/Islamic-Economics-and-Finance-A-Glossary-by-Muhammad-Akram-Khan.pdf
    • http://loaminoo.linkpc.net/8098092091090092/What-Is-Wrong-with-Islamic-Economics-Analysing-the-Present-State-and-Future-Agenda-by-Muhammad-Akram-Khan.pdf
    • http://loaminoo.linkpc.net/4097095097093097/The-Life-of-Muhammad-by-Muhammad-Husayn-Haykal.pdf
    • http://loaminoo.linkpc.net/6092090091093095/The-Life-of-Muhammad-by-Mu-ammad-Ibn-Is-q.pdf
    • http://loaminoo.linkpc.net/6090098091092096/Imam-Hasan-Al-Askari-A-Brief-Excursion-Into-the-Life-and-Thought-of-the-Fourteen-Immaculates-by-Mehdi-Rahimi.pdf
    • http://loaminoo.linkpc.net/6092092092093091/The-Future-Master-Fard-Muhammad-by-Elijah-Muhammad.pdf
    • http://loaminoo.linkpc.net/4091098099092096/The-Messenger-The-Meanings-of-the-Life-of-Muhammad-by-Tariq-Ramadan.pdf
    • http://loaminoo.linkpc.net/8091093096098093/The-Life-of-the-Prophet-Muhammad-A-Brief-History-by-Marmaduke-William-Pickthall.pdf
    • http://loaminoo.linkpc.net/4098098099091091/In-the-Footsteps-of-the-Prophet-Lessons-from-the-Life-of-Muhammad-by-Tariq-Ramadan.pdf
    • http://loaminoo.linkpc.net/6095091095095094/Bitter-Fruit-The-Very-Best-of-Saadat-Hasan-Manto-by-Saadat-Hasan-Manto.pdf
    • http://loaminoo.linkpc.net/7096095094098091/The-First-Rafael-Sabatini-s-Collected-Works-The-Sea-Hawk-Scaramouche-Captain-Blood-Mistress-Wilding-The-Lion-s-Skin-The-Life-of-Cesare-Borgia-The-Strolling-Saint-and-More-15-Works-by-Rafael-Sabatini.pdf
    • http://loaminoo.linkpc.net/4090092094/Designing-Your-Life-Build-a-Life-that-Works-for-You-by-Bill-Burnett.pdf
    • http://loaminoo.linkpc.net/6092092093097094/The-Identity-of-the-Christ-Understanding-the-Fulfillment-of-the-Christ-Through-Master-Fard-Muhammad-the-Honorable-Elijah-Muhammad-and-the-Honorable-Louis-Farrakhan-by-Karriem-Allah.pdf
    • http://loaminoo.linkpc.net/4093090095095090/The-Occasional-Virgin-by-Hanan-Al-Shaykh.pdf
    • http://loaminoo.linkpc.net/8098092091090092/What-Is-Wrong-with-Islamic-Economics-Analysing-the-Present-St