Malicious PDF — malware analysis report

Static analysis result for SHA-256 5260205636bd85f4…

MALICIOUS

PDF

19.8 KB Created: 2019-05-05 16:04:37 +01:00 Authoring application: mPDF 5.7
MD5: a7310bf2e4625e352fa62523c823c303 SHA-1: 144a691a1936d636161753b32b4f6440ee11bf14 SHA-256: 5260205636bd85f4d86aaea084737b10329862da3524d83a9fdc7b569ffe60cd
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified as a PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO manipulation or to distribute further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5092093092091090/Being-Palestinian-Personal-Reflections-on-Palestinian-Identity-in-the-Diaspora-by-Yasir-Suleiman.pdf
    • http://loaminoo.linkpc.net/4097099099098/The-Palestinian-People-A-History-by-Baruch-Kimmerling.pdf
    • http://loaminoo.linkpc.net/1093093094097/Tasting-the-Sky-A-Palestinian-Childhood-by-Ibtisam-Barakat.pdf
    • http://loaminoo.linkpc.net/1091090095091094094/Palestinian-Refugee-Problem-The-Search-for-a-Resolution-by-Rex-Brynen.pdf
    • http://loaminoo.linkpc.net/1091090095091093099/The-Palestinian-Refugee-Problem-The-Search-for-a-Resolution-by-Rex-Brynen.pdf
    • http://loaminoo.linkpc.net/1091094091092092093/Blue-Guide-Israel-and-the-Palestinian-Territories-by-Kay-Prag.pdf
    • http://loaminoo.linkpc.net/7092097098095091/Ghassan-Kanafani-the-life-of-a-Palestinian-by-Stefan-Wild.pdf
    • http://loaminoo.linkpc.net/7092093090093095/Palestinian-Women-and-Politics-in-Israel-by-Suheir-Abu-Oksa-Daoud.pdf
    • http://loaminoo.linkpc.net/1093095094096099/From-Jerusalem-to-Beverly-Hills-Memoir-of-a-Palestinian-Jew-by-Eitan-Gonen.pdf
    • http://loaminoo.linkpc.net/7095097096099097/In-Hope-and-Despair-Life-in-the-Palestinian-Refugee-Camps-by-Mia-Grondahl.pdf
    • http://loaminoo.linkpc.net/5092093092091095/Refugees-of-the-Revolution-Experiences-of-Palestinian-Exile-by-Diana-Allan.pdf
    • http://loaminoo.linkpc.net/7093096091093099/Eyes-Without-Country-Searching-for-a-Palestinian-Strategy-of-Liberation-by-Souad-R-Dajani.pdf
    • http://loaminoo.linkpc.net/2092091095095090/Palestinian-Women-Narrative-Histories-and-Gendered-Memory-by-Fatma-Kassem.pdf
    • http://loaminoo.linkpc.net/3093092096095093/The-Politics-of-Dispossession-The-Struggle-for-Palestinian-Self-Determination-1969-1994-by-Edward-W-Said.pdf
    • http://loaminoo.linkpc.net/1096096094094093/The-Iron-Cage-The-Story-of-the-Palestinian-Struggle-for-Statehood-by-Rashid-Khalidi.pdf
    • http://loaminoo.linkpc.net/3097095095091090/The-Iron-Cage-The-Story-of-the-Palestinian-Struggle-for-Statehood-by-Rashid-Khalidi.pdf
    • http://loaminoo.linkpc.net/3097095097097094/Chosen-Reading-the-Bible-Amid-the-Israeli-Palestinian-Conflict-by-Walter-Brueggemann.pdf
    • http://loaminoo.linkpc.net/3097095097096096/Beyond-Occupation-Apartheid-Colonialism-and-International-Law-in-the-Occupied-Palestinian-Territories-by-Virginia-Tilley.pdf
    • http://loaminoo.linkpc.net/3097095097097093/The-One-State-Solution-A-Breakthrough-for-Peace-in-the-Israeli-Palestinian-Deadlock-by-Virginia-Tilley.pdf
    • http://loaminoo.linkpc.net/6090095094095093/The-Secret-Life-of-Saeed-the-Ill-Fated-Pessoptimist-A-Palestinian-Who-Became-a-Citizen-of-Israel-by-Emile-Habiby.pdf