Malicious PDF — malware analysis report

Static analysis result for SHA-256 5d52546f4b92d801…

MALICIOUS

PDF

17.2 KB Created: 2019-05-02 04:27:50 +01:00 Authoring application: mPDF 5.7
MD5: 5fce1a070b11b6825d56aea9a05e2109 SHA-1: db876ac3f6d2cdfd434691c0d44dee867a67e479 SHA-256: 5d52546f4b92d8018fe8d11c56fac29a8d5ecda8197168d3317abf7f2a8a09af
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, directing users to external PDF files. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a potential attempt to manipulate search engine results or distribute content through a link farm, which can be a precursor to malicious activity. The ML classifier also flagged the document as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7097090091096093/The-Holy-Spirit-Contours-of-Christian-Theology-6-by-Sinclair-B-Ferguson.pdf
    • http://loaminoo.linkpc.net/4092094091097094/The-Church-Contours-of-Christian-Theology-4-by-Edmund-P-Clowney.pdf
    • http://loaminoo.linkpc.net/7097090091096097/The-Doctrine-of-God-Contours-of-Christian-Theology-1-by-Gerald-L-Bray.pdf
    • http://loaminoo.linkpc.net/7097090091097094/The-Providence-of-God-Contours-of-Christian-Theology-3-by-Paul-Helm.pdf
    • http://loaminoo.linkpc.net/7097090092092092/The-Doctrine-of-Humanity-Contours-of-Christian-Theology-5-by-Charles-Sherlock.pdf
    • http://loaminoo.linkpc.net/7097090092092094/Contours-of-Old-Testament-Theology-by-Bernhard-W-Anderson.pdf
    • http://loaminoo.linkpc.net/6094090094093097/Sermon-on-the-Mount-by-Sinclair-B-Ferguson.pdf
    • http://loaminoo.linkpc.net/5098093098096090/Faithful-God-An-Exposition-of-the-Book-of-Ruth-by-Sinclair-B-Ferguson.pdf
    • http://loaminoo.linkpc.net/5094092097094094/How-to-Be-Filled-with-the-Holy-Spirit-by-A-W-Tozer.pdf
    • http://loaminoo.linkpc.net/1090094096096095091/The-Work-of-the-Holy-Spirit-by-Abraham-Kuyper.pdf
    • http://loaminoo.linkpc.net/3096095098094097/In-the-School-of-the-Holy-Spirit-by-Jacques-Philippe.pdf
    • http://loaminoo.linkpc.net/7094095093092/Gifts-and-Ministries-of-the-Holy-Spirit-by-Lester-Sumrall.pdf
    • http://loaminoo.linkpc.net/6096090095093098/Fruitfulness-Bearing-the-Fruit-of-the-Holy-Spirit-by-Marcellin-Mutuyimana.pdf
    • http://loaminoo.linkpc.net/8098095098090097/The-Holy-Spirit-Activating-God-s-Power-in-Your-Life-by-Billy-Graham.pdf
    • http://loaminoo.linkpc.net/1090092097092099/The-Work-of-the-Holy-Spirit-in-You-I-am-the-Potter-you-are-the-Clay-by-Charles-E-Sivley.pdf
    • http://loaminoo.linkpc.net/5099095092099097/Inspired-The-Powerful-Presence-of-the-Holy-Spirit-by-Gary-Caster.pdf
    • http://loaminoo.linkpc.net/9094097098095095/The-Gifts-of-the-Holy-Spirit-to-Unbelievers-and-Believers-by-Clement-Read-Vaughan.pdf
    • http://loaminoo.linkpc.net/9096092091092094/The-Jewish-Trinity-When-Rabbis-Believed-in-the-Father-Son-and-Holy-Spirit-by-Yoel-Natan.pdf
    • http://loaminoo.linkpc.net/2095091091092096/Sex-Difference-in-Christian-Theology-Male-Female-and-Intersex-in-the-Image-of-God-by-Megan-K-Defranza.pdf
    • http://loaminoo.linkpc.net/1092099098096099/The-Christian-Goddess-Archetype-and-Theology-in-the-Fantasies-of-George-MacDonald-by-Bonnie-Gaarden.pdf