Malicious PDF — malware analysis report

Static analysis result for SHA-256 74169d2c86a43c09…

MALICIOUS

PDF

19.7 KB Created: 2019-05-02 19:04:38 +01:00 Authoring application: mPDF 5.7
MD5: 53455024e379225e98c3f7d4032f6034 SHA-1: 9248267e238305d7b7f9ef4df7920c8b74220061 SHA-256: 74169d2c86a43c0919b60253d846d766395d378510ab36eec733d26a1ac03874
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection scheme. While the document body is heavily obfuscated, the presence of numerous external links points to a likely attempt to direct the user to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6090095094091094/Modern-Arabic-Poetry-An-Anthology-by-Salma-Khadra-Jayyusi.pdf
    • http://loaminoo.linkpc.net/6090095094094095/Modern-Arabic-Fiction-An-Anthology-by-Salma-Khadra-Jayyusi.pdf
    • http://loaminoo.linkpc.net/6090095095096098/Literature-of-Modern-Arabia-by-Salma-Khadra-Jayyusi.pdf
    • http://loaminoo.linkpc.net/6090095095090095/Human-Rights-in-Arab-Thought-A-Reader-by-Salma-Khadra-Jayyusi.pdf
    • http://loaminoo.linkpc.net/1091097091094097090/A-Critical-Introduction-to-Modern-Arabic-Poetry-by-Mu-ammad-Mu-af-Badaw-.pdf
    • http://loaminoo.linkpc.net/4095099092095097/An-Anthology-of-Modern-Irish-Poetry-by-Wes-Davis.pdf
    • http://loaminoo.linkpc.net/4091093091097091/The-Great-Modern-Poets-An-Anthology-of-the-Best-Poets-and-Poetry-Since-1900-by-Michael-Schmidt.pdf
    • http://loaminoo.linkpc.net/1098093092097/No-Sign-of-Ceasefire-An-Anthology-of-Contemporary-Israeli-Poetry-An-Anthology-of-Contemporary-Israeli-Poetry-by-Warren-Bargad.pdf
    • http://loaminoo.linkpc.net/9092095093093093/My-poetry-depicts-you-An-anthology-of-contemporary-Kurdish-poetry-by-Rebwar-Fatah.pdf
    • http://loaminoo.linkpc.net/4099095095095090/A-Boom-in-the-Room-an-Anthology-of-Student-Poetry-Student-Poetry-Anthologies-Book-1-by-Annie-Douglass-Lima.pdf
    • http://loaminoo.linkpc.net/1098097094099098/The-Animists-A-Modern-Arabic-Novel-by-Ibrahim-al-Koni.pdf
    • http://loaminoo.linkpc.net/1091097091093094099/Modern-Written-Arabic-A-Comprehensive-Grammar-by-Elsaid-Badawi.pdf
    • http://loaminoo.linkpc.net/1091097091094097095/Modern-Arabic-Drama-in-Egypt-by-Mu-ammad-Mu-af-Badaw-.pdf
    • http://loaminoo.linkpc.net/1091097091094095091/A-Short-History-of-Modern-Arabic-Literature-by-Mu-ammad-Mu-af-Badaw-.pdf
    • http://loaminoo.linkpc.net/1091093090094090090/Elementary-Modern-Standard-Arabic-Volume-1-Pronunciation-and-Writing-Lessons-1-30-by-Peter-F-Abboud.pdf
    • http://loaminoo.linkpc.net/8092094091096098/28-Arabic-Short-Stories-In-Arabic-Language-by-Hasan-Yahya.pdf
    • http://loaminoo.linkpc.net/6095096092090097/Chadian-And-Sudanese-Arabic-In-The-Light-Of-Comparative-Arabic-Dialectology-Janua-Linguarum-Series-Practica-by-Alan-S-Kaye.pdf
    • http://loaminoo.linkpc.net/4095099093093096/The-Seashell-Anthology-of-Great-Poetry-by-Christopher-Burns.pdf
    • http://loaminoo.linkpc.net/8090090092095094/Confucius-to-Cummings-An-Anthology-of-Poetry-by-Ezra-Pound.pdf
    • http://loaminoo.linkpc.net/2096095090095096/Classical-Chinese-Poetry-An-Anthology-by-David-Hinton.pdf