Malicious PDF — malware analysis report

Static analysis result for SHA-256 94e9eb7d16250908…

MALICIOUS

PDF

24.9 KB Created: 2019-05-07 03:16:17 +01:00 Authoring application: mPDF 5.7
MD5: 0636e8ebfc855b3c990f1069d6ec46d6 SHA-1: 47c15bb866766e80885faa3784682c23d6f2b5cb SHA-256: 94e9eb7d1625090888077dc4773a5e7612ef8fa1ade1e4109054e5c11541de93
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The document body is heavily obfuscated, but the presence of numerous links suggests a link farm or distribution mechanism. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2093092092096093/Lay-Piety-and-Religious-Discipline-in-Middle-English-Literature-by-Nicole-R-Rice.pdf
    • http://loaminoo.linkpc.net/1097098090098094/The-Norton-Anthology-of-English-Literature-Volume-1-The-Middle-Ages-through-the-Restoration-amp-the-Eighteenth-Century-by-M-H-Abrams.pdf
    • http://loaminoo.linkpc.net/1090092094090094099/Literature-Suppressed-on-Religious-Grounds-Banned-Books-by-Margaret-Bald.pdf
    • http://loaminoo.linkpc.net/9093098099095091/Proceedings-of-the-Second-April-Conference-of-University-Teachers-of-English-Cracow-1981-April-23-29-Papers-in-English-and-American-Literature-Cul-by-Irena-Kaluza.pdf
    • http://loaminoo.linkpc.net/3096099092095093/English-Lit-Relit-A-Short-History-of-English-Literature-from-the-Precursors-Before-Swearing-to-the-Pre-Raphaelites-and-a-Little-After-Intended-to-Help-Students-See-the-Thing-Through-or-See-Through-the-Thing-and-Omitting-Nothing-Unimportant-by-Richard-Armour.pdf
    • http://loaminoo.linkpc.net/3096092095099093/A-Practical-View-of-the-Prevailing-Religious-System-of-Professed-Christians-in-the-Middle-and-Higher-Classes-in-this-Country-Contrasted-with-Real-Christianity-by-William-Wilberforce.pdf
    • http://loaminoo.linkpc.net/1094092090095091/A-Companion-to-Middle-High-German-Literature-to-the-14th-Century-by-Francis-G-Gentry.pdf
    • http://loaminoo.linkpc.net/6091098099099095/The-Troubadours-A-History-of-Provencal-Life-and-Literature-in-the-Middle-Ages-by-Francis-Hueffer.pdf
    • http://loaminoo.linkpc.net/8099098090094/SELF-DISCIPLINE-ACHIEVE-YOUR-GOALS-AND-GAIN-SUCCESS-IN-LIFE-THROUGH-THE-MASTERY-OF-SELF-DISCIPLINE-by-Floyd-Callahan.pdf
    • http://loaminoo.linkpc.net/8094092098093092/History-of-English-Literature---Vol-I-by-H-Taine.pdf
    • http://loaminoo.linkpc.net/2099096092098090/A-Study-of-Old-English-Literature-by-C-L-Wrenn.pdf
    • http://loaminoo.linkpc.net/7099095090098098/Middle-English-Historiography-by-Robert-A-Albano.pdf
    • http://loaminoo.linkpc.net/6090097099099093/Handbook-of-Middle-English-by-Fernand-Moss-.pdf
    • http://loaminoo.linkpc.net/6090091093095097/History-of-English-Literature-by-Hippolyte-Taine.pdf
    • http://loaminoo.linkpc.net/2097097098096099/The-Norton-Anthology-of-English-Literature-Combined-Set-by-M-H-Abrams.pdf
    • http://loaminoo.linkpc.net/5091090092099090/Beyond-Silence-Chinese-Canadian-Literature-in-English-by-Lien-Chao.pdf
    • http://loaminoo.linkpc.net/1091096090096096099/The-Edinburgh-Introduction-to-Studying-English-Literature-by-Dermot-Cavanagh.pdf
    • http://loaminoo.linkpc.net/1090093096095096090/The-Concise-Cambridge-History-of-English-Literature-by-George-Sampson.pdf
    • http://loaminoo.linkpc.net/8092098090093093/The-Civilising-Mission-and-the-English-Middle-Class-1792-1850-by-Twells-A.pdf
    • http://loaminoo.linkpc.net/3096097091093099/A-Greek-English-Lexicon-of-the-New-Testament-amp-Other-Early-Christian-Literature-by-Walter-Bauer.pdf
    • http://loaminoo.linkpc.net/3096099092095093/English-Lit-Relit-A-Short-History-of-English-Literature-from-the-Precursors-Before-Swearing-to-the-Pre-Raphaelites-and-a-Little-After-Intended-to-Help-Students-See-the-Thing-Through-or-See-Through-the-Thing-and-Om