Malicious PDF — malware analysis report

Static analysis result for SHA-256 9b8156175915e593…

MALICIOUS

PDF

22.9 KB Created: 2019-04-29 23:07:15 +01:00 Authoring application: mPDF 5.7
MD5: 984800f52e8a44db7664394661afd69b SHA-1: 1107856070f3ebaa32ae45306ca03e161c5097b4 SHA-256: 9b8156175915e59306d4d0becbd3d6531e94e8fa8fa23519254bed47f3ff57ae
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily corrupted, the presence of numerous links suggests a malicious intent, possibly for SEO manipulation or to distribute further malware. The ML classifier also flagged this PDF with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7090098097099099/The-Christian-Remembrancer-Or-Short-Reflections-Upon-the-Faith-Life-and-Conduct-of-a-Real-Christian-by-Ambrose-Serle.pdf
    • http://loaminoo.linkpc.net/7090098098092095/The-Christian-Remembrancer-Or-Short-Reflections-Upon-the-Faith-Life-and-Conduct-of-a-Real-Christian-by-Ambrose-Serle.pdf
    • http://loaminoo.linkpc.net/7090098098091099/The-Christian-Remembrancer-Or-Short-Reflections-Upon-the-Faith-Life-and-Conduct-of-a-Real-Christian-by-Ambrose-Serle.pdf
    • http://loaminoo.linkpc.net/7090098098096093/THE-CHRISTIAN-REMEMBRANCER-by-Ambrose-Serle.pdf
    • http://loaminoo.linkpc.net/5093091099093/Christian-Warrior-Women-A-Guide-to-Taking-Back-Your-Faith-Family-amp-Future-Christian-Warrior-Women-Series-Book-1-by-Lisa-Hawkins.pdf
    • http://loaminoo.linkpc.net/2092091097099093/Food-and-Faith-in-Christian-Culture-by-Ken-Albala.pdf
    • http://loaminoo.linkpc.net/3096097095094093/When-Anything-Goes-Being-Christian-in-a-Post-Christian-World-by-Leslie-Winfield-Williams.pdf
    • http://loaminoo.linkpc.net/2097090098090097/Is-Capitalism-Christian-Toward-a-Christian-Perspective-on-Economics-by-Frank-Schaeffer.pdf
    • http://loaminoo.linkpc.net/2097091098098096/God-amp-Caesar-Christian-Faith-amp-Political-Action-by-John-Eidsmoe.pdf
    • http://loaminoo.linkpc.net/6097094099091097/Why-I-Am-Not-a-Christian-Four-Conclusive-Reasons-to-Reject-the-Faith-by-Richard-C-Carrier.pdf
    • http://loaminoo.linkpc.net/4092094097095090/Voices-of-the-Mystics-Early-Christian-Discourse-in-the-Gospels-of-John-and-Thomas-and-Other-Ancient-Christian-Literature-by-April-D-De-Conick.pdf
    • http://loaminoo.linkpc.net/9096093092095/The-Creator-of-the-Universe-A-Scientific-Approach-to-Christian-Faith-by-Corrado-Ghinamo.pdf
    • http://loaminoo.linkpc.net/2093094097095093/The-Passionate-Intellect-Christian-Faith-and-the-Discipleship-of-the-Mind-by-Alister-E-McGrath.pdf
    • http://loaminoo.linkpc.net/3096094093095091/Arise-and-Walk-How-does-your-Christian-faith-fit-in-a-confused-world-by-Henry-Bocala.pdf
    • http://loaminoo.linkpc.net/2095097095096091/The-Ever-Loving-Truth-Can-Faith-Thrive-in-a-Post-Christian-Culture-by-Voddie-T-Baucham-Jr-.pdf
    • http://loaminoo.linkpc.net/5093095098095093/Proper-Confidence-Faith-Doubt-and-Certainty-in-Christian-Discipleship-by-Lesslie-Newbigin.pdf
    • http://loaminoo.linkpc.net/2093094097094095/Almost-Christian-What-the-Faith-of-Our-Teenagers-Is-Telling-the-American-Church-by-Kenda-Creasy-Dean.pdf
    • http://loaminoo.linkpc.net/9090092095098092/Dr-Christian-s-Guide-To-Growing-Up-by-Christian-Jessen.pdf
    • http://loaminoo.linkpc.net/2097091091092093/Xavier-Doolittle-Christian-End-Times-Short-Story-by-Cliff-Ball.pdf
    • http://loaminoo.linkpc.net/3096096095096099/The-Story-of-Christianity-An-Illustrated-History-of-2000-Years-of-the-Christian-Faith-by-David-Bentley-Hart.pdf