Malicious PDF — malware analysis report

Static analysis result for SHA-256 9bfad231a3b5ec28…

MALICIOUS

PDF

17.7 KB Created: 2019-04-30 04:21:44 +01:00 Authoring application: mPDF 5.7
MD5: 1abfb4f5cb17b7763b45fdec30eb4f0a SHA-1: 339ad8444f148971ebd0ddc75672e74c5626e6c8 SHA-256: 9bfad231a3b5ec28dd53d488516152f579ba0cd7be962a5655e18223bb0814fa
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links are marked as benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, possibly for SEO manipulation or to distribute further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1095094095094096/The-Next-Founders-Voices-of-Democracy-in-the-Middle-East-by-Joshua-Muravchik.pdf
    • http://loaminoo.linkpc.net/5098098096095090/Prophetic-Voices-on-Middle-East-Peace-A-Jewish-Christian-and-Humanist-Primer-on-Colonialism-Zionism-amp-Nationalism-in-the-Middle-East-by-Thomas-E-Phillips.pdf
    • http://loaminoo.linkpc.net/2097095094094093/Making-David-into-Goliath-How-the-World-Turned-Against-Israel-by-Joshua-Muravchik.pdf
    • http://loaminoo.linkpc.net/6090099094097096/The-Civilizations-of-the-East-Near-and-Middle-East-by-Ren-Grousset.pdf
    • http://loaminoo.linkpc.net/7097097096095090/Taming-Democracy-quot-the-People-quot-the-Founders-and-the-Troubled-Ending-of-the-American-Revolution-by-Terry-Bouton.pdf
    • http://loaminoo.linkpc.net/6090099091097090/Dismantling-Democracy-Stifling-debate-and-dissent-in-Canada-by-voices-voix.pdf
    • http://loaminoo.linkpc.net/6097092094090/Love-Poems-from-God-Twelve-Sacred-Voices-from-the-East-and-West-by-Daniel-Ladinsky.pdf
    • http://loaminoo.linkpc.net/6091093096094098/The-Multiple-Identities-of-the-Middle-East-by-Bernard-Lewis.pdf
    • http://loaminoo.linkpc.net/8096090097096092/A-Concise-History-of-the-Middle-East-by-Arthur-Goldschmidt-Jr-.pdf
    • http://loaminoo.linkpc.net/9092095097092098/Assignment-Cyprus-Middle-East-Mission-by-Trooper.pdf
    • http://loaminoo.linkpc.net/1091098090094099092/Middle-East-War-Imperialism-and-Ecology-by-Roland-Rance.pdf
    • http://loaminoo.linkpc.net/3098094091091090/America-s-War-for-the-Greater-Middle-East-by-Andrew-J-Bacevich.pdf
    • http://loaminoo.linkpc.net/9091093097098/The-Middle-East-Bedside-Book-by-Tahir-Shah.pdf
    • http://loaminoo.linkpc.net/4090093097095091/The-Poisoned-Well-Empire-and-Its-Legacy-in-the-Middle-East-by-Roger-Hardy.pdf
    • http://loaminoo.linkpc.net/6094098094097091/Madinah-City-Stories-from-the-Middle-East-by-Nedim-Gursel.pdf
    • http://loaminoo.linkpc.net/6097090093097095/The-Arab-Awakening-Islam-and-the-New-Middle-East-by-Tariq-Ramadan.pdf
    • http://loaminoo.linkpc.net/6092094095094095/Managing-Human-Resources-in-the-Middle-East-by-Kamel-Mellahi.pdf
    • http://loaminoo.linkpc.net/5099097092093090/From-Babel-to-Dragomans-Interpreting-the-Middle-East-by-Bernard-Lewis.pdf
    • http://loaminoo.linkpc.net/1094099097094/19-Varieties-of-Gazelle-Poems-of-the-Middle-East-by-Naomi-Shihab-Nye.pdf
    • http://loaminoo.linkpc.net/6094098093095099/Madinah-City-Stories-from-the-Middle-East-by-Joumana-Haddad.pdf