Malicious PDF — malware analysis report

Static analysis result for SHA-256 9e8975bf9f88a13f…

MALICIOUS

PDF

19.4 KB Created: 2019-04-30 05:57:10 +01:00 Authoring application: mPDF 5.7
MD5: a82bef9fa1942b5101e488135a7782a9 SHA-1: d9e3adc619507e62d4a47379c0876e8ed9b312d0 SHA-256: 9e8975bf9f88a13f9e581365f06098ec8abe52ffc42d1a2f7b63e89650913e2e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged by a machine learning classifier as malicious. The primary heuristic indicates a 'PDF_SEO_LINK_FARM' with 24 external links, suggesting a tactic to manipulate search results or distribute malicious content. While the document body is unreadable, the presence of numerous links to external PDFs, many with numeric slugs, points towards a link farm or SEO poisoning attack. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2091094097093099/Subversion-as-Foreign-Policy-The-Secret-Eisenhower-and-Dulles-Debacle-in-Indonesia-by-Audrey-R-Kahin.pdf
    • http://loaminoo.linkpc.net/1096091096097/A-Proposal-Key-to-an-Effective-Foreign-Policy-by-Max-F-Millikan.pdf
    • http://loaminoo.linkpc.net/3097091090092098/American-Foreign-Policy-by-Henry-Kissinger.pdf
    • http://loaminoo.linkpc.net/1096091096099/Nuclear-Weapons-And-Foreign-Policy-by-Henry-Kissinger.pdf
    • http://loaminoo.linkpc.net/8092095098094095/Turkish-Foreign-Policy-Since-1774-by-William-Hale.pdf
    • http://loaminoo.linkpc.net/2095095091097092/The-Israel-Lobby-and-U-S-Foreign-Policy-by-John-J-Mearsheimer.pdf
    • http://loaminoo.linkpc.net/8093093093092092/Israel-Lobby-And-U-S-Foreign-Policy-by-John-J-Mearsheimer.pdf
    • http://loaminoo.linkpc.net/2095096099095091/21-Lies-They-Tell-You-About-American-Foreign-Policy-by-Brett-Saxon-Morris.pdf
    • http://loaminoo.linkpc.net/5091099098094093/The-Foreign-Policy-Disconnect-What-Americans-Want-from-Our-Leaders-but-Don-t-Get-by-Benjamin-I-Page.pdf
    • http://loaminoo.linkpc.net/7093093098099/The-Godfather-Doctrine-A-Foreign-Policy-Parable-by-John-C-Hulsman.pdf
    • http://loaminoo.linkpc.net/1095094094094096/Rise-to-Globalism-American-Foreign-Policy-since-1938-by-Stephen-E-Ambrose.pdf
    • http://loaminoo.linkpc.net/6094094099095/A-Creative-Tension-The-Foreign-Policy-Roles-of-the-President-and-Congress-by-Lee-H-Hamilton.pdf
    • http://loaminoo.linkpc.net/1091090091099097/To-the-Farewell-Address-Ideas-of-Early-American-Foreign-Policy-by-Felix-Gilbert.pdf
    • http://loaminoo.linkpc.net/1090092091095099093/Joining-Empire-The-Political-Economy-of-the-New-Canadian-Foreign-Policy-by-Jerome-Klassen.pdf
    • http://loaminoo.linkpc.net/1091093095099098091/Readings-in-Canadian-Foreign-Policy-Classic-Debates-and-New-Ideas-by-Duane-Bratt.pdf
    • http://loaminoo.linkpc.net/7098091099090090/The-Artillery-of-the-Press-Its-Influence-on-American-Foreign-Policy-by-James-Barrett-Reston.pdf
    • http://loaminoo.linkpc.net/1090092098095092092/Expansion-and-Coexistence-Soviet-Foreign-Policy-1917-1973-by-Adam-B-Ulam.pdf
    • http://loaminoo.linkpc.net/2093092092099/John-Quincy-Adams-and-the-Foundations-of-American-Foreign-Policy-by-Samuel-Flagg-Bemis.pdf
    • http://loaminoo.linkpc.net/5092092090093098/This-Vast-Southern-Empire-Slaveholders-at-the-Helm-of-American-Foreign-Policy-by-Matthew-Karp.pdf
    • http://loaminoo.linkpc.net/4093096093090093/Magic-and-Mayhem-The-Delusions-of-American-Foreign-Policy-from-Korea-to-Afghanistan-by-Derek-Leebaert.pdf