Malicious PDF — malware analysis report

Static analysis result for SHA-256 a0c9bad3cc467aa0…

MALICIOUS

PDF

20.7 KB Created: 2019-05-05 08:46:51 +01:00 Authoring application: mPDF 5.7
MD5: 2207c0f8842f0f8fb7fa6ad7e8e40fda SHA-1: d19656135d0035445767361b8f2af02a22c103f1 SHA-256: a0c9bad3cc467aa02f07ab1e00f37279eed9ccbffca37a490381806fe02305e8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to what appear to be benign book titles, the sheer volume and the use of a dynamic DNS hostname (linkpc.net) suggest a malicious intent, possibly for SEO poisoning or to redirect users to further malicious content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2095092096091092/One-Life-Jesus-Calls-We-Follow-by-Scot-McKnight.pdf
    • http://loaminoo.linkpc.net/2094099097090092/The-King-Jesus-Gospel-The-Original-Good-News-Revisited-by-Scot-McKnight.pdf
    • http://loaminoo.linkpc.net/1094093092091095/The-Jesus-Creed-Loving-God-Loving-Others-by-Scot-McKnight.pdf
    • http://loaminoo.linkpc.net/1091092099099097091/Follow-Learning-to-Follow-Jesus-by-Daniel-McNaughton.pdf
    • http://loaminoo.linkpc.net/1094093091096092/Embracing-Grace-A-Gospel-for-All-of-Us-by-Scot-McKnight.pdf
    • http://loaminoo.linkpc.net/1096097093091098/Follow-That-Map-A-First-Book-of-Mapping-Skills-by-Scot-Ritchie.pdf
    • http://loaminoo.linkpc.net/1091095095096090095/Raising-Jesus-Lore-and-tradition-cloak-her-in-mystique-Now-experience-her-life-From-the-bliss-of-youth-to-the-foot-of-the-cross-see-the-birth-of-salvation-through-the-eyes-of-Mary-mother-of-Jesus-by-Angela-Schans.pdf
    • http://loaminoo.linkpc.net/1098096094099/Infinite-Variety-The-Life-and-Legend-of-the-Marchesa-Casati-by-Scot-D-Ryersson.pdf
    • http://loaminoo.linkpc.net/3095098092093095/Night-Calls-Night-Calls-Series-1-by-Katharine-Eliska-Kimbriel.pdf
    • http://loaminoo.linkpc.net/1091096098091091099/Confessions-of-an-Undercover-Agent-Adventures-Close-Calls-and-the-Toll-of-a-Double-Life-by-Charlie-Spillers.pdf
    • http://loaminoo.linkpc.net/4093093094090096/Follow-Me-Follow-You-by-Laura-E-James.pdf
    • http://loaminoo.linkpc.net/2092095094091/Cassie-Scot-Cassie-Scot-1-by-Christine-Amsden.pdf
    • http://loaminoo.linkpc.net/1090093099097095/Cassie-Scot-Cassie-Scot-1-by-Christine-Amsden.pdf
    • http://loaminoo.linkpc.net/3096092093096094/Jesus-The-Greatest-Life-of-All-by-Charles-R-Swindoll.pdf
    • http://loaminoo.linkpc.net/2096091092098097/Strengths-Based-Leadership-Great-Leaders-Teams-and-Why-People-Follow-A-Landmark-Study-of-Great-Leaders-Teams-and-the-Reasons-Why-We-Follow-by-Tom-Rath.pdf
    • http://loaminoo.linkpc.net/1090097097094097096/The-Road-to-New-Life-The-Way-of-Jesus-of-Nazareth-by-Phil-Rehberg.pdf
    • http://loaminoo.linkpc.net/3096093092096093/The-True-Life-of-Jesus-of-Nazareth-by-Alexander-Smyth.pdf
    • http://loaminoo.linkpc.net/2097092093092090/The-Greatest-Words-Ever-Spoken-Everything-Jesus-Said-about-You-Your-Life-and-Everything-Else-by-Steven-K-Scott.pdf
    • http://loaminoo.linkpc.net/1090097097093094094/The-Light-of-the-World-The-Life-and-Teachings-of-Jesus-of-Nazareth-by-Tim-Spiess.pdf
    • http://loaminoo.linkpc.net/6092092091091096/They-Walked-with-Jesus-Past-Life-Experiences-with-Christ-by-Dolores-Cannon.pdf
    • http://loaminoo.linkpc.net/1091095095096