Malicious PDF — malware analysis report

Static analysis result for SHA-256 a3965983c837823e…

MALICIOUS

PDF

27.9 KB Created: 2019-04-30 02:43:25 +01:00 Authoring application: mPDF 5.7
MD5: 1417b3ef2538e203ef2f6e3dcb46cba4 SHA-1: 93416b51733e3ef496cd16062489b63789d2ff3c SHA-256: a3965983c837823e7f2b866b11fb4c2ada60a801562873c829147d57e1c28b2f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The heuristic PDF_SEO_LINK_FARM indicates that these are likely intended to direct users to external content. While the document body is heavily obfuscated, the presence of numerous links suggests a social engineering attempt to drive traffic to potentially malicious or misleading content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9908

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8093097093098096/Chemistry-Meteorology-and-the-Function-of-Digestion-Considered-with-Reference-to-Natural-Theology-by-William-Prout.pdf
    • http://loaminoo.linkpc.net/9096097096093098/Jewish-Theology-Systematically-and-Historically-Considered-by-Kaufmann-Kohler.pdf
    • http://loaminoo.linkpc.net/9096099096099096/The-Natural-Pharmacy-Complete-Home-Reference-to-Natural-Medicine-by-Schuyler-W-Lininger-Jr-.pdf
    • http://loaminoo.linkpc.net/3099099098098099/Smart-Medicine-for-a-Healthier-Child-A-Practical-A-to-Z-Reference-to-Natural-and-Conventional-Treatments-for-Infants-and-Children-by-Janet-Zand.pdf
    • http://loaminoo.linkpc.net/2092091098090094/Natural-Religion-amp-Christian-Theology-Vol-1-Science-amp-Religion-Gifford-Lectures-1951-by-Charles-E-Raven.pdf
    • http://loaminoo.linkpc.net/8093097091097090/The-Kirsten-Prout-Handbook---Everything-You-Need-to-Know-about-Kirsten-Prout-by-Emily-Smith.pdf
    • http://loaminoo.linkpc.net/8093097093090092/Harmony-Its-No-and-Practice-Its-Theory-Ts-Theory-by-Ebenezer-Prout-B-Prout.pdf
    • http://loaminoo.linkpc.net/7095091090099099/The-Symbolism-of-Voltaire-s-Novels-with-Special-Reference-to-Zadig-by-William-Raleigh-Price.pdf
    • http://loaminoo.linkpc.net/7095091091092098/The-Symbolism-of-Voltaire-s-Novels-with-Special-Reference-to-Zadig-Pp-1-257-by-William-Raleigh-Price.pdf
    • http://loaminoo.linkpc.net/1093098093099097/Systematic-Theology-Vol-1-Ethics-by-James-William-McClendon-Jr-.pdf
    • http://loaminoo.linkpc.net/8093097093090097/An-Inquiry-Into-the-Nature-and-Treatment-of-Diabetes-Calculus-And-Other-Affections-of-the-Urinary-Organs-With-Remarks-on-the-Importance-of-Attending-to-the-State-of-the-Urine-in-Organic-Diseases-of-the-Kidney-and-Bladder-by-William-Prout.pdf
    • http://loaminoo.linkpc.net/1098099098099099/Visual-Faith-Art-Theology-and-Worship-in-Dialogue-by-William-A-Dyrness.pdf
    • http://loaminoo.linkpc.net/3093099099092090/The-Theology-And-Spirituality-of-Mary-Tudor-s-Church-by-William-Wizeman.pdf
    • http://loaminoo.linkpc.net/1091092095099098096/The-Fiction-of-L-Ron-Hubbard-A-Comprehensive-Bibliography-and-Reference-Guide-to-Published-and-Selected-Unpublished-Works-by-William-J-Widder.pdf
    • http://loaminoo.linkpc.net/7093091096099090/The-Reformed-Objection-to-Natural-Theology-by-Michael-Sudduth-by-Michael-Sudduth.pdf
    • http://loaminoo.linkpc.net/1090097092091096098/Chemistry-for-Higher-Education-A-Practical-Guide-to-Designing-a-Course-in-Chemistry-by-Jan-H-Apotheker.pdf
    • http://loaminoo.linkpc.net/1091097091091098093/Topics-in-Current-Chemistry-Volume-258-Supramolecular-Dye-Chemistry-by-Frank-W-rthner.pdf
    • http://loaminoo.linkpc.net/6098091092096091/Physical-Inorganic-Chemistry-A-Coordination-Chemistry-Approach-by-S-F-A-Kettle.pdf
    • http://loaminoo.linkpc.net/9091092092099099/Systematic-Theology-Perpspectives-from-Liberation-Theology-Readings-from-Mysterium-Liberationis-by-Jon-Sobrino.pdf
    • http://loaminoo.linkpc.net/6091093098094098/Symphonic-Theology-The-Validity-of-Multiple-Perspectives-in-Theology-by-Vern-Sheridan-Poythress.pdf
    • http://loaminoo.linkpc.net/3099099098098099/Smart-Medicine-for