Malicious PDF — malware analysis report

Static analysis result for SHA-256 b3d7c8624334d00a…

MALICIOUS

PDF

16.7 KB Created: 2019-04-28 10:15:51 +01:00 Authoring application: mPDF 5.7
MD5: 320429f397e2adde6f4c3e6909183f7b SHA-1: 569ab696d4d48b6a6a08caebc43d4b16334f5a19 SHA-256: b3d7c8624334d00a0eb7349033b7262f02edc37bc9f9a4121737af13f6f5b888
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links point to documents with benign titles, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a lure for malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2098093090091092/The-Battle-For-Justice-In-Palestine-The-Case-for-a-Single-Democratic-State-in-Palestine-by-Ali-Abunimah.pdf
    • http://loaminoo.linkpc.net/8099099097095095/Greek-in-Jewish-Palestine-Hellenism-in-Jewish-Palestine-by-Saul-Lieberman.pdf
    • http://loaminoo.linkpc.net/4098096090090090/The-Two-State-Delusion-Israel-and-Palestine-A-Tale-of-Two-Narratives-by-Padraig-O-39-Malley.pdf
    • http://loaminoo.linkpc.net/1098094090098094/Israel-Palestine-How-to-End-the-War-of-1948-by-Tanya-Reinhart.pdf
    • http://loaminoo.linkpc.net/9094098097090090/Sinai-and-Palestine-by-Arthur-Penrhyn-Stanley.pdf
    • http://loaminoo.linkpc.net/1098095098096090/Palestine-Peace-Not-Apartheid-by-Jimmy-Carter.pdf
    • http://loaminoo.linkpc.net/8099098091091/The-Way-to-the-Spring-Life-and-Death-in-Palestine-by-Ben-Ehrenreich.pdf
    • http://loaminoo.linkpc.net/1090091090097092093/Haifa-or-Life-in-modern-Palestine-by-Laurence-Oliphant.pdf
    • http://loaminoo.linkpc.net/1090091090094090/Palestine-Inside-Out-An-Everyday-Occupation-by-Saree-Makdisi.pdf
    • http://loaminoo.linkpc.net/7096099097096099/Gaza-Mom-Palestine-Politics-Parenting-and-Everything-in-Between-by-Laila-El-Haddad.pdf
    • http://loaminoo.linkpc.net/2098093093097093/From-India-to-Palestine-Essays-in-Solidarity-by-Githa-Hariharan.pdf
    • http://loaminoo.linkpc.net/3097095095092097/Palestine-History-of-a-Lost-Nation-by-Karl-Sabbagh.pdf
    • http://loaminoo.linkpc.net/1098095099092096/Palestine-Speaks-Narratives-of-Life-Under-Occupation-by-Cate-Malek.pdf
    • http://loaminoo.linkpc.net/9092096092098095/King-Abdallah-And-Palestine-A-Territorial-Ambition-by-Joseph-Nevo.pdf
    • http://loaminoo.linkpc.net/5096093092097090/Poetic-Injustice-Writings-on-Resistance-and-Palestine-by-Remi-Kanazi.pdf
    • http://loaminoo.linkpc.net/8094093098091092/Letters-to-Palestine-Writers-Respond-to-War-and-Occupation-by-Vijay-Prashad.pdf
    • http://loaminoo.linkpc.net/3097095097097097/The-Palestine-Diary-Volume-One-1914-1945-by-Sami-Hadawi.pdf
    • http://loaminoo.linkpc.net/6098090093097095/Isra-l-Palestine-une-terre-pour-deux-by-G-rard-Dh-tel.pdf
    • http://loaminoo.linkpc.net/7094090091091095/The-Palestine-Israeli-Conflict-A-Beginner-s-Guide-by-Dan-Cohn-Sherbok.pdf
    • http://loaminoo.linkpc.net/3097095099097095/Bitter-Harvest-A-Modern-History-of-Palestine-by-Sami-Hadawi.pdf
    • http://loaminoo.linkpc.net/1090091090094090/Palestine-Inside-Out-