Malicious PDF — malware analysis report

Static analysis result for SHA-256 b40816e8ebd55450…

MALICIOUS

PDF

15.7 KB Created: 2019-05-02 17:45:01 +01:00 Authoring application: mPDF 5.7
MD5: f868c63a14d5ee98d7f0186b38e895ae SHA-1: 210051f764f6620b954c389c7440a292d31e2961 SHA-256: b40816e8ebd554507112f525dd8c722d41fded6d06e65b0e6f5ef039c427467b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While the listed URLs themselves are marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to serve as a landing page for further malicious activity. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6098098098097/The-Lamb-s-Supper-The-Mass-as-Heaven-on-Earth-by-Scott-Hahn.pdf
    • http://loaminoo.linkpc.net/9099098099096094/Hail-Holy-Queen-The-Mother-of-God-in-the-Word-of-God-by-Scott-Hahn.pdf
    • http://loaminoo.linkpc.net/9099099091090091/First-Comes-Love-Finding-Your-Family-in-the-Church-and-the-Trinity-by-Scott-Hahn.pdf
    • http://loaminoo.linkpc.net/9099099090092099/Lord-Have-Mercy-The-Healing-Power-of-Confession-by-Scott-Hahn.pdf
    • http://loaminoo.linkpc.net/9099098099096096/A-Father-Who-Keeps-His-Promises-God-s-Covenant-Love-in-Scripture-by-Scott-Hahn.pdf
    • http://loaminoo.linkpc.net/3096092096095092/Hail-Holy-Queen-The-Mother-of-God-in-the-Word-of-God-by-Scott-Hahn.pdf
    • http://loaminoo.linkpc.net/5092093096091/Signs-of-Life-40-Catholic-Customs-and-Their-Biblical-Roots-by-Scott-Hahn.pdf
    • http://loaminoo.linkpc.net/1090090092097099093/Priest-Where-Is-Thy-Mass-Mass-Where-Is-Thy-Priest-Seventeen-Independent-Priests-Tell-Why-They-Celebrate-the-Latin-Mass-by-Angelus-Press.pdf
    • http://loaminoo.linkpc.net/1091094099099096097/Somewhere-in-Heaven-on-Earth-by-Joe-Bonobo.pdf
    • http://loaminoo.linkpc.net/3096098097098092/Heaven-And-Earth-by-Le-Ly-Hayslip.pdf
    • http://loaminoo.linkpc.net/2095094093096/Heaven-on-Earth-by-Constance-O-39-Day-Flannery.pdf
    • http://loaminoo.linkpc.net/6095094096095092/Locke-amp-Key-Heaven-and-Earth-by-Joe-Hill.pdf
    • http://loaminoo.linkpc.net/3094093093098098/Heaven-on-Earth-by-Martyn-Croft.pdf
    • http://loaminoo.linkpc.net/2094099097096093/Heaven-on-Earth-by-Gioconda-Lyss.pdf
    • http://loaminoo.linkpc.net/1091097099098097092/Heaven-on-Earth-by-Gioconda-Lyss.pdf
    • http://loaminoo.linkpc.net/1091094095096096091/In-heaven-on-earth-by-Thomas-W-gstr-m.pdf
    • http://loaminoo.linkpc.net/2096098091094099/The-Stairway-to-Heaven-The-Earth-Chronicles-2-by-Zecharia-Sitchin.pdf
    • http://loaminoo.linkpc.net/8098097095099/Heaven-and-Earth-Three-Sisters-Island-2-by-Nora-Roberts.pdf
    • http://loaminoo.linkpc.net/8099097090093091/Heaven-on-Earth-Art-and-the-Church-in-Byzantium-by-Linda-Safran.pdf
    • http://loaminoo.linkpc.net/1090093097091099093/When-Heaven-Invades-Earth-Multimedia-Kit-by-Bill-Johnson.pdf
    • http://loaminoo.linkpc.net/