Malicious PDF — malware analysis report

Static analysis result for SHA-256 b5dda70fe7ecb3c7…

MALICIOUS

PDF

22.9 KB Created: 2019-05-01 17:21:40 +01:00 Authoring application: mPDF 5.7
MD5: da413d9e3fcf2e663ad35546b438bb2e SHA-1: 4cfdd323c2ae0e5f6331a80b36dabdf7e9465547 SHA-256: b5dda70fe7ecb3c7300ab8afc4883105374183d80e8ca33ade40f5ac92402fb6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged the document as malicious. The embedded links point to various book titles hosted on loaminoo.linkpc.net, suggesting a potential link farm or redirection scheme designed to lead users to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090099092094095096/How-to-Make-amp-Use-Talismans-by-Israel-Regardie.pdf
    • http://loaminoo.linkpc.net/3096095098093095/The-Bible-Unearthed-Archaeology-s-New-Vision-of-Ancient-Israel-and-the-Origin-of-Its-Sacred-Texts-by-Israel-Finkelstein.pdf
    • http://loaminoo.linkpc.net/8096093092098097/Who-Is-Israel-Redeemed-Israel---A-Primer-by-Batya-Ruth-Wootten.pdf
    • http://loaminoo.linkpc.net/7090099098096091/Israel-First-The-Key-to-Understanding-the-Blood-Moons-Shemitah-Promises-to-Israel-the-Coming-Jubilee-and-How-It-All-Fits-Together-by-Gidon-Ariel.pdf
    • http://loaminoo.linkpc.net/9092096092092095/Women-In-The-Israel-Defense-Forces-A-Symposium-Held-On-21-November-2002-At-The-Israel-Democracy-Institute-The-Army-And-Society-Forum-by-Baruch-Nevo.pdf
    • http://loaminoo.linkpc.net/9096099098/Ready-or-Not-150-Make-Ahead-Make-Over-and-Make-Now-Recipes-by-Nom-Nom-Paleo-by-Michelle-Tam.pdf
    • http://loaminoo.linkpc.net/8093092094095098/Four-Pretenders-amp-the-Talismans-of-Darkness-amp-Light-Grimlindian-Chronicles-2-by-Melvin-Karew.pdf
    • http://loaminoo.linkpc.net/1090095097090096091/Theodor-Herzl-the-Road-to-Israel-The-Road-to-Israel-by-Miriam-Gurko.pdf
    • http://loaminoo.linkpc.net/5096094092090090/1972-in-Israel-Munich-Massacre-Lod-Airport-Massacre-Abu-Daoud-David-Mark-Berger-Sabena-Flight-571-Israel-at-the-1972-Summer-Olympics-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/4091092098094/The-Talismans-of-Shannara-Heritage-of-Shannara-4-by-Terry-Brooks.pdf
    • http://loaminoo.linkpc.net/2095094096094094/Make-Money-Online-How-I-Make-1700-A-Month-Plus-40-Ways-to-Make-Money-Online-by-Stacey-Davidson.pdf
    • http://loaminoo.linkpc.net/2096090099096095/Make-Me-Shiver-Just-Make-Me-1-by-Aline-Hunter.pdf
    • http://loaminoo.linkpc.net/2090097099097090/Whoogles-Can-a-Dog-Make-a-Woman-Pregnant---And-Hundreds-of-Other-Searches-That-Make-You-Ask-quot-Who-Would-Google-That-quot-by-Kendall-Almerico.pdf
    • http://loaminoo.linkpc.net/2095095091097097/How-to-Make-Love-All-the-Time-Make-Love-Last-a-Lifetime-by-Barbara-De-Angelis.pdf
    • http://loaminoo.linkpc.net/1093097097094/Make-Lemonade-Make-Lemonade-1-by-Virginia-Euwer-Wolff.pdf
    • http://loaminoo.linkpc.net/4090094092090096/Make-Room-Make-Room-by-Harry-Harrison.pdf
    • http://loaminoo.linkpc.net/5090091091092090/Make-Room-Make-Room-by-Harry-Harrison.pdf
    • http://loaminoo.linkpc.net/8098099097094092/Israel-s-Lebanon-War-by-Ze-39-ev-Schiff.pdf
    • http://loaminoo.linkpc.net/6091095094092/Israel-My-Beloved-by-Kay-Arthur.pdf
    • http://loaminoo.linkpc.net/9099098094095098/Israel-in-Palastina-by-Dan-Diner.pdf
    • http://loaminoo.linkpc.net/9092096092092095/Women-In-The-Israel-Defense-Force