Malicious PDF — malware analysis report

Static analysis result for SHA-256 c06778f85ed2c57b…

MALICIOUS

PDF

20.5 KB Created: 2019-05-07 04:11:15 +01:00 Authoring application: mPDF 5.7
MD5: fc3ebcd3efc9baa0e0f1c2f5b6e8905a SHA-1: aec13e9d32866f91208547d69000d08135acddd9 SHA-256: c06778f85ed2c57b813f9ccf47c758ab4fb94b881157030f1b322654ee2248cf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to external PDF documents hosted on a dynamic DNS domain. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier strongly flagged this PDF as malicious, supporting the assessment of a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3093099099092090/The-Theology-And-Spirituality-of-Mary-Tudor-s-Church-by-William-Wizeman.pdf
    • http://loaminoo.linkpc.net/5094092090097092/Church-Charism-and-Power-Liberation-Theology-and-the-Institutional-Church-by-Leonardo-Boff.pdf
    • http://loaminoo.linkpc.net/6098091098099099/Reel-Spirituality-Theology-and-Film-in-Dialogue-by-Robert-K-Johnston.pdf
    • http://loaminoo.linkpc.net/3093099098099099/Mary-Tudor-Courageous-Queen-or-Bloody-Mary-by-Jane-Buchanan.pdf
    • http://loaminoo.linkpc.net/6093091095098094/The-Mystery-of-Faith-An-Introduction-to-the-Teaching-and-Spirituality-of-the-Orthodox-Church-by-Hilarion-Alfeyev.pdf
    • http://loaminoo.linkpc.net/8094094094096093/Theses-on-Justification-by-Commission-on-Theology-and-Church-Relations.pdf
    • http://loaminoo.linkpc.net/4092094091097094/The-Church-Contours-of-Christian-Theology-4-by-Edmund-P-Clowney.pdf
    • http://loaminoo.linkpc.net/1090093097091094096/Integrating-Spirituality-into-Multicultural-Counseling-by-Mary-A-Fukuyama.pdf
    • http://loaminoo.linkpc.net/3094090091095093/Mary-Tudor-The-White-Queen-by-Walter-C-Richardson.pdf
    • http://loaminoo.linkpc.net/1095092094094097/Mary-Tudor-Princess-Bastard-Queen-by-Anna-Whitelock.pdf
    • http://loaminoo.linkpc.net/1093098093099097/Systematic-Theology-Vol-1-Ethics-by-James-William-McClendon-Jr-.pdf
    • http://loaminoo.linkpc.net/2097094092090092/The-Sisters-Who-Would-Be-Queen-Mary-Katherine-and-Lady-Jane-Grey-A-Tudor-Tragedy-by-Leanda-de-Lisle.pdf
    • http://loaminoo.linkpc.net/3093099099090099/Reforming-Catholicism-in-the-England-of-Mary-Tudor-The-Achievement-of-Friar-Bartolom-Carranza-by-John-Edwards.pdf
    • http://loaminoo.linkpc.net/1098099098099099/Visual-Faith-Art-Theology-and-Worship-in-Dialogue-by-William-A-Dyrness.pdf
    • http://loaminoo.linkpc.net/2096093099091098/How-To-Be-a-Tudor-A-Dawn-to-Dusk-Guide-to-Tudor-Life-by-Ruth-Goodman.pdf
    • http://loaminoo.linkpc.net/1094099091090098/The-Tudor-Heresy-The-Tudor-Mystery-Trials-0-5-by-Samantha-Burnell.pdf
    • http://loaminoo.linkpc.net/1091093094090098092/Church-by-William-Henn.pdf
    • http://loaminoo.linkpc.net/8093097093098096/Chemistry-Meteorology-and-the-Function-of-Digestion-Considered-with-Reference-to-Natural-Theology-by-William-Prout.pdf
    • http://loaminoo.linkpc.net/3099091095096094/Buddhist-Spirituality-II-Later-China-Korea-Japan-and-the-Modern-World-World-Spirituality-An-Encyclopedic-History-of-the-Religious-Quest-Volume-9-by-Takeuchi-Yoshinori.pdf
    • http://loaminoo.linkpc.net/2098096093098/Split-A-Child-a-Priest-and-the-Catholic-Church-by-Mary-Dispenza.pdf
    • http://loaminoo.linkpc.net/10950920