Malicious PDF — malware analysis report

Static analysis result for SHA-256 c07c607dd71e1901…

MALICIOUS

PDF

24.1 KB Created: 2019-04-29 23:28:36 +01:00 Authoring application: mPDF 5.7
MD5: 329d594db04ac29fafcfc2d594b5b9e8 SHA-1: 59b70c9293c058e96b084480883b713e480b447e SHA-256: c07c607dd71e1901b67f0b875f04b32724369eb46016b0539b5ba2098488c5ea
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While the linked content appears to be related to Christian leadership and spirituality, the sheer volume and the use of a link farm suggest a deceptive tactic. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc
    • http://loaminoo.linkpc.net/9096098091092099/A-Call-to-Lead-Spirit-Filled-Christian-Leadership-by-Adjei-Kyere-Duodu.pdf
    • http://loaminoo.linkpc.net/5094092097094094/How-to-Be-Filled-with-the-Holy-Spirit-by-A-W-Tozer.pdf
    • http://loaminoo.linkpc.net/5094092098096097/The-Spirit-Filled-Life-by-Charles-F-Stanley.pdf
    • http://loaminoo.linkpc.net/5094092098096098/The-Spirit-Filled-Believer-s-Handbook-by-Derek-Prince.pdf
    • http://loaminoo.linkpc.net/9096090090091/Spirit-Filled-Words-To-Awaken-the-Sleeping-Giant-by-Jessica-Cager.pdf
    • http://loaminoo.linkpc.net/5094092097094096/New-Spirit-Filled-Life-Bible-Kingdom-Equipping-Through-the-Power-of-the-Word-by-Anonymous.pdf
    • http://loaminoo.linkpc.net/7091090094094099/Lead-Like-It-Matters-Because-It-Does-Core-Leadership-Tools-That-Engage-Employees-Attract-Talent-and-Move-Business-Forward-by-Roxana-Bahar-Hewertson.pdf
    • http://loaminoo.linkpc.net/2093094097094097/Christians-Are-Hate-Filled-Hypocrites-and-Other-Lies-You-ve-Been-Told-A-Sociologist-Shatters-Myths-from-the-Secular-and-Christian-Media-by-Bradley-R-E-Wright.pdf
    • http://loaminoo.linkpc.net/8098094093095/Bearing-the-Cross-Martin-Luther-King-Jr-and-the-Southern-Christian-Leadership-Conference-by-David-J-Garrow.pdf
    • http://loaminoo.linkpc.net/7097090091096093/The-Holy-Spirit-Contours-of-Christian-Theology-6-by-Sinclair-B-Ferguson.pdf
    • http://loaminoo.linkpc.net/5094092098093092/Smith-Wigglesworth-on-Spirit-Filled-Living-by-Smith-Wigglesworth.pdf
    • http://loaminoo.linkpc.net/7092091099097097/Call-Centre-Work-Smile-by-Wire-by-Christian-Dormann.pdf
    • http://loaminoo.linkpc.net/5098094092093091/Novel-Anticancer-Agents-Strategies-for-Discovery-and-Clinical-Testing-by-Alex-A-Adjei.pdf
    • http://loaminoo.linkpc.net/1090091095093095/Leadership-Mosaic-5-Leadership-Principles-for-Ministry-and-Everyday-Life-by-Daniel-Montgomery.pdf
    • http://loaminoo.linkpc.net/4099098090099090/Leadership-and-the-One-Minute-Manager-Increasing-Effectiveness-Through-Situational-Leadership-by-Kenneth-H-Blanchard.pdf
    • http://loaminoo.linkpc.net/1090093090092091/The-Toyota-Way-to-Lean-Leadership-Achieving-and-Sustaining-Excellence-Through-Leadership-Development-by-Jeffrey-K-Liker.pdf
    • http://loaminoo.linkpc.net/4096093091092092/Leadership-Reflections-on-Biblical-Leadership-Today-by-Philip-Greenslade.pdf
    • http://loaminoo.linkpc.net/1091095099092096090/WALKING-IN-THE-SPIRIT-A-STUDY-OF-PAUL-S-TEACHING-ON-THE-SPIRIT-AND-ETHICS-IN-GALATIANS-by-KWESI-OTOO.pdf
    • http://loaminoo.linkpc.net/1090090093090093099/Enhancing-Your-Executive-Edge-How-to-Develop-the-Skills-to-Lead-and-Succeed-How-to-Develop-the-Skills-to-Lead-and-Succeed-by-Kim-Zoller.pdf
    • http://loaminoo.linkpc.net/4091091094090095/Dark-Spirit-Spirit-Wild-2-by-Kate-Douglas.pdf