Malicious PDF — malware analysis report

Static analysis result for SHA-256 d20b8d3c922638c0…

MALICIOUS

PDF

25.3 KB Created: 2019-04-30 17:29:01 +01:00 Authoring application: mPDF 5.7
MD5: c885783ae6abf597a2d117aabccdd002 SHA-1: f1ce94cc2e85602d1d3c72347e58e68d2bdb74fa SHA-256: d20b8d3c922638c051195ac88eb0d5572c0a6b3399602df6514a1c93ee3f2f22
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are classified as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to distribute further malware. The ML_NYX_PDF_MALICIOUS classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9910

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2093095091098/The-Cousins-Wars-Religion-Politics-and-the-Triumph-of-Anglo-America-by-Kevin-Phillips.pdf
    • http://loaminoo.linkpc.net/1098099092093095/American-Dynasty-Aristocracy-Fortune-and-the-Politics-of-Deceit-in-the-House-of-Bush-by-Kevin-Phillips.pdf
    • http://loaminoo.linkpc.net/3096095095095097/The-Right-to-Be-Wrong-Ending-the-Culture-War-over-Religion-in-America-by-Kevin-Seamus-Hasson.pdf
    • http://loaminoo.linkpc.net/6093093093099093/The-Mormonizing-of-America-How-the-Mormon-Religion-Became-a-Dominant-Force-in-Politics-Entertainment-and-Pop-Culture-by-Stephen-Mansfield.pdf
    • http://loaminoo.linkpc.net/1095092098099092/Never-Too-Late-Carolina-Cousins-3-by-Michael-R-Phillips.pdf
    • http://loaminoo.linkpc.net/1095092092091096/Travail-and-Triumph-The-Russians-3-by-Michael-R-Phillips.pdf
    • http://loaminoo.linkpc.net/5092092097091098/Politics-at-the-Centre-The-Selection-and-Removal-of-Party-Leaders-in-the-Anglo-Parliamentary-Democracies-by-William-P-Cross.pdf
    • http://loaminoo.linkpc.net/1098096098091097/One-Electorate-under-God-A-Dialogue-on-Religion-and-American-Politics-by-E-J-Dionne-Jr-.pdf
    • http://loaminoo.linkpc.net/9094097097096/Revengeful-Heart-Magic-Wars-Collection-1-by-Chrys-Phillips.pdf
    • http://loaminoo.linkpc.net/8099097091093095/The-Secular-and-the-Sacred-Nation-Religion-and-Politics-by-William-Safran.pdf
    • http://loaminoo.linkpc.net/2092098091095096/Why-We-Love-the-Church-In-Praise-of-Institutions-and-Organized-Religion-by-Kevin-DeYoung.pdf
    • http://loaminoo.linkpc.net/6096096094095090/The-Russians-The-Crown-and-the-Crucible-A-House-Divided-Travail-and-Triumph-Heirs-of-the-Motherland-The-Dawning-of-Deliverance-The-Russians-1-5-by-Michael-R-Phillips.pdf
    • http://loaminoo.linkpc.net/2093093099094/Fear-City-New-York-s-Fiscal-Crisis-and-the-Rise-of-Austerity-Politics-by-Kim-Phillips-Fein.pdf
    • http://loaminoo.linkpc.net/1090092091096094/Buddhism-Betrayed-Religion-Politics-and-Violence-in-Sri-Lanka-by-Stanley-Jeyaraja-Tambiah.pdf
    • http://loaminoo.linkpc.net/7095098094096093/The-Many-Faces-of-Political-Islam-Religion-and-Politics-in-the-Muslim-World-by-Mohammed-Ayoob.pdf
    • http://loaminoo.linkpc.net/1091097094092099096/Seculosity-How-Career-Parenting-Technology-Food-Politics-and-Romance-Became-Our-New-Religion-and-What-to-Do-about-It-by-David-Zahl.pdf
    • http://loaminoo.linkpc.net/9091099098098094/Star-Wars-Flucht-ins-Ungewisse-by-Kevin-J-Anderson.pdf
    • http://loaminoo.linkpc.net/1098099097092093/Age-of-Greed-The-Triumph-of-Finance-and-the-Decline-of-America-1970-to-the-Present-by-Jeff-Madrick.pdf
    • http://loaminoo.linkpc.net/3097090090098096/All-the-Presidents-Children-Triumph-and-Tragedy-in-the-Lives-of-America-s-First-Families-by-Doug-Wead.pdf
    • http://loaminoo.linkpc.net/1090095096092091/From-a-World-at-War-to-the-Triumph-of-Freedom-1914-1989-America-The-Last-Best-Hope-2-by-William-J-Bennett.pdf
    • http://loaminoo.linkpc.net/1095092098099092/Never