Malicious PDF — malware analysis report

Static analysis result for SHA-256 d8c389b1df2cc890…

MALICIOUS

PDF

24.1 KB Created: 2019-04-30 17:46:18 +01:00 Authoring application: mPDF 5.7
MD5: 2b3ca0c55eaecd39414ef51a2a94182f SHA-1: 0eb8974cf7da3c034c8cc1fea0215615ab3fc09a SHA-256: d8c389b1df2cc8907766dba2ba90b6daa0e3906d8821cc3ea076805f789a14cf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While most of these URLs are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a landing page for further malicious activity. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091092091099094090/The-Apostolic-Age-of-the-Christian-Church-Volume-1-by-Carl-Weizsacker.pdf
    • http://loaminoo.linkpc.net/1091092091098096090/Weizs-cker-Neue-Testament-by-Carl-Heinrich-Weizs-cker.pdf
    • http://loaminoo.linkpc.net/1091092092091093091/Carl-Friedrich-Von-Weizsacker-Major-Texts-on-Politics-and-Peace-Research-by-Ulrich-Bartosch.pdf
    • http://loaminoo.linkpc.net/1091090090098098097/The-Life-of-Carl-Theodor-Korner-Volume-1-by-Christian-Gottfried-Korner.pdf
    • http://loaminoo.linkpc.net/9090097095097094/Lieber-Freund-Lieber-Gegner-Briefe-Aus-Funf-Jahrzehnten-by-Carl-Friedrich-Weizsacker.pdf
    • http://loaminoo.linkpc.net/4091093093090096/Church-History-Volume-One-From-Christ-to-Pre-Reformation-The-Rise-and-Growth-of-the-Church-in-Its-Cultural-Intellectual-and-Political-Context-by-Everett-Ferguson.pdf
    • http://loaminoo.linkpc.net/6096099094096094/Bruton-Parish-Church-An-Architectural-History-by-Carl-Lounsbury.pdf
    • http://loaminoo.linkpc.net/1091092092091092094/Ernst-Ulrich-Von-Weizsacker-A-Pioneer-on-Environmental-Climate-and-Energy-Policies-by-Ernst-Ulrich-Weizsacker.pdf
    • http://loaminoo.linkpc.net/4092094091097094/The-Church-Contours-of-Christian-Theology-4-by-Edmund-P-Clowney.pdf
    • http://loaminoo.linkpc.net/3096099097099094/The-Fathers-of-the-Church-An-Introduction-to-the-First-Christian-Teachers-by-Mike-Aquilina.pdf
    • http://loaminoo.linkpc.net/4092094091095098/If-the-Church-Were-Christian-Rediscovering-the-Values-of-Jesus-by-Philip-Gulley.pdf
    • http://loaminoo.linkpc.net/8098099094095096/Old-Testament-Criticism-and-the-Christian-Church-by-John-Edgar-McFadyen.pdf
    • http://loaminoo.linkpc.net/2093094097094095/Almost-Christian-What-the-Faith-of-Our-Teenagers-Is-Telling-the-American-Church-by-Kenda-Creasy-Dean.pdf
    • http://loaminoo.linkpc.net/4095096099099/A-Church-in-the-House-Restoring-Daily-Worship-to-the-Christian-Household-by-Matthew-Henry.pdf
    • http://loaminoo.linkpc.net/1090090090097096099/Carl-Zuckmayer-Deutsche-K-nstler-Im-Salzburger-Exil-1933-1938-by-Christian-Stra-er.pdf
    • http://loaminoo.linkpc.net/4092094097096092/Reading-the-Old-Testament-with-the-Ancient-Church-Exploring-the-Formation-of-Early-Christian-Thought-by-Ronald-E-Heine.pdf
    • http://loaminoo.linkpc.net/1090092091090097092/The-Mysteries-of-Jesus-A-Muslim-Study-of-the-Origins-and-Doctrines-of-the-Christian-Church-by-Ruqaiyyah-Waris-Maqsood.pdf
    • http://loaminoo.linkpc.net/1091094099092092091/An-Abridgement-of-the-Book-of-Martyrs-To-Which-Are-Prefixed-the-Living-Testimonies-of-the-Church-of-God-an-Account-of-the-Just-Judgements-of-God-on-Persecutors-amp-C-Also-a-Christian-Plea-Against-Persecution-for-the-Cause-of-Conscience-by-John-Foxe.pdf
    • http://loaminoo.linkpc.net/1091098099094093093/Commentary-on-the-Old-Testament-The-Pentateuch-Volume-1-by-Carl-Friedrich-Keil.pdf
    • http://loaminoo.linkpc.net/3096099092090093/The-Apostolic-Fathers-by-Jack-N-Sparks.pdf