Malicious PDF — malware analysis report

Static analysis result for SHA-256 db005c9b2209e83f…

MALICIOUS

PDF

22.0 KB Created: 2019-04-30 05:19:30 +01:00 Authoring application: mPDF 5.7
MD5: ef6b00ec1ee3583f315ddf4eea86cdeb SHA-1: 3777a3745904e31529c3c40b25a534a38c8d6434 SHA-256: db005c9b2209e83fafa856a1531042049b5084e6dc4daa473429caf7da7026c1
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. The ML classifier strongly indicated maliciousness. The primary heuristic identified a link farm with 27 external PDF links, with the first URL being http://loaminoo.linkpc.net/2094099097090092/The-King-Jesus-Gospel-The-Original-Good-News-Revisited-by-Scot-McKnight.pdf. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2094099097090092/The-King-Jesus-Gospel-The-Original-Good-News-Revisited-by-Scot-McKnight.pdf
    • http://loaminoo.linkpc.net/1094093091096092/Embracing-Grace-A-Gospel-for-All-of-Us-by-Scot-McKnight.pdf
    • http://loaminoo.linkpc.net/2095092096091092/One-Life-Jesus-Calls-We-Follow-by-Scot-McKnight.pdf
    • http://loaminoo.linkpc.net/1094093092091095/The-Jesus-Creed-Loving-God-Loving-Others-by-Scot-McKnight.pdf
    • http://loaminoo.linkpc.net/3099097097097091/The-Lost-Gospel-Q-The-Original-Sayings-of-Jesus-by-Marcus-J-Borg.pdf
    • http://loaminoo.linkpc.net/1091096095092094098/Good-News-Preaching-Offering-the-Gospel-in-Every-Sermon-by-Gennifer-Benjamin-Brooks.pdf
    • http://loaminoo.linkpc.net/4091094091099/The-Ragamuffin-Gospel-Good-News-for-the-Bedraggled-Beat-Up-and-Burnt-Out-by-Brennan-Manning.pdf
    • http://loaminoo.linkpc.net/3096097095090099/The-Good-News-We-Almost-Forgot-Rediscovering-the-Gospel-in-a-16th-Century-Catechism-by-Kevin-DeYoung.pdf
    • http://loaminoo.linkpc.net/1091098092096090099/GOSPEL-CENTERED-MARRIAGE---Applying-the-Gospel-of-Jesus-to-the-major-areas-of-your-married-life-by-John-Stange.pdf
    • http://loaminoo.linkpc.net/3090099091093097/Good-News-Bad-News-Best-Defence-series-by-William-H-S-McIntyre.pdf
    • http://loaminoo.linkpc.net/2097090094092095/Searching-for-Jesus-New-Discoveries-in-the-Quest-for-Jesus-of-Nazareth-and-How-They-Confirm-the-Gospel-Accounts-by-Robert-J-Hutchinson.pdf
    • http://loaminoo.linkpc.net/1094090091095099/Gospel-Principles-by-The-Church-of-Jesus-Christ-of-Latter-day-Saints.pdf
    • http://loaminoo.linkpc.net/3096093099097097/The-Gospel-According-to-Moses-What-My-Jewish-Friends-Taught-Me-about-Jesus-by-Athol-Dickson.pdf
    • http://loaminoo.linkpc.net/4095090090095093/At-the-Praetorium-Good-Friday-Revisited-by-Sean--Walsh.pdf
    • http://loaminoo.linkpc.net/8092090091091098/Jesus-the-Evangelist-Learning-to-Share-the-Gospel-from-the-Book-of-John-by-Richard-D-Phillips.pdf
    • http://loaminoo.linkpc.net/1091095095093094092/Grace-the-Forbidden-Gospel-Jesus-Tore-the-Veil-Religion-Sewed-It-Back-Up-by-Andre-Van-Der-Merwe.pdf
    • http://loaminoo.linkpc.net/1090094090095099/Good-News-from-Outer-Space-by-John-Kessel.pdf
    • http://loaminoo.linkpc.net/3096099092090094/The-Jesus-Papyrus-The-Most-Sensational-Evidence-on-the-Origin-of-the-Gospel-Since-the-Discover-of-the-Dead-Sea-Scrolls-by-Carsten-Peter-Thiede.pdf
    • http://loaminoo.linkpc.net/1091093098092092094/What-Would-Pope-Francis-Do-Bringing-the-Good-News-to-People-in-Need-by-Sean-Salai.pdf
    • http://loaminoo.linkpc.net/3095095092093095/And-the-Good-News-Is-Lessons-and-Advice-from-the-Bright-Side-by-Dana-Perino.pdf
    • http://loaminoo.linkpc.net/3096097095090099/The-Good-News-We-Almost-Forgot-Rediscovering-the-Gospel-in-a-16t