Malicious PDF — malware analysis report

Static analysis result for SHA-256 e0d25abffd865f51…

MALICIOUS

PDF

20.4 KB Created: 2019-05-02 05:05:50 +01:00 Authoring application: mPDF 5.7
MD5: 994dd2a92a001d83a8594db572985d3d SHA-1: 41cf7caa0dd5e7c4ba8b8e4ce899a9611d28266e SHA-256: e0d25abffd865f51807a190942936da4b9d35597f07e2dd18a2c70b2d53f7988
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded links to external PDF documents. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. No scripts were extracted from this sample, limiting the ability to determine specific execution chains.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3096092096097098/Light-of-the-World-The-Pope-the-Church-and-the-Signs-of-the-Times---A-Conversation-with-Peter-Seewald-by-Pope-Benedict-XVI.pdf
    • http://loaminoo.linkpc.net/7095092097092091/Church-Fathers-From-Clement-of-Rome-to-Augustine-by-Pope-Benedict-XVI.pdf
    • http://loaminoo.linkpc.net/9094099094094092/The-Pope-Francis-Benedict-and-the-Decision-That-Shook-the-World-by-Anthony-McCarten.pdf
    • http://loaminoo.linkpc.net/1090092095099091090/Benedict-XVI-An-Intimate-Portrait-by-Peter-Seewald.pdf
    • http://loaminoo.linkpc.net/1090092096093095099/Luz-del-mundo-by-Pope-Benedict-XVI.pdf
    • http://loaminoo.linkpc.net/7093096092091091/On-Conscience-Two-Essays-by-Pope-Benedict-XVI.pdf
    • http://loaminoo.linkpc.net/1091096098095098091/Einf-hrung-in-das-Christentum-by-Pope-Benedict-XVI.pdf
    • http://loaminoo.linkpc.net/7096092098095/God-Is-Love-Deus-Caritas-Est-by-Pope-Benedict-XVI.pdf
    • http://loaminoo.linkpc.net/7096097092092094/Sept-psaumes-pour-la-vie-BENOIT-XVI-by-Pope-Benedict-XVI.pdf
    • http://loaminoo.linkpc.net/1091093098092092091/All-the-Pope-s-Saints-The-Jesuits-Who-Shaped-Pope-Francis-by-Sean-Salai.pdf
    • http://loaminoo.linkpc.net/3096094090099095/Finding-Life-s-Purpose-Inspiration-for-Young-People-by-Pope-Benedict-XVI.pdf
    • http://loaminoo.linkpc.net/1090099091098098092/Einf-hrung-in-das-Christentum-Vorlesungen-ber-das-apostolische-Glaubensbekenntnis-by-Pope-Benedict-XVI.pdf
    • http://loaminoo.linkpc.net/7093099094092099/A-Present-for-a-Papist-Or-the-History-of-the-Life-of-Pope-Joan-taken-Mainly-from-A-Cooke-s-Pope-Joane-by-Alexander-Cooke.pdf
    • http://loaminoo.linkpc.net/7093099094092096/A-Present-for-a-Papist-Or-the-History-of-the-Life-of-Pope-Joan-Taken-Mainly-from-A-Cooke-s-Pope-Joane-by-Alexander-Cooke.pdf
    • http://loaminoo.linkpc.net/1090099090091094098/The-Life-and-Times-of-Rodrigo-Borgia-Pope-Alexander-VI-by-Arnold-Harris-Mathew.pdf
    • http://loaminoo.linkpc.net/1090090090095094/Fish-Into-Wine-The-Newfoundland-Plantation-in-the-Seventeenth-Century-by-Peter-E-Pope.pdf
    • http://loaminoo.linkpc.net/2094096095098090/The-Abacus-and-the-Cross-The-Story-of-the-Pope-Who-Brought-the-Light-of-Science-to-the-Dark-Ages-by-Nancy-Marie-Brown.pdf
    • http://loaminoo.linkpc.net/7091093094096099/Signs-of-the-Times-Unlocking-the-Symbolic-Language-of-World-Events-by-Ray-Grasse.pdf
    • http://loaminoo.linkpc.net/6097095096097096/Signs-and-Symptoms-Thomas-Pynchon-and-the-Contemporary-World-by-Peter-L-Cooper.pdf
    • http://loaminoo.linkpc.net/4092096096097099/The-Dunciad-by-Alexander-Pope.pdf
    • http://loaminoo.linkpc.net/1091093098092092091/All-the-Pope-s-Saints-The-Jesuits-Who-Shap