Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5144747ab0a20be…

MALICIOUS

PDF

23.7 KB Created: 2019-05-01 18:23:44 +01:00 Authoring application: mPDF 5.7
MD5: d341f0038d5b5d816d5d444de9568ba7 SHA-1: 7dd24240324f17729e5caf9fbedf187b986c54ff SHA-256: e5144747ab0a20be8e3735cac5715ad89586f458f156667d869ecd10eb9dff4d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a PDF_SEO_LINK_FARM heuristic. While most of these URLs point to benign-looking book titles, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO manipulation or to distribute further malicious content. The embedded URLs themselves are the primary IOCs in this case.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4090097098094091/The-Snapping-of-the-American-Mind-Healing-a-Nation-Broken-by-a-Lawless-Government-and-Godless-Culture-by-David-Kupelian.pdf
    • http://loaminoo.linkpc.net/2093098098093092/One-Nation-Under-A-Groove-Motown-amp-American-Culture-by-Gerald-Early.pdf
    • http://loaminoo.linkpc.net/1090098099095099099/Tarmac-s-Broken-Dreams-The-Story-of-Svarog-by-Rod-Lawless.pdf
    • http://loaminoo.linkpc.net/1090098099095097091/Tarmac-s-Broken-Dreams-The-Story-of-Svarog-by-MR-Rod-Lawless.pdf
    • http://loaminoo.linkpc.net/1090090090096098091/The-Godfather-and-American-Culture-How-the-Corleones-Became-quot-Our-Gang-quot-SUNY-series-in-Italian-American-Culture-by-Chris-Messenger.pdf
    • http://loaminoo.linkpc.net/2096097091090094/The-Marketing-of-Evil-How-Radicals-Elitists-and-Pseudo-Experts-Sell-Us-Corruption-Disguised-as-Freedom-by-David-Kupelian.pdf
    • http://loaminoo.linkpc.net/7099098096099096/History-of-Mozambique-Culture-of-Mozambique-Religion-in-Mozambique-Republic-of-Mozambique-Mozambique-The-origin-of-Mozambique-her-Culture-and-her-Ethnic-differences-Mozambique-government-by-Sampson-Jerry.pdf
    • http://loaminoo.linkpc.net/9098097090096096/The-Next-American-Nation-The-New-Nationalism-and-the-Fourth-American-Revolution-by-Michael-Lind.pdf
    • http://loaminoo.linkpc.net/9099092098094098/Trumped-and-Divided-Healing-an-Angry-Nation-by-D-Farang.pdf
    • http://loaminoo.linkpc.net/4093096096094099/So-Beautifully-Broken-by-Lacie-Nation.pdf
    • http://loaminoo.linkpc.net/1090097096090093/Broken-Nation-Australians-in-the-Great-War-by-Joan-Beaumont.pdf
    • http://loaminoo.linkpc.net/2095091099095092/The-American-Mind-An-Interpretation-of-American-Thought-amp-Character-Since-the-1880-s-by-Henry-Steele-Commager.pdf
    • http://loaminoo.linkpc.net/1090091091099094/Qi-Healing-The-Way-to-a-New-Mind-and-Body-by-Toshihiko-Yayama.pdf
    • http://loaminoo.linkpc.net/1091096093095094093/Pni-The-Mind-Body-Healing-Program-by-Elliott-S-Dacher.pdf
    • http://loaminoo.linkpc.net/7094094099093090/Haiti-The-Tumultuous-History---From-Pearl-of-the-Caribbean-to-Broken-Nation-by-Philippe-Girard.pdf
    • http://loaminoo.linkpc.net/1091092092098099097/The-Federalist-The-Constitution-and-American-Government-by-Alex-Aichinger.pdf
    • http://loaminoo.linkpc.net/1090096092098094095/Comic-Book-Nation-The-Transformation-of-Youth-Culture-in-America-by-Bradford-W-Wright.pdf
    • http://loaminoo.linkpc.net/4091092095097091/Bioplasticity-Hypnosis-Mind-Body-Healing-by-Joseph-Sansone.pdf
    • http://loaminoo.linkpc.net/7098095095098096/A-Necessary-Evil-A-History-of-American-Distrust-of-Government-by-Garry-Wills.pdf
    • http://loaminoo.linkpc.net/4099092095099095/Healing-Back-Pain-The-Mind-Body-Connection-by-John-E-Sarno.pdf