Malicious PDF — malware analysis report

Static analysis result for SHA-256 00b29778856af170…

MALICIOUS

PDF

26.3 KB Created: 2019-05-03 12:43:53 +01:00 Authoring application: mPDF 5.7
MD5: 87aadd71b825352ad446948fd1528434 SHA-1: 6de21fd831beb5a4a724de81949fc5e9e4f2d97f SHA-256: 00b29778856af170fe142a2b99ef158f7feb7ff5e5c57d448fc3b460ebcd205f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various documents. While the specific URLs extracted are currently flagged as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to host malicious content under a guise of legitimate documents. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1098094090090093/The-Qur-an-Text-Translation-and-Commentary-by-Anonymous.pdf
    • http://loaminoo.linkpc.net/2098090093099097/The-Didache-Text-Translation-Analysis-and-Commentary-by-Anonymous.pdf
    • http://loaminoo.linkpc.net/5095099098098092/The-Noble-Qur-an-English-Translation-of-the-Meanings-and-Commentary-by-Anonymous.pdf
    • http://loaminoo.linkpc.net/6099099094094094/Kavyadarsah-of-Dandin-Text-with-english-translation-amp-commentary-of-Jibanand-Vidyasagar-by-R-K-Panda.pdf
    • http://loaminoo.linkpc.net/3099097090096091/Imperial-Plato-Albinus-Maximus-Apuleius-Text-and-Translation-with-an-Introduction-and-Commentary-by-Ryan-C-Fowler.pdf
    • http://loaminoo.linkpc.net/3099097090094095/The-Fragments-of-Parmenides-A-Critical-Text-With-Introduction-and-Translation-the-Ancient-Testimonia-and-a-Commentary-by-Allan-H-Coxon.pdf
    • http://loaminoo.linkpc.net/6093092097090097/Jackal-At-The-Shaman-s-Gate-A-Study-Of-Anubis-Lord-Of-Ro-Setawe-With-The-Conjuration-To-Chthonic-Deities-Pgm-Xxiii-Text-Translation-And-Commentary-by-Terence-Duquesne.pdf
    • http://loaminoo.linkpc.net/5097092091094096/The-Lysistrata-of-Aristophanes-Acted-at-Athens-in-the-Year-B-C-411-The-Greek-Text-Revised-with-a-Translation-Into-Corresponding-Metres-Introduction-and-Commentary-by-Aristophanes.pdf
    • http://loaminoo.linkpc.net/5093093097097097/Text-Analysis-in-Translation-Theory-Methodology-and-Didactic-Application-of-a-Model-for-Translation-Oriented-Text-Analysis-Amsterdamer-Publikationen-Zur-Sprache-Und-Literatur-94-by-Christiane-Nord.pdf
    • http://loaminoo.linkpc.net/4090093094092097/A-Plainer-Translation-Joseph-Smith-s-Translation-Of-The-Bible-A-History-and-Commentary-by-Robert-J-Matthews.pdf
    • http://loaminoo.linkpc.net/7092097094091090/The-Tao-Te-Ching-A-New-Translation-with-Commentary-by-Lao-Tzu.pdf
    • http://loaminoo.linkpc.net/1091092096093091093/Tao-Te-Ching-Crowley-A-New-Translation-and-Commentary-by-Lao-Tzu.pdf
    • http://loaminoo.linkpc.net/9096097098099097/Tao-Te-Ching-A-New-Translation-with-Commentary-from-Ko-Hs-an-by-Lao-Tzu.pdf
    • http://loaminoo.linkpc.net/7091092090098091/Code-of-Canon-Law-A-Text-and-Commentary-by-The-Catholic-Church.pdf
    • http://loaminoo.linkpc.net/3099097090090092/PLOTINUS-Ennead-IVI-3-4-29-Problems-Concerning-the-Soul-Translation-with-an-Introduction-and-Commentary-by-John-M-Dillon.pdf
    • http://loaminoo.linkpc.net/1091098093099094096/Yajurveda-Sanskrit-Text-with-English-Translation-by-Devi-Chand.pdf
    • http://loaminoo.linkpc.net/9095094090093099/Early-Notebooks-The-Physical-Questions-A-Translation-from-the-Latin-with-Historical-and-Paleographical-Commentary-by-Galileo-Galilei.pdf
    • http://loaminoo.linkpc.net/4091093096091092/Koheles-Ecclesiastes-A-New-Translation-with-a-Commentary-Anthologized-from-Talmudic-Midrashic-and-Rabbinic-Sources-by-Meir-Zlotowitz.pdf
    • http://loaminoo.linkpc.net/2092092091096097/New-World-Translation-of-the-Holy-Scriptures-by-Anonymous.pdf
    • http://loaminoo.linkpc.net/4097094096093095/Domesday-Book-A-Complete-Translation-by-Anonymous.pdf