Malicious PDF — malware analysis report

Static analysis result for SHA-256 0103239e5ac2faac…

MALICIOUS

PDF

17.8 KB Created: 2019-05-07 07:43:53 +01:00 Authoring application: mPDF 5.7
MD5: 02d17440dde797217b0221eb6ea10e6b SHA-1: 3ac02c83ea6ad7ce4a0704b3bcd0ce58bbb23d47 SHA-256: 0103239e5ac2faac3c60a42746b56eade354b181196942321f27e771554a4187
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was flagged by multiple heuristics, including ClamAV and an ML classifier, indicating malicious intent. The primary finding is a large number of embedded external links, suggesting a link farm or redirection mechanism. While many of these links resolve to benign-looking academic papers, the sheer volume and the PDF_SEO_LINK_FARM heuristic indicate a potential for malicious redirection or SEO abuse.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7175819-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7175819-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7095093092099096/Valuing-the-Environment-Six-Case-Studies-by-Jean-Philippe-Barde.pdf
    • http://loaminoo.linkpc.net/7095093092098099/Arming-the-South-by-Jean-Philippe-Barde.pdf
    • http://loaminoo.linkpc.net/1091090091098098093/Military-Intervenes-The-Case-Studies-in-Political-Development-Case-Studies-in-Political-Development-by-Henry-Bienen.pdf
    • http://loaminoo.linkpc.net/5094094095095091/Aesthetik-Des-Fragments-Fragmentarisches-Erzaehlen-Bei-Jean-Philippe-Toussaint-Und-Jean-Echenoz-by-Christine-Keidel.pdf
    • http://loaminoo.linkpc.net/1091092090099092092/On-Liberty-A-Translation-into-Modern-English-ISR-Business-amp-the-political-legal-environment-studies-Book-6-by-John-Stuart-Mill.pdf
    • http://loaminoo.linkpc.net/6095097099090095/Case-Studies-Art-in-a-Valise-by-Katonah-Museum-of-Art.pdf
    • http://loaminoo.linkpc.net/5092099096095092/Moi-Jean-Cocteau-by-Philippe-de-Miomandre.pdf
    • http://loaminoo.linkpc.net/2093097092/The-6-41-to-Paris-by-Jean-Philippe-Blondel.pdf
    • http://loaminoo.linkpc.net/7096094099099/Camera-by-Jean-Philippe-Toussaint.pdf
    • http://loaminoo.linkpc.net/1091095096091093097/The-Biology-of-Consciousness-Case-Studies-in-Kundalini-by-J-J-Semple.pdf
    • http://loaminoo.linkpc.net/8092094094096090/Case-Studies-in-Ethics-and-HIV-Research-by-Sana-Loue.pdf
    • http://loaminoo.linkpc.net/8097094091098094/Case-Studies-In-Environmental-Science-by-Robert-M-Schoch.pdf
    • http://loaminoo.linkpc.net/6090091096098098/Making-Love-by-Jean-Philippe-Toussaint.pdf
    • http://loaminoo.linkpc.net/1090094093091093098/Case-Studies-in-Immunology-Fifth-Edition-Factor-I-Deficiency-by-Raif-Geha.pdf
    • http://loaminoo.linkpc.net/1090094093091094096/Case-Studies-in-Immunology-Fifth-Edition-Congenital-Asplenia-by-Raif-Geha.pdf
    • http://loaminoo.linkpc.net/1090094093092090097/Case-Studies-in-Immunology-Fifth-Edition-Multiple-Myeloma-by-Raif-Geha.pdf
    • http://loaminoo.linkpc.net/1090094093090093095/Case-Studies-in-Immunology-Fifth-Edition-Mhc-Class-II-Deficiency-by-Raif-Geha.pdf
    • http://loaminoo.linkpc.net/1090094093092090093/Case-Studies-in-Immunology-Fifth-Edition-Myasthenia-Gravis-by-Raif-Geha.pdf
    • http://loaminoo.linkpc.net/6094093096095/Journey-of-Souls-Case-Studies-of-Life-Between-Lives-by-Michael-Newton.pdf
    • http://loaminoo.linkpc.net/6097097098092097/R-veil-ultra-matinal-by-Jean-Philippe-Touzeau.pdf