Malicious PDF — malware analysis report

Static analysis result for SHA-256 097e64521558eed2…

MALICIOUS

PDF

18.2 KB Created: 2019-04-30 18:47:04 +01:00 Authoring application: mPDF 5.7
MD5: c13b3fc6642cf440b355fc8c72d152ed SHA-1: 884265c5580a4ad0c6776753a57402d01591c6a6 SHA-256: 097e64521558eed2bf389d9b07b9b094e6ffc1619277b52665ed3abfbc4f40bf
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, many of which are numeric slugs pointing to what appear to be academic documents. This behavior is indicative of a link farm or SEO spam technique, likely intended to drive traffic or potentially host malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090094096097090099/Aldous-Huxley-Brave-New-World-Inhaltsangaben-und-Interpretationen-Themen-und-Wortschatz-Musterklausur-by-J-Bernhard-M-ller.pdf
    • http://loaminoo.linkpc.net/7096090098094094/The-Doors-of-Perception-by-Aldous-Huxley.pdf
    • http://loaminoo.linkpc.net/2095096099096096/Collected-Essays-by-Aldous-Huxley.pdf
    • http://loaminoo.linkpc.net/1093098094091095/Time-Must-Have-a-Stop-by-Aldous-Huxley.pdf
    • http://loaminoo.linkpc.net/4090099090096/The-Devils-of-Loudun-by-Aldous-Huxley.pdf
    • http://loaminoo.linkpc.net/7091092099095/Ends-and-Means-by-Aldous-Huxley.pdf
    • http://loaminoo.linkpc.net/4090099099099096/Those-Barren-Leaves-by-Aldous-Huxley.pdf
    • http://loaminoo.linkpc.net/1093098095099090/Collected-Short-Stories-by-Aldous-Huxley.pdf
    • http://loaminoo.linkpc.net/7093099097094090/Vrata-zaznavanja-Nebesa-in-pekel-by-Aldous-Huxley.pdf
    • http://loaminoo.linkpc.net/9094093092099098/Aldous-Huxley-An-English-Intellectual-by-Nicholas-Murray.pdf
    • http://loaminoo.linkpc.net/9094093092099099/Moksha-Writings-on-Psychedelics-amp-the-Visionary-Experience-by-Aldous-Huxley.pdf
    • http://loaminoo.linkpc.net/8090099094090091/The-Human-Situation-Lectures-at-Santa-Barbara-1959-by-Aldous-Huxley.pdf
    • http://loaminoo.linkpc.net/1091096099099096092/The-Review-of-Contemporary-Fiction-Flann-O-Brien-Guy-Davenport-Aldous-Huxley-Fall-2005-by-John-O-39-Brien.pdf
    • http://loaminoo.linkpc.net/1098095090098093/Brave-New-World-Monster-Kids-Academy-1-by-Robert-Mynor.pdf
    • http://loaminoo.linkpc.net/9098093094094090/This-Brave-New-World-India-China-and-the-United-States-by-Anja-Manuel.pdf
    • http://loaminoo.linkpc.net/3095090098093092/Brave-Land-Brave-Love-Australian-Trilogy-3-by-Connie-Mason.pdf
    • http://loaminoo.linkpc.net/1098094093097092/Junior-Braves-of-the-Apocalypse-Volume-1-A-Brave-is-Brave-1-by-Greg-Smith.pdf
    • http://loaminoo.linkpc.net/8093098094096092/Brave-New-World-1984-and-We-An-Essay-on-Anti-Utopia-by-Edward-James-Brown.pdf
    • http://loaminoo.linkpc.net/8095096095093094/Malala-a-Brave-Girl-from-Pakistan-Iqbal-a-Brave-Boy-from-Pakistan-Two-Stories-of-Bravery-by-Jeanette-Winter.pdf
    • http://loaminoo.linkpc.net/1090095093098091092/Batman-in-The-Brave-amp-the-Bold-The-Bronze-Age-Vol-1-The-Brave-and-the-Bold-1955-1983-by-Bob-Haney.pdf