Malicious PDF — malware analysis report

Static analysis result for SHA-256 1d0819f9fa3c2e29…

MALICIOUS

PDF

22.6 KB Created: 2019-04-30 08:12:18 +01:00 Authoring application: mPDF 5.7
MD5: b6e0c417454c8b2e8b538d1433b62282 SHA-1: ad2ce988f11a115a7df54e4dd738c97a08b4bfd6 SHA-256: 1d0819f9fa3c2e29abe6e2c1abe29d789f5bda939313ac8b6fb53813c7bde46a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier strongly indicated maliciousness. While the document body is unreadable, the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm, suggesting a deceptive or malicious intent behind the document's creation. The primary IOCs are the numerous URLs embedded within the PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091092093093099098/Quantum-Theory-of-Resonant-Scattering-Spectroscopy-and-Signal-Processing-by-Dzevad-Belkic.pdf
    • http://loaminoo.linkpc.net/1091092093093093098/Principles-of-Quantum-Scattering-Theory-by-Dzevad-Belkic.pdf
    • http://loaminoo.linkpc.net/1091092093093099091/Theory-of-Heavy-Ion-Collision-Physics-in-Hadron-Therapy-by-Dzevad-Belkic.pdf
    • http://loaminoo.linkpc.net/6091090098097091/Biomedical-Signal-Processing-by-Metin-Akay.pdf
    • http://loaminoo.linkpc.net/1091098096092092098/Discrete-Time-Signal-Processing-An-Introduction-by-A-W-M-van-den-Enden.pdf
    • http://loaminoo.linkpc.net/6098091097090094/Digital-Signal-and-Image-Processing-Using-MATLAB-by-G-Blanchet.pdf
    • http://loaminoo.linkpc.net/5098093094099090/Higher-Order-Statistical-Signal-Processing-by-Boualem-Boashash.pdf
    • http://loaminoo.linkpc.net/1091091094097096093/Digital-Signal-Processing-in-Communications-Systems-by-Marvin-Frerking.pdf
    • http://loaminoo.linkpc.net/6098091096091093/Digital-Signal-and-Image-Processing-Using-Matlab-Volume-1-Fundamentals-by-G-rard-Blanchet.pdf
    • http://loaminoo.linkpc.net/1091092096098091090/Icsp-06-2006-8th-International-Conference-on-Signal-Processing-Proceedings-November-16-20-2006-Guilin-China-by-Beijing-Jiao-Tong-Da-Xue.pdf
    • http://loaminoo.linkpc.net/9098095094094090/Quantum-Theory-and-the-Schism-in-Physics-by-Karl-Popper.pdf
    • http://loaminoo.linkpc.net/5096090097098096/The-Bit-and-the-Pendulum-From-Quantum-Computing-to-M-Theory--The-New-Physics-of-Information-by-Tom-Siegfried.pdf
    • http://loaminoo.linkpc.net/8093097092092093/Adiabatic-Perturbation-Theory-In-Quantum-Dynamics-by-Stefan-Teufel.pdf
    • http://loaminoo.linkpc.net/9092098090097094/Quantum-Field-Theory-and-Beyond-Essays-in-Honor-of-Wolfhart-Zimmermann-by-Erhard-Seiler.pdf
    • http://loaminoo.linkpc.net/1091094098096094094/The-Semantics-of-Prepositions-From-Mental-Processing-to-Natural-Language-Processing-by-Cornelia-Zelinsky-Wibbelt.pdf
    • http://loaminoo.linkpc.net/4094097091090093/Quantum-Evolution-How-Physics-Weirdest-Theory-Explains-Life-s-Biggest-Mystery-by-Johnjoe-McFadden.pdf
    • http://loaminoo.linkpc.net/4094098095093095/Quantum-Theory-Cannot-Hurt-You-Understanding-the-Mind-Blowing-Building-Blocks-of-the-Universe-by-Marcus-Chown.pdf
    • http://loaminoo.linkpc.net/7099091090095090/Alice-and-Bob-Meet-Banach-The-Interface-of-Asymptotic-Geometric-Analysis-and-Quantum-Information-Theory-by-Guillaume-Aubrun.pdf
    • http://loaminoo.linkpc.net/8095097090099093/Sensory-Processing-Techniques-Tactics-amp-SPD-Games-To-Help-Your-Child-With-Sensory-Processing-Disorder-by-Martin-Lamonde.pdf
    • http://loaminoo.linkpc.net/2092096095098094/Quantum-Anthropology-Man-Cultures-and-Groups-in-a-Quantum-Perspective-by-Radek-Trnka.pdf