Malicious PDF — malware analysis report

Static analysis result for SHA-256 29c03c03023a4339…

MALICIOUS

PDF

18.4 KB Created: 2020-03-20 02:21:17 +00:00 Authoring application: mPDF 5.7 First seen: 2021-10-04
MD5: b487a972c3b4fc0fa056bbe4ec8c51bb SHA-1: b36b686aca19acb342af0eb1d826b0314c6a6803 SHA-256: 29c03c03023a4339f651c91824f6ef25241d9e8760ad8a08e973464a4e6c283f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, indicative of a link farm. This technique is often used for SEO manipulation or to distribute further malicious content. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://laoieoa.myhome.cx/8c01c05c09c00c02/Walden-Ou-la-vie-dans-les-bois-by-Henry-David-Thoreau.pdf In PDF document text
    • http://laoieoa.myhome.cx/5c09c00c03c06c08/Walden-ou-La-Vie-dans-les-Bois-Annot--Version-Francaise-Version-Originale-en-Anglais-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/2c06c07c08c00c03/Thoreau-Walden-and-Other-Writings-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/7c05c00c05c09c01/Walden-By-Henry-David-Thoreau---Illustrated-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/3c02c03c06c01/Walden-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/7c03c06c05c07c00/Walden-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/2c08c07c09c04c08/Walden-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/5c07c00c04c03c02/Walden-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/8c08c09c02c08c05/Walden-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/1c00c02c01c08c00/Walden-and-Other-Writings-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/1c01c07c07c09c02c08/Walden-and-Civil-Disobedience-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/5c09c09c06c06c09/Walden-and-Civil-Disobedience-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/5c06c00c00c03c06/Walden-Or-Life-in-the-Woods-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/6c00c01c06c02c05/Walden---Essay-on-Civil-Disobedience-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/8c00c03c00c01c03/Walden-Color-Illustrated-Formatted-for-E-Readers-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/5c07c09c08c06c04/Walden-Black-Illustrated-Classics-Bonus-Free-Audiobook-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/4c03c06c05c05c00/A-Week-on-the-Concord-and-Merrimack-Rivers-Walden-The-Maine-Woods-Cape-Cod-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/8c09c05c05c04c02/Walden-oder-Leben-in-den-W-ldern-Vollst-ndig-berarbeitete-deutsche-Ausgabe-mit-neuer-Rechtschreibung-by-Henry-David-Thoreau.pdfIn PDF document text
    • http://laoieoa.myhome.cx/8c05c01c08c07c00/Thumbing-Through-Thoreau-A-Book-of-Quotations-by-Henry-David-Thoreau-by-Kenny-Luck.pdfIn PDF document text
    • http://laoieoa.myhome.cx/2c05c02c03c01c08/The-Price-of-Freedom-Political-Philosophy-from-Thoreau-s-Journals-by-Henry-David-Thoreau.pdfIn PDF document text