Malicious PDF — malware analysis report

Static analysis result for SHA-256 33e9eb3a1f87bd9c…

MALICIOUS

PDF

22.6 KB Created: 2019-05-01 08:07:10 +01:00 Authoring application: mPDF 5.7
MD5: 9bda3725aa33f37af1b46936e4563d5c SHA-1: d96e10f97bb4205838c6f17b9bb4e391097ee638 SHA-256: 33e9eb3a1f87bd9c8bded0cddc3084fb5dccc9855d0752b3cbd65cb808224783
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a PDF SEO link farm. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing suggest a malicious intent to redirect users to potentially harmful content. The ML classifier also flagged this PDF with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4099090098096094/Medieval-Indian-Society-And-Culture-Advanced-Study-In-The-History-Of-Medieval-India-Vol-Iii-by-J-L-Mehta.pdf
    • http://loaminoo.linkpc.net/3099095095098097/The-Medieval-Theologians-An-Introduction-to-Theology-in-the-Medieval-Period-by-G-R-Evans.pdf
    • http://loaminoo.linkpc.net/6090092097091095/Medieval-Popular-Culture-by-Aaron-Gurevich.pdf
    • http://loaminoo.linkpc.net/8094098093091096/The-Household-in-Late-Medieval-Cities-Italy-amp-Northwestern-Europe-Compared-Proceedings-of-the-International-Conference-at-Ghent-21-22-January-2000-Studies-the-Medieval-and-Modern-Low-Countries-12-by-Myriam-Carlier.pdf
    • http://loaminoo.linkpc.net/6090097095096090/The-Allegory-of-Love-A-Study-in-Medieval-Tradition-by-C-S-Lewis.pdf
    • http://loaminoo.linkpc.net/9099095097092096/Corpus-Christi-The-Eucharist-in-Late-Medieval-Culture-by-Miri-Rubin.pdf
    • http://loaminoo.linkpc.net/1091096096098092092/Medieval-Material-Culture-Studies-in-Honour-of-Jan-Thijssen-by-Hemmy-Clevis.pdf
    • http://loaminoo.linkpc.net/5090098092092091/Nuns-as-Artists-The-Visual-Culture-of-a-Medieval-Convent-by-Jeffrey-F-Hamburger.pdf
    • http://loaminoo.linkpc.net/7095098092090095/Experiencing-the-Afterlife-Soul-and-Body-in-Dante-and-Medieval-Culture-by-Manuele-Gragnolati.pdf
    • http://loaminoo.linkpc.net/8099093091092097/Medievalia-Et-Humanistica-No-44-Studies-in-Medieval-and-Renaissance-Culture-New-Series-by-Reinhold-F-Glei.pdf
    • http://loaminoo.linkpc.net/1094094090096092/The-Tainted-Relic-An-Historical-Mystery-The-Medieval-Murderers-1-by-The-Medieval-Murderers.pdf
    • http://loaminoo.linkpc.net/2093092092097092/Music-Body-and-Desire-in-Medieval-Culture-Hildegard-of-Bingen-to-Chaucer-by-Bruce-Holsinger.pdf
    • http://loaminoo.linkpc.net/3099096098090095/King-Arthur-s-Bones-The-Medieval-Murderers-5-by-The-Medieval-Murderers.pdf
    • http://loaminoo.linkpc.net/4090093097096094/Medieval-Europe-A-Short-History-by-Judith-M-Bennett.pdf
    • http://loaminoo.linkpc.net/3099096091097095/A-Cultural-History-of-Animals-in-the-Medieval-Age-by-Brigitte-Resl.pdf
    • http://loaminoo.linkpc.net/4099096090093092/Medieval-Europe-A-Short-History-by-C-Warren-Hollister.pdf
    • http://loaminoo.linkpc.net/1093099092091091/The-New-Penguin-Atlas-of-Medieval-History-by-Colin-McEvedy.pdf
    • http://loaminoo.linkpc.net/5098095098092092/Cambridge-Medieval-History-The-Eastern-Roman-Empire-by-E-W-Brooks.pdf
    • http://loaminoo.linkpc.net/9099098091099096/The-New-Cambridge-Medieval-History-Volume-3-c-900---c-1024-by-Timothy-Reuter.pdf
    • http://loaminoo.linkpc.net/4098097098099090/Nibelungenlied-History-and-Interpretation-Illinois-Medieval-Monographs-by-Edward-W-Haymes.pdf