Malicious PDF — malware analysis report

Static analysis result for SHA-256 3edd4eb51e5f2a22…

MALICIOUS

PDF

18.8 KB Created: 2019-04-30 04:00:33 +01:00 Authoring application: mPDF 5.7 First seen: 2021-06-20
MD5: 09ff5543121675d594befea0750f3e7f SHA-1: a7e357dc108c6d6220b7c1d1d103c5252cfa4a74 SHA-256: 3edd4eb51e5f2a22af340e707727847dc2596d1360efd8bd8fe1f24061815a42
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently flagged as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091095099095094097/Psychodynamic-Psychiatry-Theory-amp-Practice-1-by-John-Frosch.pdf In PDF document text
    • http://loaminoo.linkpc.net/8095090094098097/The-Theory-and-Practice-of-Socialism-by-John-Strachey.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1090093090098095094/SOFSEM-2004-Theory-and-Practice-of-Computer-Science-30th-Conference-on-Current-Trends-in-Theory-and-Practice-of-Computer-Science-Merin-Czech-Republic-2004-Lecture-Notes-in-Computer-Science-by-Peter-Van-Emde-Boas.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3097098097090091/The-Interpersonal-Theory-of-Psychiatry-by-Harry-Stack-Sullivan.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8090091098092090/Theory-and-Practice-of-Managed-Competition-in-Health-Care-Finance-Lectures-in-Economics-Theory-Institutions-Policy-by-Alain-C-Enthoven.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1091095096092094094/Oxford-Handbook-of-Psychiatry-With-Emergencies-in-Psychiatry-by-David-Semple.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1091095099095093097/The-Psychotic-Process-by-John-Frosch.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8093097093090092/Harmony-Its-No-and-Practice-Its-Theory-Ts-Theory-by-Ebenezer-Prout-B-Prout.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1090090096095096098/Theory-amp-Practice-in-Listening-by-Dunkel.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1090092092090090094/Patient-Management-Problems-in-Psychiatry-by-Olumuyiwa-John-Olumoroti.pdfIn PDF document text
    • http://loaminoo.linkpc.net/9094090092093/Theory-and-practice-of-hell-by-Eugen-Kogon.pdfIn PDF document text
    • http://loaminoo.linkpc.net/5096098091092093/The-Practice-and-Theory-of-Bolshevism-by-Bertrand-Russell.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3091098096091097/Magick-in-Theory-and-Practice-by-Aleister-Crowley.pdfIn PDF document text
    • http://loaminoo.linkpc.net/9098090090091094/Theory-and-Practice-of-Seamanship-XI-by-Graham-Danton.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8094096090093098/Theory-and-Practice-of-the-Philosopher-s-Stone-by-Nicholas-Flamel.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2096091092096092/Feminist-Practice-and-Poststructuralist-Theory-by-Chris-Weedon.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1090094090094095098/Random-Vibrations-Theory-and-Practice-by-Paul-H-Wirsching.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1091098097092099094/Central-Banking-in-Theory-and-Practice-by-Alan-S-Blinder.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7096096099095097/Network-Coding-From-Theory-to-Practice-by-Muriel-Medard.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2092098099093093/Dance-Analysis-Theory-and-Practice-by-Janet-Adshead-Lansdale.pdfIn PDF document text