Malicious PDF — malware analysis report

Static analysis result for SHA-256 4e6b2bed36f623f5…

MALICIOUS

PDF

20.1 KB Created: 2019-04-29 23:44:45 +01:00 Authoring application: mPDF 5.7
MD5: 0cdbd2106a8b7070ea36b055545e7001 SHA-1: e1e71843171b9e73f4f17aceb4ac9ee53a317b0e SHA-256: 4e6b2bed36f623f5d8faca1ee7cbb2e8935c5dcd946740fdab428c95e8a6556f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, likely to manipulate search engine results or to serve as a lure for users to click on potentially harmful content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5092096093098093/The-Philosophy-of-Jean-Paul-Sartre-by-Jean-Paul-Sartre.pdf
    • http://loaminoo.linkpc.net/8090099092094099/Situations-by-Jean-Paul-Sartre.pdf
    • http://loaminoo.linkpc.net/3099096099090092/Nausea-by-Jean-Paul-Sartre.pdf
    • http://loaminoo.linkpc.net/5092096094093094/Baudelaire-by-Jean-Paul-Sartre.pdf
    • http://loaminoo.linkpc.net/3094096098097/No-Exit-by-Jean-Paul-Sartre.pdf
    • http://loaminoo.linkpc.net/1092097095090090/What-Is-Subjectivity-by-Jean-Paul-Sartre.pdf
    • http://loaminoo.linkpc.net/3093094092097/No-Exit-and-Three-Other-Plays-by-Jean-Paul-Sartre.pdf
    • http://loaminoo.linkpc.net/3097096090096094/The-Flies-Les-Mouches-by-Jean-Paul-Sartre.pdf
    • http://loaminoo.linkpc.net/8090099094094092/Critical-essays-Situations-1-by-Jean-Paul-Sartre.pdf
    • http://loaminoo.linkpc.net/4091091098093097/Critique-of-Dialectical-Reason-Vols-1-and-2-by-Jean-Paul-Sartre.pdf
    • http://loaminoo.linkpc.net/2098099091091091/The-Transcendence-of-the-Ego-An-Existentialist-Theory-of-Consciousness-by-Jean-Paul-Sartre.pdf
    • http://loaminoo.linkpc.net/5098090093098096/The-Family-Idiot-4-Gustave-Flaubert-1821-57-by-Jean-Paul-Sartre.pdf
    • http://loaminoo.linkpc.net/6099090098091094/Condamn-s-tre-libres-l-anthropologie-existentielle-de-Jean-Paul-Sartre-by-Teoli-Antonia.pdf
    • http://loaminoo.linkpc.net/6098091090090098/La-Naus-e-de-Jean-Paul-Sartre-Fiche-de-lecture-R-sum-complet-et-analyse-d-taill-e-de-l-oeuvre-by-Catherine-Nelissen.pdf
    • http://loaminoo.linkpc.net/6098091090090092/La-Naus-e-de-Jean-Paul-Sartre-Fiche-de-lecture-Universalis-by-Encyclop-dia-Universalis.pdf
    • http://loaminoo.linkpc.net/5092096094099096/At-the-Existentialist-Caf-Freedom-Being-and-Apricot-Cocktails-with-Jean-Paul-Sartre-Simone-de-Beauvoir-Albert-Camus-Martin-Heidegger-Maurice-Merleau-Ponty-and-Others-by-Sarah-Bakewell.pdf
    • http://loaminoo.linkpc.net/1091090090093098097/Jean-Paul-S-mtliche-Romane-in-einem-Band-Die-unsichtbare-Loge-Flegeljahre-Hesperus-oder-45-Hundposttage-Siebenk-s-Titan-Leben-Fibels-Der-Komet-Leben-des-Quintus-Fixlein-by-Jean-Paul.pdf
    • http://loaminoo.linkpc.net/8096099098093/Intellectuals-From-Marx-and-Tolstoy-to-Sartre-and-Chomsky-by-Paul-Johnson.pdf
    • http://loaminoo.linkpc.net/8095090097092096/Jean-Paul-Riopelle-Peinture-1946-1977-Musee-national-d-art-moderne-Centre-Georges-Pompidou-Paris-30-septembre-16-novembre-1981-Musee-du-juillet-1982-22-aout-1982-by-Jean-Paul-Riopelle.pdf
    • http://loaminoo.linkpc.net/5092094097090098/Jean-Luc-Godard-An-Investigation-Into-His-Films-and-Philosophy-by-Jean-Collet.pdf
    • http://loaminoo.linkpc.net/6099090098091094/Condamn-s-tre-