Malicious PDF — malware analysis report

Static analysis result for SHA-256 700983901806dc6d…

MALICIOUS

PDF

17.1 KB Created: 2019-04-30 04:44:20 +01:00 Authoring application: mPDF 5.7
MD5: 0b2e3c61d9ea35ae4b437d38da0a667f SHA-1: 9002ab5cce3f81ae3485b92627b769aa52495f59 SHA-256: 700983901806dc6d9af46c35a76e32b93044ce6993de18e153e245f6f1a0274a
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which suggests a link farm or SEO spamming attempt. While no scripts were explicitly extracted, the presence of embedded URLs within the PDF structure, as indicated by EMBEDDED_URL and the DOC BODY content, points towards a malicious intent to redirect users to potentially harmful sites. The ML_NYX_PDF_MALICIOUS classifier further supports the malicious nature of this file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090097099097092091/The-Kumbh-Mela-Greatest-Show-On-Earth-by-Tahir-Shah.pdf
    • http://loaminoo.linkpc.net/1090097099099094093/The-Maha-Kumbh-Mela-by-Stefano-Folgaria.pdf
    • http://loaminoo.linkpc.net/1090097099097091091/Kumbh-Mela-and-the-Sadhus-The-Quest-for-Immortality-by-Badri-Narain.pdf
    • http://loaminoo.linkpc.net/1090090096092098097/The-Greatest-Show-Off-Earth-by-Robert-Rankin.pdf
    • http://loaminoo.linkpc.net/3096093090094/The-Greatest-Show-on-Earth-The-Evidence-for-Evolution-by-Richard-Dawkins.pdf
    • http://loaminoo.linkpc.net/3099099097091095/The-Greatest-Show-on-Earth-The-Evidence-for-Evolution-by-Richard-Dawkins.pdf
    • http://loaminoo.linkpc.net/5090098097093090/Big-Top-Burning-The-True-Story-of-an-Arsonist-a-Missing-Girl-and-The-Greatest-Show-On-Earth-by-Laura-A-Woollett.pdf
    • http://loaminoo.linkpc.net/8090097098097/Travels-With-Myself-by-Tahir-Shah.pdf
    • http://loaminoo.linkpc.net/4095094096096/Sorcerer-s-Apprentice-by-Tahir-Shah.pdf
    • http://loaminoo.linkpc.net/6092091098098099/Casablanca-Blues-by-Tahir-Shah.pdf
    • http://loaminoo.linkpc.net/3099094096099093/The-Caliph-s-House-A-Year-in-Casablanca-by-Tahir-Shah.pdf
    • http://loaminoo.linkpc.net/9091093097098/The-Middle-East-Bedside-Book-by-Tahir-Shah.pdf
    • http://loaminoo.linkpc.net/8095096099099/Trail-of-Feathers-In-Search-of-the-Birdmen-of-Peru-by-Tahir-Shah.pdf
    • http://loaminoo.linkpc.net/4096095098094/House-of-the-Tiger-King-The-Quest-for-a-Lost-City-by-Tahir-Shah.pdf
    • http://loaminoo.linkpc.net/5098094099091091/Scorpion-Soup-A-story-in-a-story-by-Tahir-Shah.pdf
    • http://loaminoo.linkpc.net/4095096090091090/Wickedest-Show-on-Earth-by-Marcia-Muller.pdf
    • http://loaminoo.linkpc.net/4090098090092093/Carnival-Of-Fear-Creepiest-Show-On-Earth-Book-1-by-A-J-Norris.pdf
    • http://loaminoo.linkpc.net/6099092099091093/Jeopardy-What-Is-Quiz-Book-4-Featuring-Answers-and-Questions-from-the-Greatest-Quiz-Show-in-History-by-Sony.pdf
    • http://loaminoo.linkpc.net/6099092099095097/Jeopardy-What-Is-Quiz-Book-3-Featuring-Answers-and-Questions-from-the-Greatest-Quiz-Show-in-History-by-Sony.pdf
    • http://loaminoo.linkpc.net/8094095092091090/The-Rubaiyat-of-Baba-Tahir-Oryan-of-Hamadan-by-Baba-Tahir.pdf