Malicious PDF — malware analysis report

Static analysis result for SHA-256 72c49c0724fc729c…

MALICIOUS

PDF

21.0 KB Created: 2019-04-30 05:26:52 +01:00 Authoring application: mPDF 5.7
MD5: 04be9a11ae6c723aa063e6c4ac51eb03 SHA-1: 54447a98c74328fc634198d26a1b8e7e59e0c503 SHA-256: 72c49c0724fc729c961b5d83b0da4a78aacd73309ba425768fa7817a2b1cfe4e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm. While many of these links point to seemingly benign academic papers, the sheer volume and the heuristic firing 'PDF_SEO_LINK_FARM' suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9097092096093099/Quine-s-Views-on-Meaning-and-Translation-as-Presented-in-His-Articles-Two-Dogmas-of-Empiricism-and-Translation-and-Meaning-by-Svenja-Christen.pdf
    • http://loaminoo.linkpc.net/9097092096093095/Contrastive-Pragmatics-and-Translation-Evaluation-Epistemic-Modality-and-Communicative-Styles-in-English-and-German-by-Svenja-Kranich.pdf
    • http://loaminoo.linkpc.net/1090099093097095/The-Path-to-Meaning-How-to-Align-Yourself-with-the-Universe-Make-Use-of-its-Hidden-Laws-and-Fill-Your-Life-with-Meaning-by-Agnes-Bodi.pdf
    • http://loaminoo.linkpc.net/8094091092092098/Decolonizing-Translation-Francophone-African-Novels-in-English-Translation-by-Kathryn-Batchelor.pdf
    • http://loaminoo.linkpc.net/4090093094092097/A-Plainer-Translation-Joseph-Smith-s-Translation-Of-The-Bible-A-History-and-Commentary-by-Robert-J-Matthews.pdf
    • http://loaminoo.linkpc.net/5093093097097097/Text-Analysis-in-Translation-Theory-Methodology-and-Didactic-Application-of-a-Model-for-Translation-Oriented-Text-Analysis-Amsterdamer-Publikationen-Zur-Sprache-Und-Literatur-94-by-Christiane-Nord.pdf
    • http://loaminoo.linkpc.net/4092099099090099/The-Meaning-of-Liff-Meaning-of-Liff-1-by-Douglas-Adams.pdf
    • http://loaminoo.linkpc.net/9095091096093/Your-Meaning-by-Marius-Croeser.pdf
    • http://loaminoo.linkpc.net/9091091093094091/The-Meaning-of-Hitler-by-Sebastian-Haffner.pdf
    • http://loaminoo.linkpc.net/5090094098098097/Man-s-Search-for-Meaning-by-Viktor-E-Frankl.pdf
    • http://loaminoo.linkpc.net/4093093091099098/The-Meaning-of-History-by-Nikolai-A-Berdyaev.pdf
    • http://loaminoo.linkpc.net/3098095096092090/The-Meaning-of-Madness-by-Neel-Burton.pdf
    • http://loaminoo.linkpc.net/3092099092091093/Man-s-Search-for-Meaning-by-Viktor-E-Frankl.pdf
    • http://loaminoo.linkpc.net/6092090094094096/The-Meaning-of-Aphrodite-by-Paul-Friedrich.pdf
    • http://loaminoo.linkpc.net/2091096095098/War-Is-a-Force-That-Gives-Us-Meaning-by-Chris-Hedges.pdf
    • http://loaminoo.linkpc.net/1093093096090/The-True-Meaning-of-Smekday-by-Adam-Rex.pdf
    • http://loaminoo.linkpc.net/4093095091096094/The-Meaning-of-Liff-by-Douglas-Adams.pdf
    • http://loaminoo.linkpc.net/6097091097097/The-Translation-of-the-Bones-by-Francesca-Kay.pdf
    • http://loaminoo.linkpc.net/7092097094091090/The-Tao-Te-Ching-A-New-Translation-with-Commentary-by-Lao-Tzu.pdf
    • http://loaminoo.linkpc.net/5091096097095092/Translation-by-Matthew-Minicucci.pdf