Malicious PDF — malware analysis report

Static analysis result for SHA-256 05530d453148f545…

MALICIOUS

PDF

18.1 KB Created: 2019-04-30 02:43:20 +01:00 Authoring application: mPDF 5.7
MD5: 6529752451c4d4c4867161d457024f37 SHA-1: c373d0463a4a5f16d63a86eeda661e8dbe5bde05 SHA-256: 05530d453148f545813ec072dcef6efc44d64b3eec4e94a1699524df8bbd4074
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO spam or to direct users to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2095096097096099/The-Great-War-in-Africa-1914-1918-by-Byron-Farwell.pdf
    • http://loaminoo.linkpc.net/4093092096094098/African-Kaiser-General-Paul-von-Lettow-Vorbeck-and-the-Great-War-in-Africa-1914-1918-by-Robert-Gaudi.pdf
    • http://loaminoo.linkpc.net/4093092094097091/Over-There-The-United-States-in-the-Great-War-1917-18-by-Byron-Farwell.pdf
    • http://loaminoo.linkpc.net/1090092091095093096/The-Great-War-1914-1918-by-Marc-Ferro.pdf
    • http://loaminoo.linkpc.net/6091098098099/A-World-Undone-The-Story-of-the-Great-War-1914-to-1918-by-G-J-Meyer.pdf
    • http://loaminoo.linkpc.net/4093092096099099/In-Flanders-Fields-The-Great-War-Seen-from-the-Air-1914-1918-by-Birger-Stichelbaut.pdf
    • http://loaminoo.linkpc.net/2095096098099094/Mr-Kipling-s-Army-All-the-Queen-s-Men-by-Byron-Farwell.pdf
    • http://loaminoo.linkpc.net/1090092091096096091/The-First-Air-War-1914-1918-by-Lee-B-Kennett.pdf
    • http://loaminoo.linkpc.net/5098091094099097/Charles-de-Gaulle-Soldat-1914-1918-by-Somme.pdf
    • http://loaminoo.linkpc.net/4090091098092094/Journal-De-La-Guerre-1914-1918-by-Yves-Congar.pdf
    • http://loaminoo.linkpc.net/3094094093096093/Without-Warning-Ellen-s-Story-1914-1918-by-Dennis-Hamley.pdf
    • http://loaminoo.linkpc.net/5096090093096091/We-Lead-Others-Follow-First-Canadian-Division-1914---1918-by-Kenneth-Radley.pdf
    • http://loaminoo.linkpc.net/9090090092095092/Douglas-Haig-War-Diaries-and-Letters-1914-1918-by-Gary-Sheffield.pdf
    • http://loaminoo.linkpc.net/6092091097095091/1914-1918-Quatre-Annees-Sur-Le-Front-Carnets-D-Un-Combattant-by-Paul-Tuffrau.pdf
    • http://loaminoo.linkpc.net/4090090099099093/Tommy-The-British-Soldier-on-the-Western-Front-1914-1918-by-Richard-Holmes.pdf
    • http://loaminoo.linkpc.net/1091097092099093097/Tijdelijk-thuisland-Belgische-kunstenaars-in-Domburg-1914-1918-by-Francisca-van-Vloten.pdf
    • http://loaminoo.linkpc.net/1090091099097095094/Halbmond-Und-Kaiseradler-Goeben-Und-Breslau-Am-Bosporus-1914-1918-by-Helmut-Hubel.pdf
    • http://loaminoo.linkpc.net/4093092094096092/The-Story-of-Kinmel-Park-Military-Training-Camp-1914-to-1918-by-Robert-H-Griffiths.pdf
    • http://loaminoo.linkpc.net/9093097092097095/Die-Flotte-Schlaft-Im-Hafen-Ein-Kriegsalltag-1914-1918-in-Matrosen-Tagebuchern-by-Stephan-Huck.pdf
    • http://loaminoo.linkpc.net/1090092091095094090/Paris-at-the-End-of-the-World-How-the-City-of-Lights-Soared-in-Its-Darkest-Hour-1914-1918-by-John-Baxter.pdf