Malicious PDF — malware analysis report

Static analysis result for SHA-256 08120a498ce76b51…

MALICIOUS

PDF

18.7 KB Created: 2019-05-02 07:29:30 +01:00 Authoring application: mPDF 5.7
MD5: 15b1bf63ce06745286fc890be66ca3b5 SHA-1: 82d708dbea2992346e72f1a67ecbccafb5691218 SHA-256: 08120a498ce76b519c8a2141cf4ffe4c0ad20f86ece3a048de0fafafb3466f1c
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which are presented as book titles. These links likely serve as a lure to direct users to potentially malicious websites. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification of this document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5091092090095094/Hitler-s-Prisons-Legal-Terror-in-Nazi-Germany-by-Nikolaus-Wachsmann.pdf
    • http://loaminoo.linkpc.net/4095091099094098/What-We-Knew-Terror-Mass-Murder-and-Everyday-Life-in-Nazi-Germany-by-Eric-A-Johnson.pdf
    • http://loaminoo.linkpc.net/9092098093091090/The-Trial-of-Adolf-Hitler-The-Beer-Hall-Putsch-and-the-Rise-of-Nazi-Germany-by-David-King.pdf
    • http://loaminoo.linkpc.net/9092098092096091/The-Rise-of-Nazi-Germany-The-History-of-the-Events-that-Brought-Adolf-Hitler-to-Power-by-Charles-River-Editors.pdf
    • http://loaminoo.linkpc.net/1091091090096097096/Meine-Kindheit-im-zweiten-Weltkrieg-Nazi-Terror-Bomben-Terror-Todes-ngste-Wohnungsnot-Hungersnot-Alliierten-Terror-by-Dieter-Schulz.pdf
    • http://loaminoo.linkpc.net/2092097099094098/Suicide-in-Nazi-Germany-by-Christian-Goeschel.pdf
    • http://loaminoo.linkpc.net/4093092098/Blitzed-Drugs-in-Nazi-Germany-by-Norman-Ohler.pdf
    • http://loaminoo.linkpc.net/1090090094091091096/Different-Drummers-Jazz-in-the-Culture-of-Nazi-Germany-by-Michael-H-Kater.pdf
    • http://loaminoo.linkpc.net/1095094099093/Mischling-Second-Degree-My-Childhood-in-Nazi-Germany-by-Ilse-Koehn.pdf
    • http://loaminoo.linkpc.net/1091093093096094097/Nazi-Germany-and-the-Jews-1933-1945-by-Saul-Friedl-nder.pdf
    • http://loaminoo.linkpc.net/8093096092093091/The-Cause-of-Hitler-s-Germany-by-Leonard-Peikoff.pdf
    • http://loaminoo.linkpc.net/3097093091095093/Good-bye-Marianne-A-Story-of-Growing-Up-in-Nazi-Germany-by-Irene-N-Watts.pdf
    • http://loaminoo.linkpc.net/1095094098090091/Destined-to-Witness-Growing-Up-Black-in-Nazi-Germany-by-Hans-J-Massaquoi.pdf
    • http://loaminoo.linkpc.net/6096098090091090/NAZI-EVIL-Hitler-and-Mengele---2-Books-in-1-by-Anna-Ravell.pdf
    • http://loaminoo.linkpc.net/1091095096098092090/Selling-Hitler-Propaganda-and-the-Nazi-Brand-by-Nicholas-O-39-Shaughnessy.pdf
    • http://loaminoo.linkpc.net/1095099093098090/Exit-Berlin-How-One-Woman-Saved-Her-Family-from-Nazi-Germany-by-Charlotte-Bonelli.pdf
    • http://loaminoo.linkpc.net/2093090091095/Nazi-Germany-and-the-Jews-The-Years-of-Extermination-1939-1945-by-Saul-Friedl-nder.pdf
    • http://loaminoo.linkpc.net/5090097093095096/Nazi-Germany-Canadian-Responses-Confronting-Antisemitism-in-the-Shadow-of-War-by-L-Ruth-Klein.pdf
    • http://loaminoo.linkpc.net/4098096098096093/Churchill-s-Deception-The-Dark-Secret-That-Destroyed-Nazi-Germany-by-Louis-C-Kilzer.pdf
    • http://loaminoo.linkpc.net/8095098097092098/Nazi-Germany-And-British-Guilt-Epilogue-The-German-Victory-by-Cecil-Genese.pdf