Malicious PDF — malware analysis report

Static analysis result for SHA-256 0a2b594d65e019ca…

MALICIOUS

PDF

19.6 KB Created: 2019-04-30 08:59:23 +01:00 Authoring application: mPDF 5.7
MD5: 1e2304aee0d9fc6c2bc38522e0debdcf SHA-1: 38b6c4ec78322ebb45d97ed0b28a1806952cfaf8 SHA-256: 0a2b594d65e019ca8ce0d598c7575ead9bd56b4f683cc99c59978b30860c8513
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document. The embedded links point to various URLs, suggesting a link farm or a phishing attempt to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090093096090091091/herb-ritts-calendar-1994-by-Herb-Ritts.pdf
    • http://loaminoo.linkpc.net/1090093095098095092/H-Ritts-Poster-Film-by-Ritts.pdf
    • http://loaminoo.linkpc.net/2096099095094099/Is-Your-Body-Trying-to-Tell-You-Something-Why-It-Is-Wise-to-Listen-to-Your-Body-and-How-Massage-and-Body-Work-Can-Help-by-Carmen-Renee-Berry.pdf
    • http://loaminoo.linkpc.net/7093094099090092/The-Ultimate-Vegetable-Container-Gardening-Guide-for-Beginners-How-to-Grow-Healthy-Vegetable-amp-Herb-Gardens-in-Small-Spaces-amp-Containers-vegetable-gardening-herb-gardening-container-gardening-diy-garden-by-Chloe-Maelle.pdf
    • http://loaminoo.linkpc.net/3098096093095095/6-1-2-Body-Parts-Body-Movers-6-5-by-Stephanie-Bond.pdf
    • http://loaminoo.linkpc.net/2097092094096098/Body-by-Science-A-Research-Based-Program-for-Strength-Training-Body-Building-and-Complete-Fitness-in-12-Minutes-a-Week-by-John-Little.pdf
    • http://loaminoo.linkpc.net/4093092091096092/3-Men-And-A-Body-Body-Movers-3-by-Stephanie-Bond.pdf
    • http://loaminoo.linkpc.net/9098096091097097/Body-Language---Read-and-Understand-Body-Language-by-Body-Language-Guru.pdf
    • http://loaminoo.linkpc.net/3094095095091/Brotherman-by-Herb-Boyd.pdf
    • http://loaminoo.linkpc.net/9097094096091094/Kain-No-Ori-by-Herb-Chapman.pdf
    • http://loaminoo.linkpc.net/1093095097099091/The-Spice-and-Herb-Bible-by-Ian-Hemphill.pdf
    • http://loaminoo.linkpc.net/6090098098097096/The-Bonsai-Workshop-by-Herb-Gustafson.pdf
    • http://loaminoo.linkpc.net/6090098098099095/Miniature-Bonsai-by-Herb-Gustafson.pdf
    • http://loaminoo.linkpc.net/7098099091094091/The-House-of-Ennui-by-Herb-Childress.pdf
    • http://loaminoo.linkpc.net/1091097095099091095/The-Brennen-Siding-Trilogy-by-Herb-Curtis.pdf
    • http://loaminoo.linkpc.net/3094095097098097/African-History-for-Beginners-by-Herb-Boyd.pdf
    • http://loaminoo.linkpc.net/1090099099095098098/The-Mick-by-Mickey-Mantle-Herb-Gluck.pdf
    • http://loaminoo.linkpc.net/1093091097091090/The-Herb-of-Grace-Chain-of-Charms-3-by-Kate-Forsyth.pdf
    • http://loaminoo.linkpc.net/9099092097094094/Cannabis---A-Demonized-Herb-The-Infamy-Refuted-by-D-Farang.pdf
    • http://loaminoo.linkpc.net/3092099095097093/You-Can-Negotiate-Anything-The-World-s-Best-Negotiator-Tells-You-How-To-Get-What-You-Want-by-Herb-Cohen.pdf