Malicious PDF — malware analysis report

Static analysis result for SHA-256 0b2339b671366c59…

MALICIOUS

PDF

18.7 KB Created: 2019-04-30 06:35:41 +01:00 Authoring application: mPDF 5.7
MD5: f009672d2b0be97a40ea459f32754057 SHA-1: bc919aa0065b114fe9cb2f04a495d2b40c83be56 SHA-256: 0b2339b671366c59e8261f9c556404e062e2d0c186cb31ad51a3f44236e0f514
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS classifier also flagged the document with high confidence. The embedded URLs, while appearing benign in reputation checks, are part of a link farm designed to direct users to external content, potentially for SEO manipulation or to host malicious payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6095090098095092/Marcella-s-Italian-Kitchen-by-Marcella-Hazan.pdf
    • http://loaminoo.linkpc.net/6095090099095094/Marcella-Says-Italian-Cooking-Wisdom-from-the-Legendary-Teacher-s-Master-Classes-with-120-of-Her-Irresistible-New-Recipes-by-Marcella-Hazan.pdf
    • http://loaminoo.linkpc.net/3090098093096090/More-Classic-Italian-Cooking-by-Marcella-Hazan.pdf
    • http://loaminoo.linkpc.net/6095090098095091/Amarcord-Marcella-Remembers-by-Marcella-Hazan.pdf
    • http://loaminoo.linkpc.net/6095090099092091/A-Bitter-Chill-An-Aurelia-Marcella-Roman-Mystery-Aurelia-Marcella-Roman-Series-by-Jane-Finnis.pdf
    • http://loaminoo.linkpc.net/4099099091095094/Marcella-by-Mrs-Humphry-Ward.pdf
    • http://loaminoo.linkpc.net/6095090098095099/Marcella-by-Marilyn-Coffey.pdf
    • http://loaminoo.linkpc.net/2091093091095099/Nightmare-Ink-Living-Ink-1-by-Marcella-Burnard.pdf
    • http://loaminoo.linkpc.net/6095090099091091/Marcella-s-Awakening-by-Johnny-Dorsey.pdf
    • http://loaminoo.linkpc.net/6095091090090092/Marcella-by-Mary-Arnold-Ward.pdf
    • http://loaminoo.linkpc.net/1092099095094/Of-Rascals-And-Rainbows-by-Marcella-Thompson.pdf
    • http://loaminoo.linkpc.net/4091097095090090/Bound-by-Ink-Living-Ink-2-by-Marcella-Burnard.pdf
    • http://loaminoo.linkpc.net/6095090098097091/Marcella-A-Raggedy-Ann-Story-by-Johnny-Gruelle.pdf
    • http://loaminoo.linkpc.net/6095090099091094/Danger-in-the-Wind-Aurelia-Marcella-4-by-Jane-Finnis.pdf
    • http://loaminoo.linkpc.net/6095090098097098/A-Bitter-Chill-Aurelia-Marcella-2-by-Jane-Finnis.pdf
    • http://loaminoo.linkpc.net/4097096095098095/Call-of-the-Witch-Tony-Marcella-Mysteries-7-by-Dana-E-Donovan.pdf
    • http://loaminoo.linkpc.net/6095090099096094/Organizational-Culture-Change-Unleashing-Your-Organization-s-Potential-in-Circles-of-10-by-Marcella-Bremer.pdf
    • http://loaminoo.linkpc.net/8094090097091099/Chloe-s-Vegan-Italian-Kitchen-150-Pizzas-Pastas-Pestos-Risottos-amp-Lots-of-Creamy-Italian-Classics-by-Chloe-Coscarelli.pdf
    • http://loaminoo.linkpc.net/4097096095098097/Return-Of-The-Witch-Detective-Marcella-Witch-s-series-9-by-Dana-E-Donovan.pdf
    • http://loaminoo.linkpc.net/8095097099092095/Gennaro-s-Italian-Family-Favourites-Authentic-recipes-from-an-Italian-kitchen-by-Gennaro-Contaldo.pdf