Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e06f2e8f1aeb2d0…

MALICIOUS

PDF

26.2 KB Created: 2019-04-30 04:06:54 +01:00 Authoring application: mPDF 5.7
MD5: fce02aceef4d4915d66f071fd35f3968 SHA-1: 607fa26b48e54441870039c7837ba8ecef7123ff SHA-256: 1e06f2e8f1aeb2d016543380151885cbcc8ceb2a4a7409b56dc03b6a66429dde
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF was flagged by a machine learning classifier as malicious and contains a large number of embedded URLs. The primary heuristic indicates a 'PDF_SEO_LINK_FARM', suggesting the document's purpose is to redirect users to numerous external sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9896

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6091096097095092/Systematic-Catalogue-of-Plants-Growing-in-the-Open-Air-in-the-Garden-of-Thomas-Hanbury-F-L-S-Knight-of-the-Order-of-St-Maurice-and-St-Lazarus-and-Officer-of-the-Cross-of-the-Crown-of-Italy-Palazzo-Orengo-La-Mortola-Near-Ventimiglia-Italy-by-Anonymous.pdf
    • http://loaminoo.linkpc.net/8092091096092097/Travels-Through-the-Low-Countries-Germany-Italy-and-France-with-Curious-Observations-Natural-Topographical-Moral-Physiological-amp-C-Also-a-Catalogue-of-Plants-Found-Spontaneously-Growing-in-Those-Parts-and-Their-Virtues-Volume-V-2-by-Ray-John-1627-1705.pdf
    • http://loaminoo.linkpc.net/5097094096093095/Eating-Italy-A-Culinary-Adventure-through-Italy-s-Best-Meals-by-Jeff-Michaud.pdf
    • http://loaminoo.linkpc.net/3098095093091096/It-Happened-in-Italy-Untold-Stories-of-How-the-People-of-Italy-Defied-the-Horrors-of-the-Holocaust-by-Elizabeth-Bettina.pdf
    • http://loaminoo.linkpc.net/3090095091093093/Lost-In-Italy-Italy-Intrigue-1-by-Stacey-Joy-Netzel.pdf
    • http://loaminoo.linkpc.net/3094092090098092/A-Weaver-s-Garden-Growing-Plants-for-Natural-Dyes-and-Fibers-by-Rita-Buchanan.pdf
    • http://loaminoo.linkpc.net/7096091093094097/Italy-and-her-invaders-by-Thomas-Hodkin.pdf
    • http://loaminoo.linkpc.net/7095090093090098/Travels-Through-That-Part-of-North-America-Formerly-Called-Louisiana-Vol-2-Illustrated-with-Notes-Relative-Chiefly-to-Natural-History-To-Which-Is-Added-by-the-Translator-a-Systematic-Catalogue-of-All-the-Known-Plants-of-English-North-America-or-a-Flo-by-Bossu-Bossu.pdf
    • http://loaminoo.linkpc.net/5090095097095090/The-Origin-of-Plants-The-People-and-Plants-That-Have-Shaped-Britain-s-Garden-History-Since-the-Year-1000-by-Maggie-Campbell-Culver.pdf
    • http://loaminoo.linkpc.net/2093096097099097/The-Italy-Conspiracy-by-J-D-Mallinson.pdf
    • http://loaminoo.linkpc.net/7097098095096094/Lucrezia-in-Cile-by-Italy.pdf
    • http://loaminoo.linkpc.net/3095094092096090/All-the-Way-to-Italy-by-Flavia-Brunetti.pdf
    • http://loaminoo.linkpc.net/1094091094090092/Home-to-Italy-by-Peter-Pezzelli.pdf
    • http://loaminoo.linkpc.net/3091090099095/American-in-Italy-by-Herbert-Kubly.pdf
    • http://loaminoo.linkpc.net/1091092098090097098/Pictures-from-Italy-by-Emanuel-Christ.pdf
    • http://loaminoo.linkpc.net/6094095091092096/Art-in-Renaissance-Italy-by-John-T-Paoletti.pdf
    • http://loaminoo.linkpc.net/9097098097097097/Italy-for-First-Timers-by-Lynnette-Hartwig.pdf
    • http://loaminoo.linkpc.net/8097095099096090/Pictures-from-Italy-by-Charles-Dickens.pdf
    • http://loaminoo.linkpc.net/9097094096096092/Italy-On-Two-Cappuccinos-by-Gregory-Harris.pdf
    • http://loaminoo.linkpc.net/2098095092091094/Calabria-The-Other-Italy-by-Karen-Haid.pdf
    • http://loaminoo.linkpc.net/5097094096093095/Eating-It