Malicious PDF — malware analysis report

Static analysis result for SHA-256 32443cbad67437b1…

MALICIOUS

PDF

22.5 KB Created: 2019-04-30 04:57:49 +01:00 Authoring application: mPDF 5.7
MD5: 0a046bcc66ee38274bb7c820d4f7be63 SHA-1: 57703452ff57531e8f79de31dfec564f957abb15 SHA-256: 32443cbad67437b1f1d7450af62842cc467314fbbf997ab6388ebfa4a6a1cee4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, characteristic of a link farm designed to redirect users to potentially harmful content. While the specific URLs extracted were classified as benign, the sheer volume and the heuristic firing indicate a malicious intent to leverage these links for further attacks. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5099097098092096/Portuguese-Cochin-and-the-Maritime-Trade-of-India-1500-1663-by-Pius-Malekandathil.pdf
    • http://loaminoo.linkpc.net/5099097097090099/Phoenix-Portuguese-Voyages-1498-1663-Tales-from-the-Great-Age-of-Discovery-by-C-D-Ley.pdf
    • http://loaminoo.linkpc.net/6090097094092091/A-Letter-to-the-Right-Honorable-the-Earl-of-Buckinghamshire-President-of-the-Board-of-Commissioners-for-the-Affairs-of-India-on-the-Subject-of-an-Open-Trade-to-India-by-Fabius-Fabius.pdf
    • http://loaminoo.linkpc.net/6099091090092091/Organizing-the-Revolution-Selections-from-Augustin-Cochin-by-Augustin-Cochin.pdf
    • http://loaminoo.linkpc.net/2093092092098090/Trade-and-Traders-in-Muslim-Spain-The-Commercial-Realignment-of-the-Iberian-Peninsula-900-1500-by-Olivia-Remie-Constable.pdf
    • http://loaminoo.linkpc.net/2098093098093/Sea-Road-to-the-Indies-An-Account-of-the-Voyages-and-Exploits-of-the-Portuguese-Navigators-Together-with-the-Life-and-Times-of-Dom-Vasco-Da-Gama-Capitao-Mor-Viceroy-of-India-and-Count-of-Vidigueira-by-Henry-Hersch-Hart.pdf
    • http://loaminoo.linkpc.net/2094098098097099/A-Pius-Stand-The-Pius-Trilogy-3-by-Declan-Finn.pdf
    • http://loaminoo.linkpc.net/1090092090095091090/Mini-Michaelis-Dicionario-English-Portuguese-Portuguese-English-by-Michaelis.pdf
    • http://loaminoo.linkpc.net/5094098097092091/Trade-And-Competition-Policies-Comparing-Objectives-And-Methods-Trade-Policy-Issues-No-4-by-Phedon-Nicolaides.pdf
    • http://loaminoo.linkpc.net/9096095093097097/Future-Track-India-Blue-Print-for-a-Dynamic-India-by-Kartik-H-.pdf
    • http://loaminoo.linkpc.net/1090094091096093095/No-Woman-s-Land-Women-from-Pakistan-India-amp-Bangladesh-Write-on-the-Partition-of-India-by-Ritu-Menon.pdf
    • http://loaminoo.linkpc.net/4098096096091094/The-Slave-Trade-The-Story-of-the-Atlantic-Slave-Trade-1440-1870-by-Hugh-Thomas.pdf
    • http://loaminoo.linkpc.net/2094098098099093/A-Pius-Legacy-by-Declan-Finn.pdf
    • http://loaminoo.linkpc.net/8092091094096/Jornada-Dos-Anjos-Portuguese-by-Sandra-Carneiro.pdf
    • http://loaminoo.linkpc.net/1091093092094096093/Sonnets-from-the-Portuguese-by-Elizabeth-Barrett-Browning.pdf
    • http://loaminoo.linkpc.net/5092092092098094/Our-Lady-of-the-Artichokes-and-Other-Portuguese-American-Stories-by-Katherine-Vaz.pdf
    • http://loaminoo.linkpc.net/7091092091090097/The-Canons-and-Decrees-of-the-Council-Of-Trent-by-Pope-Pius-V.pdf
    • http://loaminoo.linkpc.net/2098090094092091/Casti-Connubii-On-Christian-Marriage-by-Pope-Pius-XI.pdf
    • http://loaminoo.linkpc.net/8095090092099094/Pope-Pius-VII-1800-1823-by-Robin-Anderson.pdf
    • http://loaminoo.linkpc.net/2098090095097099/Quadragesimo-Anno-On-Reconstructing-the-Social-Order-by-Pope-Pius-XI.pdf
    • http://loaminoo.linkpc.net/2093092092098090/Trad