Malicious PDF — malware analysis report

Static analysis result for SHA-256 38f148a33eaf8fcc…

MALICIOUS

PDF

19.6 KB Created: 2019-04-30 03:11:25 +01:00 Authoring application: mPDF 5.7
MD5: 0f6476e301213354a9b8ddcc890849ed SHA-1: 533f9919e8c6ff7e12b3821cfc96cf5763830295 SHA-256: 38f148a33eaf8fccb99abc5e930ddbb863c5702e4691cdadcc72abd0833209da
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, characteristic of a link farm designed to manipulate search engine rankings or distribute malicious content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm. No scripts were extracted from this sample. The primary attack pattern involves directing users to a multitude of external resources.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/74e54e84e34e04e7/Le-Ceramiche-Islamiche-Della-Collezione-Laura-The-Islamic-Ceramics-Of-The-Laura-Collection-by-Manuele-Scagliola.pdf
    • http://unieoooq.linkpc.net/84e04e94e24e94e3/The-Midnight-Diary-of-Zoya-Blume-Laura-Geringer-Books-by-Laura-Shaine-Cunningham.pdf
    • http://unieoooq.linkpc.net/94e44e54e04e34e9/Laura-will-zum-Ballett-Laura-1-by-Dagmar-Ho-feld.pdf
    • http://unieoooq.linkpc.net/74e54e84e34e64e9/La-Mafia-Restituisce-Il-Maltolto-Guida-All-applicazione-Della-Legge-109-96-Sull-uso-Sociale-Dei-Beni-Confiscati-AI-Mafiosi-by-Manuele-Braghero.pdf
    • http://unieoooq.linkpc.net/24e04e44e94e74e5/Beautiful-Angiola-The-Lost-Sicilian-Folk-and-Fairy-Tales-of-Laura-Gonzenbach-by-Laura-Gonzenbach.pdf
    • http://unieoooq.linkpc.net/54e94e14e54e84e6/Masterpieces-from-the-Gianni-Mattioli-Collection-by-Laura-Mattioli-Rossi.pdf
    • http://unieoooq.linkpc.net/34e24e24e24e3/The-Little-House-Collection-Little-House-1-9-by-Laura-Ingalls-Wilder.pdf
    • http://unieoooq.linkpc.net/34e74e24e24e14e2/The-Middlefield-Family-Collection-Treasuring-Emma-Faithful-to-Laura-Letters-to-Katie-A-Middlefield-Family-Novel-by-Kathleen-Fuller.pdf
    • http://unieoooq.linkpc.net/14e04e54e34e14e74e7/Joan-of-Arc-The-Collection-5-Collected-Works-by-Mark-Twain-Laura-E-Richards-Lord-Ronald-Gower-Lucy-Foster-Madison-and-Mrs-Oliphant-by-Mark-Twain.pdf
    • http://unieoooq.linkpc.net/74e34e04e94e4/Laura-Ingalls-Wilder-s-Fairy-Poems-by-Laura-Ingalls-Wilder.pdf
    • http://unieoooq.linkpc.net/44e24e34e34e94e7/Commit-To-Get-Fit-with-Laura-Dion-Jones-Casey-by-Laura-Dion-Jones-Casey.pdf
    • http://unieoooq.linkpc.net/34e34e24e0/Please-Don-t-Tell-by-Laura-Tims.pdf
    • http://unieoooq.linkpc.net/14e64e84e54e2/I-d-Know-You-Anywhere-by-Laura-Lippman.pdf
    • http://unieoooq.linkpc.net/14e94e54e34e14e7/Run-Away-by-Laura-Salters.pdf
    • http://unieoooq.linkpc.net/64e84e54e04e14e0/Hot-Sur-by-Laura-Restrepo.pdf
    • http://unieoooq.linkpc.net/14e94e54e94e74e0/Keep-Kept-2-by-Laura-Bailey.pdf
    • http://unieoooq.linkpc.net/34e24e64e84e74e0/Not-Yet-Not-Yet-1-by-Laura-Ward.pdf
    • http://unieoooq.linkpc.net/14e74e54e44e04e0/Initiate-by-Laura-L-Fox.pdf
    • http://unieoooq.linkpc.net/34e54e14e94e54e0/I-d-Know-You-Anywhere-by-Laura-Lippman.pdf
    • http://unieoooq.linkpc.net/24e64e84e24e5/After-I-m-Gone-by-Laura-Lippman.pdf
    • http://unieoooq.linkpc.net/24e04e44e94e74e5/Beautiful-Angiola-The-Lost-Sicilia