Malicious PDF — malware analysis report

Static analysis result for SHA-256 c63f50129cb05bab…

MALICIOUS

PDF

21.7 KB Created: 2019-05-02 06:16:55 +01:00 Authoring application: mPDF 5.7 First seen: 2019-10-01
MD5: c08e19c217770f2e545fbd4a118c4bd4 SHA-1: d24181ea033ad58f64134df45d966ff9228a0a7c SHA-256: c63f50129cb05babc448c6b9d50e7ff4a38ab40256199ed8283796329a664ce1
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files, hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a distribution mechanism for malicious content, as flagged by the PDF_SEO_LINK_FARM heuristic. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8094091091098094/Larousse-Gastronomique-Desserts-Cakes-and-Pastries-by-Jo-l-Robuchon.pdf In PDF document text
    • http://loaminoo.linkpc.net/8094091094092096/le-grand-larousse-gastronomique-by-Jo-l-Robuchon.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8094091094093090/Larousse-Gastronomique-The-Encyclopedia-of-Food-Wine-amp-Cookery-by-Prosper-Montagn-.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8094091093094092/New-Larousse-Gastronomique-The-World-s-Greatest-Cookery-Reference-Book-by-Janet-Dunbar.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3090091091096090/A-World-of-Cake-150-Recipes-for-Sweet-Traditions-from-Cultures-Near-and-Far-Honey-cakes-to-flat-cakes-fritters-to-chiffons-tartes-to-tortes-meringues-to-mooncakes-fruit-cakes-to-spice-cakes-by-Krystina-Castella.pdfIn PDF document text
    • http://loaminoo.linkpc.net/6095093098098092/Chocolate-Heavenly-recipes-for-desserts-cakes-and-other-divine-treats-by-Jennifer-Donovan.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3090097098096098/The-Complete-Robuchon-by-Jo-l-Robuchon.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3090099097091090/The-Absolute-Best-Mug-Cakes-Cookbook-100-Family-Friendly-Microwave-Cakes-by-Rockridge-Press.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3091091094098090/5-Minute-Mug-Cakes-Over-100-Yummy-Cakes-from-Funfetti-to-Peanut-Butter-by-Jennifer-Lee.pdfIn PDF document text
    • http://loaminoo.linkpc.net/6093094097099095/Raw-Desserts-11-Healthy-Desserts-With-Chocolate-by-Bj-rk-Baldursd-ttir.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3090098093094090/Martha-Stewart-s-Cakes-Our-First-Ever-Book-of-Bundts-Loaves-Layers-Coffee-Cakes-and-more-by-Martha-Stewart.pdfIn PDF document text
    • http://loaminoo.linkpc.net/6099098098090098/Pastries-and-Pilfering-Margot-Durand-3-by-Danielle-Collins.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7094099090099090/LAROUSSE-DES-MATERNELLES-by-Patricia-Maire.pdfIn PDF document text
    • http://loaminoo.linkpc.net/6096092098094091/LAROUSSE-DU-CHIEN-ET-DU-CHIOT-N-P-by-Collectif.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8096094098094090/Larousse-Biographical-Dictionary-by-Magnus-Magnusson.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3090099092098096/Success-with-Pastry-Pies-Pastries-and-Tarts-The-Essential-Guide-to-Home-Baking-by-Catherine-Atkinson.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8090092093094090/Passeport-Gastronomique-The-Netherlands-by-G-Scholten.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8090092092093096/Passeport-Gastronomique-France-Spain-by-J-Torres.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7091091095097098/Gratins-Gastronomique-la-Maison-S-rie-by-Danielle-Thi-ry.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1091093090093090092/Sweet-Eats-for-All-250-Decadent-Gluten-Free-Vegan-Recipes---from-Candy-to-Cookies-Puff-Pastries-to-Petits-Fours-by-Allyson-Kramer.pdfIn PDF document text