Linux Analysis Report
sample-link.pdf

Overview

General Information

Sample name: sample-link.pdf
Analysis ID: 1523489
MD5: 72dc5a929aa6b537e7b244313cd03940
SHA1: 06dff1e526b60ee381f6bad27b2386d58f552155
SHA256: ba4827b1b4f0e5d650c464287f6d55b542296f0acb628fb5575aa97d13990ac1
Infos:

Detection

Score: 2
Range: 0 - 100
Whitelisted: false

Signatures

Creates hidden files and/or directories
Document contains embedded VBA macros
Document misses a certain OLE stream usually present in this Microsoft Office document type
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Source: recently-used.xbel.IDNSU2.38.dr String found in binary or memory: http://freedesktop.org
Source: sample-link.pdf String found in binary or memory: http://www.antennahouse.com/purchase.htm)
Source: recently-used.xbel.IDNSU2.38.dr String found in binary or memory: http://www.freedesktop.org/standards/desktop-bookmarks
Source: recently-used.xbel.IDNSU2.38.dr String found in binary or memory: http://www.freedesktop.org/standards/shared-mime-info
Source: recently-used.xbel.IDNSU2.38.dr OLE indicator, VBA macros: true
Source: recently-used.xbel.IDNSU2.38.dr OLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
Source: classification engine Classification label: clean2.linPDF@0/2@0/0
Source: /usr/bin/exo-open (PID: 4790) Directory: /home/james/.Xauthority Jump to behavior
Source: /usr/bin/exo-open (PID: 4790) Directory: /home/james/.cache Jump to behavior
Source: /usr/bin/dbus-launch (PID: 4798) Directory: /home/james/.Xauthority Jump to behavior
Source: /usr/bin/evince (PID: 4816) Directory: /home/james/.Xauthority Jump to behavior
Source: /usr/bin/evince (PID: 4816) Directory: /home/james/.Xauthority Jump to behavior
Source: /usr/bin/evince (PID: 4816) Directory: /home/james/.Xdefaults-ubuntu Jump to behavior
Source: /usr/bin/evince (PID: 4816) Directory: /home/james/.cache Jump to behavior
Source: /usr/bin/dbus-launch (PID: 4833) Directory: /home/james/.Xauthority Jump to behavior
Source: /usr/bin/exo-open (PID: 4790) Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/dbus-launch (PID: 4798) Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/evince (PID: 4816) Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/dbus-launch (PID: 4833) Queries kernel information via 'uname': Jump to behavior
No contacted IP infos