Malicious PDF — malware analysis report

Static analysis result for SHA-256 5b68a74bf66802f1…

MALICIOUS

PDF

23.0 KB Created: 2019-04-30 05:29:09 +01:00 Authoring application: mPDF 5.7
MD5: 6fbded6f0d6df73a2e6acc86c88c38b1 SHA-1: b3ad6a2e04c15f55baa19c77ceb037267e962bad SHA-256: 5b68a74bf66802f1cf95339b857e4293bffb330bb01f414a92dd6e5a29d0760f
132 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, suggesting a link farm or a method to distribute further malicious content. The 'PDF_LAUNCH' heuristic indicates an attempt to automatically launch an action, likely to redirect the user to these links. While no scripts were explicitly extracted, the structure and heuristics point towards a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9977

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Launch action high PDF_LAUNCH
    PDF contains a /Launch action with an unresolved or extension-less target — treat as potentially dangerous
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2092095096097093/Solomon-Time-Adventures-in-the-South-Pacific-by-Will-Randall.pdf
    • http://loaminoo.linkpc.net/1091092093094093099/The-First-South-Pacific-Campaign-Pacific-Fleet-Strategy-December-1941-June-1942-by-John-B-Lundstrom.pdf
    • http://loaminoo.linkpc.net/4095091099090096/Guns-Drugs-and-Coconuts-South-Pacific-and-South-East-Asia-by-John-Frederick-Dixon.pdf
    • http://loaminoo.linkpc.net/7096092097093090/Michener-s-South-Pacific-by-Stephen-J-May.pdf
    • http://loaminoo.linkpc.net/6098098092093095/The-Tale-of-South-Pacific-by-Thana-Skouras.pdf
    • http://loaminoo.linkpc.net/4095098090095095/The-South-Pacific-Murders-A-Mia-Ferrari-Mystery-3-by-Sylvia-Massara.pdf
    • http://loaminoo.linkpc.net/5091091096096090/Representing-the-South-Pacific-Colonial-Discourse-from-Cook-to-Gauguin-by-Rod-Edmond.pdf
    • http://loaminoo.linkpc.net/3097091093095091/The-Ghost-Mountain-Boys-Their-Epic-March-and-the-Terrifying-Battle-for-New-Guinea--The-Forgotten-War-of-the-South-Pacific-by-James-Campbell.pdf
    • http://loaminoo.linkpc.net/4093097091097090/The-Epidemic-of-Our-Time-by-Dr-Solomon-Agbor.pdf
    • http://loaminoo.linkpc.net/8091091097091094/Launch-Advertising-and-Promotion-in-Real-Time-by-Michael-R-Solomon.pdf
    • http://loaminoo.linkpc.net/2097097091098092/Adventures-Through-Time-Time-Patrol-Nancy-Laplante-2-by-Michel-Poulin.pdf
    • http://loaminoo.linkpc.net/1093091099095/The-Adventures-of-a-South-Pole-Pig-A-Novel-of-Snow-and-Courage-by-Chris-Kurtz.pdf
    • http://loaminoo.linkpc.net/2099097099098092/South-Toward-Home-Adventures-and-Misadventures-in-my-Native-Land-by-Julia-Reed.pdf
    • http://loaminoo.linkpc.net/2091090096097098/The-Curve-of-Time-The-Classic-Memoir-of-a-Woman-and-Her-Children-Who-Explored-the-Coastal-Waters-of-the-Pacific-Northwest-by-M-Wylie-Blanchet.pdf
    • http://loaminoo.linkpc.net/9099099092094091/The-Seal-of-Solomon-The-Gifts-of-Solomon-Volume-1-by-Ryan-Mitchell.pdf
    • http://loaminoo.linkpc.net/1093095094093096/Time-Travel-Adventures-Of-The-1800-Club-Time-Travel-Adventures-of-the-1800-Club-1-by-Robert-McAuley.pdf
    • http://loaminoo.linkpc.net/7096092097093091/Rascals-in-Paradise-Turbulent-Adventures-and-Bold-Courage-on-the-South-Seas-by-James-A-Michener.pdf
    • http://loaminoo.linkpc.net/4098090098095095/1st-Time-Love-Dirty-Down-South-Novel-by-Sapphire-Knight.pdf
    • http://loaminoo.linkpc.net/9099099092094092/Long-Time-Dying-Box-Set-Long-Time-Dying-1-3-by-Solomon-Carter.pdf
    • http://loaminoo.linkpc.net/7095093096097096/Martin-Meursault-s-Enjoy-The-Authoritative-Guide-To-The-Restaurants-Of-The-Monterey-Peninsula-Including-Carmel-Monterey-Pacific-Grove-Pebble-Beach-Marina-Seaside-Carmel-Valley-The-South-Coast-And-Beyond-by-Martin-Meursault.pdf