Malicious PDF — malware analysis report

Static analysis result for SHA-256 6b1901aa3ca9e9d3…

MALICIOUS

PDF

14.9 KB Created: 2019-05-02 01:12:27 +01:00 Authoring application: mPDF 5.7
MD5: e43d2522700b51435b682c0dfed0fc86 SHA-1: 3dd8547a5df7664790733f16e382ec5c6bd5eec0 SHA-256: 6b1901aa3ca9e9d320b4bd1b72eab648af8789a4946772017d5c0ee9bdaaf260
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various book titles hosted on loaminoo.linkpc.net. While the ML_NYX_PDF_MALICIOUS classifier indicates malicious intent, the specific purpose of these links is unclear beyond potential SEO manipulation or as a distribution vector for further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7097097099097/Kinfolk-by-Pearl-S-Buck.pdf
    • http://loaminoo.linkpc.net/1090091096099098099/The-Mother-A-Novel-by-Pearl-S-Buck.pdf
    • http://loaminoo.linkpc.net/1090091097091095095/The-Hidden-Flower-by-Pearl-S-Buck.pdf
    • http://loaminoo.linkpc.net/1090093094091091/Imperial-Woman-by-Pearl-S-Buck.pdf
    • http://loaminoo.linkpc.net/9093097090093098/The-Living-Reed-A-Novel-of-Korea-by-Pearl-S-Buck.pdf
    • http://loaminoo.linkpc.net/2091094096097091/Living-Reed-A-Novel-of-Korea-by-Pearl-S-Buck.pdf
    • http://loaminoo.linkpc.net/2093099096092099/Three-Daughters-of-Madame-Liang-by-Pearl-S-Buck.pdf
    • http://loaminoo.linkpc.net/8097096094090/Pearl-Buck-in-China-Journey-to-the-Good-Earth-by-Hilary-Spurling.pdf
    • http://loaminoo.linkpc.net/5096091099097094/Die-gute-Erde-Roman-des-chinesischen-Menschen-House-of-Earth-1-by-Pearl-S-Buck.pdf
    • http://loaminoo.linkpc.net/1093097090092094/A-House-Divided-House-of-Earth-3-by-Pearl-S-Buck.pdf
    • http://loaminoo.linkpc.net/4093098092092091/----by-Pearl-S-Buck.pdf
    • http://loaminoo.linkpc.net/1090091096099098095/Buck-Em-The-Autobiography-of-Buck-Owens-by-Randy-Poe.pdf
    • http://loaminoo.linkpc.net/1090091097092091090/Buck-Buck-the-Chicken-by-Amy-Ehrlich.pdf
    • http://loaminoo.linkpc.net/1090091097090097093/Buck-Baxter-Love-Detective-The-Buck-Baxter-Mysteries-1-by-Geoffrey-Knight.pdf
    • http://loaminoo.linkpc.net/1090091097090098092/Buck-Godot-Zap-Gun-for-Hire-Buck-Godot-1-by-Phil-Foglio.pdf
    • http://loaminoo.linkpc.net/1090091096099098098/Buck-Godot-Psmith-Buck-Godot-2-by-Phil-Foglio.pdf
    • http://loaminoo.linkpc.net/2095097090091094/The-Poems-Of-The-Pearl-Manuscript-Pearl-Cleanness-Patience-Sir-Gawain-And-The-Green-Knight-by-Unknown.pdf
    • http://loaminoo.linkpc.net/4097095093092094/A-Mighty-Heart-The-Brave-Life-and-Death-of-My-Husband-Danny-Pearl-by-Mariane-Pearl.pdf
    • http://loaminoo.linkpc.net/8092099092093/Mistress-of-the-Pearl-The-Pearl-Saga-3-by-Eric-Van-Lustbader.pdf
    • http://loaminoo.linkpc.net/3090093093095/Defining-Pearl-a-precious-difference-by-Pearl-Matibe.pdf