Malicious PDF — malware analysis report

Static analysis result for SHA-256 b7370668598295b5…

MALICIOUS

PDF

18.5 KB Created: 2019-05-01 18:32:05 +01:00 Authoring application: mPDF 5.7
MD5: a0917c0ebf185a57c448509899cb5d28 SHA-1: a0eb715211cebf02fe53606ed2e2950d58bf82f5 SHA-256: b7370668598295b5fe0214872628fad5f71cb3c6c99949e81d61bb23961b5a04
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, all hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8090091093097/Shogun-A-Novel-of-Japan-by-James-Clavell.pdf
    • http://loaminoo.linkpc.net/1097097097092091/Shogun-by-James-Clavell.pdf
    • http://loaminoo.linkpc.net/7092096095090/Shogun-Part-1-by-James-Clavell.pdf
    • http://loaminoo.linkpc.net/3093093093093099/Sh-gun-Asian-Saga-1-by-James-Clavell.pdf
    • http://loaminoo.linkpc.net/8090093097090092/Correcting-James-Clavell-s-Shogun-44-Japanese-History-amp-Cultural-Facts-That-You-May-Not-Know-by-Shiratsuyu-Asano.pdf
    • http://loaminoo.linkpc.net/1095090094090096/Shogun-Iemitsu-War-And-Romance-In-17th-Century-Tokugawa-Japan-by-Michael-R-Zomber.pdf
    • http://loaminoo.linkpc.net/1090099093090091095/Samurai-Revolution-The-Dawn-of-Modern-Japan-Seen-Through-the-Eyes-of-the-Shogun-s-Last-Samurai-by-Romulus-Hillsborough.pdf
    • http://loaminoo.linkpc.net/2094093099093099/Escape-The-Love-Story-from-Whirlwind-by-James-Clavell.pdf
    • http://loaminoo.linkpc.net/8095091093097/Noble-House-Asian-Saga-5-by-James-Clavell.pdf
    • http://loaminoo.linkpc.net/3093092092099/Noble-House-Asian-Saga-5-by-James-Clavell.pdf
    • http://loaminoo.linkpc.net/7093093095094094/Noble-House-A-Novel-Of-Contemporary-Hong-Kong-by-James-Clavell.pdf
    • http://loaminoo.linkpc.net/7096091097093/Japan-AI-A-Tall-Girl-s-Adventures-in-Japan-by-Aimee-Major-Steinberger.pdf
    • http://loaminoo.linkpc.net/8092098093092098/Phantasm-Japan-Fantasies-Light-and-Dark-From-and-About-Japan-by-Nick-Mamatas.pdf
    • http://loaminoo.linkpc.net/8098099094092/In-Ghostly-Japan-Spooky-Stories-with-the-Folklore-Superstitions-and-Traditions-of-Old-Japan-by-Lafcadio-Hearn.pdf
    • http://loaminoo.linkpc.net/6095091096095094/Escaping-Japan-Reflections-on-Estrangement-and-Exile-in-the-Twenty-First-Century-Japan-Anthropology-Workshop-Series-by-Blai-Guarn-.pdf
    • http://loaminoo.linkpc.net/4099095095096098/Strong-Society-Smart-State-The-Rise-of-Public-Opinion-in-China-s-Japan-Policy-by-James-Reilly.pdf
    • http://loaminoo.linkpc.net/9090094098092093/JLA-Shogun-Of-Steel-by-Ben-Raab.pdf
    • http://loaminoo.linkpc.net/9092094091090095/The-Shogun-s-Queen-by-Lesley-Downer.pdf
    • http://loaminoo.linkpc.net/2094093097097099/Across-a-Bridge-of-Dreams-The-Shogun-Quartet-4-by-Lesley-Downer.pdf
    • http://loaminoo.linkpc.net/1097098093096090/The-Courtesan-and-the-Samurai-The-Shogun-Quartet-3-by-Lesley-Downer.pdf
    • http://loaminoo.linkpc.net/