Malicious PDF — malware analysis report

Static analysis result for SHA-256 38867b27e9c9ecc4…

MALICIOUS

PDF

17.6 KB Created: 2019-05-02 12:30:30 +01:00 Authoring application: mPDF 5.7
MD5: 0f8fa8f2d7425908921aa648faae8732 SHA-1: d61658c83365a329ff9dc29a55235922097db7b5 SHA-256: 38867b27e9c9ecc449ec8b027e4b483a2f1610cd8621c9f3be04d67b6296a6e5
150 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. ClamAV also detected this as Pdf.Dropper.Agent-7379354-0, further supporting its malicious nature. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7379354-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7379354-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8099095090099098/Beyond-Good-and-Evil-Prelude-to-a-Philosophy-of-the-Future-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/6091096090099098/Beyond-Good-and-Evil-Prelude-to-a-Philosophy-of-the-Future-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/8090093090099099/Beyond-Good-And-Evil-FREE-The-Republic-By-Plato-100-Formatted-Illustrated---JBS-Classics-100-Greatest-Novels-of-All-Time-Book-78-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/6094099090095095/Also-sprach-Zarathustra-Ein-Buch-f-r-alle-und-keinen-by-Friedrich-Wilhelm-Nietzsche-Friedrich-Nietzsche-Fritz-Koegel-Publication-date-1907-by-Friedrich-Wilhelm-Nietzsche.pdf
    • http://loaminoo.linkpc.net/2092092091093099/Basic-Writings-of-Nietzsche-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/4098092093096094/A-Nietzsche-Reader-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/7097097098091090/The-School-for-Good-and-Evil-B-amp-N-Exclusive-Edition-The-School-for-Good-and-Evil-Series-1-by-Iacopo-Bruno-Illustrator-Soman-Chainani.pdf
    • http://loaminoo.linkpc.net/5098099097097092/The-School-for-Good-and-Evil-Reihe-The-School-for-Good-and-Evil-1-3-by-Soman-Chainani.pdf
    • http://loaminoo.linkpc.net/1090093091090090090/Al-m-do-bem-e-do-mal-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/3099096097092097/Twilight-of-the-Idols-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/4096095094091/On-the-Genealogy-of-Morals-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/3096090099095/The-Anti-Christ-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/8095095099093097/Thus-Spoke-Zarathustra-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/2091095095093098/The-Anti-Christ-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/9097095094099090/Joyful-Wisdom-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/7093093091096096/Thus-Spoke-Zarathustra-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/3094097091097/Thus-Spake-Zarathustra-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/6090099094093091/Schopenhauer-as-Educator-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/8098097099099/The-Pre-Platonic-Philosophers-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/5097097092095093/Thus-Spoke-Zarathustra-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/6094099090095095/Also-sprach-Zarathustra-Ein-Buch-f-r-alle-und-keinen-by-Friedrich-Wilhelm-Nietzsche-Friedrich-Nietzsche-Fritz-Koegel-Publicat