Malicious PDF — malware analysis report

Static analysis result for SHA-256 8874998175d5a789…

MALICIOUS

PDF

16.1 KB Created: 2019-04-30 19:12:45 +01:00 Authoring application: mPDF 5.7
MD5: 8156e9cf0469e6ddf6b59d5155221b8d SHA-1: 7d091daa7bb380bb0f4a0554d674fc01dfa23d55 SHA-256: 8874998175d5a789bcc757ac898685acb8a25824750854a325e0ed94456e2140
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links were labeled as confirmed_benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted, but the presence of embedded links points towards a potential initial access vector via spearphishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9099094091097098/The-Fighting-McCooks---America-s-Famous-Fighting-Family-by-Charles-Whalen.pdf
    • http://loaminoo.linkpc.net/1094098097099099/The-Fighting-Series-Box-Set-BONUS-Fighting-the-Fall-Prologue-by-J-B-Salsbury.pdf
    • http://loaminoo.linkpc.net/1093090096098097/Fighting-Men-A-Chronicle-of-Three-Black-Civil-War-Fighting-Men-by-John-Zubritsky.pdf
    • http://loaminoo.linkpc.net/1091096098/Fighting-for-Forever-Fighting-5-by-J-B-Salsbury.pdf
    • http://loaminoo.linkpc.net/1094097096092091/Fighting-to-Forget-Fighting-3-by-J-B-Salsbury.pdf
    • http://loaminoo.linkpc.net/1098092096098097/Fighting-for-Flight-Fighting-1-by-J-B-Salsbury.pdf
    • http://loaminoo.linkpc.net/1090098093090098/The-Birth-of-a-Phoenix-Phoenix-Chronicles-1-by-Candice-Snow.pdf
    • http://loaminoo.linkpc.net/3090099098095092/Phoenix-Descending-Curse-of-the-Phoenix-1-by-Dorothy-Dreyer.pdf
    • http://loaminoo.linkpc.net/3097090091093093/Secrets-in-Phoenix-Phoenix-Holt-1-by-Gabriella-Lepore.pdf
    • http://loaminoo.linkpc.net/4090093094091092/Search-for-the-Phoenix-Phoenix-Series-Book-2-by-Jim-Proctor.pdf
    • http://loaminoo.linkpc.net/1096093096099095/The-Phoenix-Embryo-Seasons-of-the-Phoenix-1-by-Jeanne-Marcella.pdf
    • http://loaminoo.linkpc.net/7090099090092093/Phoenix-Awakens-The-Phoenix-1-by-Eliza-Nolan.pdf
    • http://loaminoo.linkpc.net/4095096090097094/Dark-Phoenix-Phoenix-2-by-Elise-Faber.pdf
    • http://loaminoo.linkpc.net/7090099090099091/Red-Phoenix-Burning-Red-Phoenix-2-by-Larry-Bond.pdf
    • http://loaminoo.linkpc.net/9091092095097/Phoenix-Wright-Ace-Attorney-Official-Casebook-Vol-1---The-Phoenix-Wright-Files-by-Kenji-Kuroda.pdf
    • http://loaminoo.linkpc.net/1099099092092099/Fighting-Dirty-Fighting-Dirty-1-by-Olley-White.pdf
    • http://loaminoo.linkpc.net/3098099095091092/The-Three-Colonels-Jane-Austen-s-Fighting-Men-Jane-Austen-s-Fighting-Men-1-by-Jack-Caldwell.pdf
    • http://loaminoo.linkpc.net/2095096093091094/The-Phoenix-Project-Series-Books-1-3-The-Phoenix-Project-1-3-by-M-R-Pritchard.pdf
    • http://loaminoo.linkpc.net/2098095098092090/Phoenix-Child-Phoenix-Child-1-by-Alica-McKenna-Johnson.pdf
    • http://loaminoo.linkpc.net/1095095097094095/Phoenix-Island-Phoenix-Island-1-by-John-Dixon.pdf