Malicious PDF — malware analysis report

Static analysis result for SHA-256 8a67fb839e9542f3…

MALICIOUS

PDF

18.3 KB Created: 2019-05-01 06:19:29 +01:00 Authoring application: mPDF 5.7
MD5: 3da5f39bc2c368cab64f6dbf1baefa62 SHA-1: 0b21cc59c74fa288dc57b88d1c6b5e7cac67bcc4 SHA-256: 8a67fb839e9542f36ddb0249de90167de5074f7edaa8401fbeb756d01fe21fbf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs extracted appear to point to book titles, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to redirect users to malicious sites. The ML_NYX_PDF_MALICIOUS classifier strongly supports this assessment. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/9da4da2da2da2/Acheron-Dark-Hunter-8-Entire-Dark-Hunterverse-15-Dark-Hunterverse-23-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/5da0da4da3da8da3/House-of-the-Rising-Son-Dark-Hunter-22-5-The-Entire-Dark-Hunterverse-28-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/4da0da5da3da5da9/The-Simi-s-ABCs-Adventures-with-Dark-Hunters-Dark-Hunter-30-Dark-Hunterverse-31-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/4da0da3da1da2da6/Winter-Born-Were-Hunter-1-5-Dark-Hunterverse-6-5-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/3da2da5da2da0/Acheron-Dark-Hunter-14-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/1da4da7da7da4da7/The-Dark-Hunters-Vol-2-Dark-Hunter-Manga-2-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/3da4da9da5da7/Dark-Side-of-the-Moon-Dark-Hunter-9-Were-Hunter-3-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/1da4da5da1da1da9/A-Dark-Hunter-Christmas-Dark-Hunter-3-6-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/3da0da1da1da1da6/Styxx-Dark-Hunter-23-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/1da4da8da9da7da5/Second-Chances-Dark-Hunter-7-5-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/4da7da8da4da2da7/Styxx-Dark-Hunter-22-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/4da7da5da0da9/Styxx-Dark-Hunter-23-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/1da4da8da6da8da7/Styxx-Dark-Hunter-23-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/3da8da9da4da3/The-Guardian-Dark-Hunter-20-Dream-Hunter-5-Were-Hunter-6-Hellchaser-3-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/3da0da5da0da3da0/Seize-the-Night-Dark-Hunter-7-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/4da4da5da8da5da2/Sins-of-the-Night-Dark-Hunter-8-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/1da8da1da5da4da6/Seize-the-Night-Dark-Hunter-6-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/3da4da4da0da3/Seize-the-Night-Dark-Hunter-6-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/3da2da2da6da0da3/Night-Embrace-Dark-Hunter-3-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/4da0da2da9da2da8/Bad-Moon-Rising-Dark-Hunter-14-Were-Hunter-6-Hellchaser-3-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/1da4da5da1