Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b8b28ab7c039d62…

MALICIOUS

PDF

14.8 KB Created: 2019-05-03 05:10:44 +01:00 Authoring application: mPDF 5.7
MD5: 2a612e1482b09828f88268f48a052a97 SHA-1: d68c89040bc267eaa28fa57f1e9be85877159fe3 SHA-256: 8b8b28ab7c039d62996760f7c24f57f2309eba36efb0a532b4072e5d484e1c52
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external websites, as indicated by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently flagged as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, likely for SEO spam or to redirect users to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091090096099091092/Big-Boobs-Sex-Stories-by-Erik-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096099099093/Foerster-Amer-P-amp-P-Vol-1-amp-2-Combo-5ed-by-Michael-H-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096098091098/Cerebral-Localization-An-Otfrid-Foerster-Symposium-by-Otfrid-Foerster.pdf
    • http://loaminoo.linkpc.net/1090097092091097096/Sinnliche-Fickgeschichten-by-Marie-Fried.pdf
    • http://loaminoo.linkpc.net/1090098090090097091/Rotes-Meer-Der-achte-Fall-f-r-Erik-Winter-Ein-Erik-Winter-Krimi-by-ke-Edwardson.pdf
    • http://loaminoo.linkpc.net/6094097099094096/Buddhism-in-China-Collected-Papers-of-Erik-Zurcher-by-Erik-Z-rcher.pdf
    • http://loaminoo.linkpc.net/6091095095092095/A-Mammal-s-Notebook-Collected-Writings-of-Erik-Satie-by-Erik-Satie.pdf
    • http://loaminoo.linkpc.net/8097094090094096/Erik-Lundberg-Studies-in-Economic-Instability-and-Change-by-Erik-Lundberg.pdf
    • http://loaminoo.linkpc.net/1091090096099098094/Algebra-And-Trigonometry-by-Paula-A-Foerster.pdf
    • http://loaminoo.linkpc.net/1091098097095090/River-Road-by-Richard-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096098093093/The-Burning-of-Troy-by-Richard-Foerster.pdf
    • http://loaminoo.linkpc.net/1091096094090097094/Erstaunliche-BDSM-Sexgeschichten-by-Marie-Fried.pdf
    • http://loaminoo.linkpc.net/1090096090095092090/The-Erik-Erikson-Reader-by-Erik-H-Erikson.pdf
    • http://loaminoo.linkpc.net/1091090096098092091/Calculus-Concepts-and-Applications-by-Paul-A-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090097090090091/Algebra-I-Teacher-s-Edition-by-Paul-A-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096099091094/Introduction-to-American-Poetry-and-Prose-by-Norman-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096098093091/Hidden-in-the-Trees-An-Isle-Royale-Sojourn-by-Vic-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096097093098/Financial-Management-Concepts-and-Applications-by-Stephen-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096096093098/Lost-Ancient-Technology-Of-Egypt-by-Brien-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096099098098/Algebra-and-Trigonometry-Teacher-s-Edition-by-Paul-A-Foerster.pdf
    • http://loaminoo.linkpc.net/1091096094090097094/Erstaunliche-BDSM-Sexgeschichten-by-Mari