Malicious PDF — malware analysis report

Static analysis result for SHA-256 8ce80d1a600388e9…

MALICIOUS

PDF

25.9 KB Created: 2019-05-01 18:33:14 +01:00 Authoring application: mPDF 5.7
MD5: 7cc8dd81a6060cfd83cd6094d218e90a SHA-1: a3f9709d4eb006a7ebc0b9491d1535446a3d5367 SHA-256: 8ce80d1a600388e90fda2132eb72461057b5bea6be13390a7a0e5cab1fe75d01
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or distribution mechanism. While the specific URLs extracted are currently marked as benign, the sheer volume and the ML classifier's high confidence indicate malicious intent. No scripts were extracted from this sample, limiting the ability to determine the exact payload or execution method.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9914

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://zacdsa.linkpc.net/5c55c54c50c57/A-Court-of-Thorns-and-Roses-A-Court-of-Thorns-and-Roses-1-by-Sarah-J-Maas.pdf
    • http://zacdsa.linkpc.net/4c53c51c55c53c55/A-Court-of-Thorns-and-Roses-A-Court-of-Thorns-and-Roses-1-by-Sarah-J-Maas.pdf
    • http://zacdsa.linkpc.net/1c59c56c54c53c50/A-Court-of-Thorns-and-Roses-Box-Set-A-Court-of-Thorns-and-Roses-1-3-by-Sarah-J-Maas.pdf
    • http://zacdsa.linkpc.net/3c53c54c50c58/A-Court-of-Mist-and-Fury-A-Court-of-Thorns-and-Roses-2-by-Sarah-J-Maas.pdf
    • http://zacdsa.linkpc.net/9c59c55c50c59/A-Court-of-Mist-and-Fury-A-Court-of-Thorns-and-Roses-2-by-Sarah-J-Maas.pdf
    • http://zacdsa.linkpc.net/3c56c53c51c56/A-Court-of-Wings-and-Ruin-A-Court-of-Thorns-and-Roses-3-by-Sarah-J-Maas.pdf
    • http://zacdsa.linkpc.net/1c58c51c56c53c54/Untitled-A-Court-of-Thorns-and-Roses-6-by-Sarah-J-Maas.pdf
    • http://zacdsa.linkpc.net/9c57c59c56c51c54/Hof-van-mist-en-woede-A-Court-of-Thorns-and-Roses-2-by-Sarah-J-Maas.pdf
    • http://zacdsa.linkpc.net/1c51c52c50c57c56c55/Crimson-Red-Roses-and-Their-Sharpened-Thorns-Crimson-Red-Roses-and-Their-Sharpened-Thorns-1-by-Geraldine-O-39-Connor.pdf
    • http://zacdsa.linkpc.net/2c55c52c56c57c52/A-Court-of-Wings-and-Ruin-by-Sarah-J-Maas.pdf
    • http://zacdsa.linkpc.net/3c50c57c57c56c55/The-Girl-of-Fire-and-Thorns-Stories-Fire-and-Thorns-0-5-0-7-by-Rae-Carson.pdf
    • http://zacdsa.linkpc.net/2c55c55c51c58c55/Blood-and-Roses-One-Family-s-Struggle-and-Triumph-During-the-Tumultuous-Wars-of-the-Roses-by-Helen-Castor.pdf
    • http://zacdsa.linkpc.net/3c57c52c52c57c56/Roses-Roses-Harpur-amp-Iles-10-by-Bill-James.pdf
    • http://zacdsa.linkpc.net/8c55c52c58c51c58/United-States-Court-of-Appeals-for-the-Ninth-Circuit-Vol-1-of-3-Greene-Process-Metal-Company-a-Corporation-Appellant-vs-Washington-Iron-Works-a-Corporation-Appelle-Transcript-of-Record-Pages-1-522-Upon-Appeal-from-the-District-Court-of-the-Uni-by-United-States-Circuit-Court-of-Appeals.pdf
    • http://zacdsa.linkpc.net/8c55c56c59c51c55/Il-court-il-court-le-furet-by-Bruno-Papet.pdf
    • http://zacdsa.linkpc.net/1c51c54c52c53c51c56/The-Deathly-Roses-Volume-2-The-Deathly-Roses-Volumes-by-Melina-Turner.pdf
    • http://zacdsa.linkpc.net/8c55c52c58c50c54/United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-N-N-S-Matcovich-Appellant-vs-Richard-Nickell-as-Collector-of-Internal-Revenue-for-the-First-District-of-California-Appelle-Transcript-of-Record-Upon-Appeal-from-the-District-Court-of-by-United-States-Circuit-Court-of-Appeals.pdf
    • http://zacdsa.linkpc.net/5c53c52c54c51c53/Twin-Roses-Beau-Rivage-1-6-by-Sarah-Cross.pdf
    • http://zacdsa.linkpc.net/4c53c50c56c50c51/Fire-and-Thorns-Fire-and-Thorns-1-by-Rae-Carson.pdf
    • http://zacdsa.linkpc.net/9c57c57c57c53c57/Totenham-Court-a-Pleasant-Comedy-Acted-at-the-Private-House-in-Salisbury-Court-by-Thomas-Nabbs-1639-by-Thomas-Nabbes.pdf
    • http://zacdsa.linkpc.net/1c51