Malicious PDF — malware analysis report

Static analysis result for SHA-256 8d86f78a3df69a92…

MALICIOUS

PDF

16.0 KB Created: 2019-05-03 16:47:31 +01:00 Authoring application: mPDF 5.7
MD5: a127b74f6c4617e6433e53d64ad5738c SHA-1: 815ca197a135002e7e4472b79a9184de85c3f398 SHA-256: 8d86f78a3df69a92ece7f947f202e6d3f753f46468dcf8cf8a4660ec0c4a32fe
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to distribute further malware. The ML_NYX_PDF_MALICIOUS heuristic also strongly indicates maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3096090091097092/The-Mammoth-Book-of-Zombie-Apocalypse-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/4090096095091096/Zombie-Apocalypse-Fightback-Zombie-Apocalypse-2-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/4090096091097098/The-Mammoth-Book-of-Zombies-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/3096097097097092/Best-New-Horror-16-The-Mammoth-Book-of-Best-New-Horror-16-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/2096091096097/Best-New-Horror-12-The-Mammoth-Book-of-Best-New-Horror-12-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/9095099095091/Best-New-Horror-21-The-Mammoth-Book-of-Best-New-Horror-21-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/9095097092091/Best-New-Horror-20-The-Mammoth-Book-of-Best-New-Horror-20-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/9095097094090/Best-New-Horror-14-The-Mammoth-Book-of-Best-New-Horror-14-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/4090098094090090/Best-New-Horror-22-The-Mammoth-Book-of-Best-New-Horror-22-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/9092090090099/Love-amp-the-Zombie-Apocalypse-Zombie-Apocalypse-1-by-Chelsea-Luna.pdf
    • http://loaminoo.linkpc.net/4094099090095095/Zombie-Country-Zombie-Apocalypse-2-by-Samantha-Hoffman.pdf
    • http://loaminoo.linkpc.net/1092096090095096/Zombie-Island-Zombie-Apocalypse-1-by-Samantha-Hoffman.pdf
    • http://loaminoo.linkpc.net/6091097090095092/Dawn-of-the-Apocalypse-A-Zombie-Apocalypse-Novel-by-T-W-Gallier.pdf
    • http://loaminoo.linkpc.net/2096090095095/A-Book-of-Horrors-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/3096090097091099/Dead-Days-Season-Six-Dead-Days-Zombie-Apocalypse-Series-Book-6-by-Ryan-Casey.pdf
    • http://loaminoo.linkpc.net/1090093095093099093/Kyler-Cleave-and-the-Zombie-Apocalypse-Book-One-of-the-Kyler-Cleave-Series-by-Tyler-Reno.pdf
    • http://loaminoo.linkpc.net/2092090094096096/Apocalypse-Mom-Diary-of-an-Ordinary-Woman-in-a-Not-So-Ordinary-World-Apocalypse-Mom-Series-1-by-Elizabeth-L-Jones.pdf
    • http://loaminoo.linkpc.net/3099094099094094/Apocalypse-Z-A-Zombie-Novel-by-G-E-Swanson.pdf
    • http://loaminoo.linkpc.net/3099091090097098/H-P-Lovecraft-s-Book-of-the-Supernatural-Classic-Tales-of-the-Macabre-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/2091094092095091/Vegan-Zombie-Apocalypse-by-Wol-vriey.pdf
    • http://loaminoo.linkpc.net/4094099090095095/Zombie-Country-Zombie-Apocalypse-2-by-Samanth