Malicious PDF — malware analysis report

Static analysis result for SHA-256 8f8679b216e0aa30…

MALICIOUS

PDF

17.4 KB Created: 2019-05-07 03:37:18 +01:00 Authoring application: mPDF 5.7
MD5: d213d4c4ccc5b49cfd9daf2d60b93de8 SHA-1: a363d92a45001f2fbf2f0161eab8fade101713e7 SHA-256: 8f8679b216e0aa301719513fea2af8dae1f327d908c52f05f37ca300c340bf32
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links resolve to benign-looking book titles, the sheer volume and the use of a dynamic DNS hostname suggest a potential attempt at SEO manipulation or a distribution mechanism for malicious content. The ML classifier also flagged the document as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2097099099092097/Brick-Agent-Inside-the-Mafia-for-the-FBI-by-Anthony-Villano.pdf
    • http://loaminoo.linkpc.net/2093099099090/Doom-Patrol-Volume-1-Brick-by-Brick-by-Gerard-Way.pdf
    • http://loaminoo.linkpc.net/1091095095094099090/Blood-and-Honor-Inside-the-Scarfo-Mob--The-Mafia-s-Most-Violent-Family-by-George-Anastasia.pdf
    • http://loaminoo.linkpc.net/6090091098099096/Muslim-Mafia-Inside-the-Secret-Underworld-That-s-Conspiring-to-Islamize-America-by-P-David-Gaubatz.pdf
    • http://loaminoo.linkpc.net/5093096094096094/Un-Agent-Qui-Vous-Veut-Du-Bien-by-Anthony-Burgess.pdf
    • http://loaminoo.linkpc.net/5090095099093099/American-Radical-Inside-the-World-of-an-Undercover-Muslim-FBI-Agent-by-Tamer-Elnoury.pdf
    • http://loaminoo.linkpc.net/1099091094092099/A-Time-to-Betray-The-Astonishing-Double-Life-of-a-CIA-Agent-Inside-the-Revolutionary-Guards-of-Iran-by-Reza-Kahlili.pdf
    • http://loaminoo.linkpc.net/9097092090093090/Mafia-Mistress-Mafia-2-by-Nikki-Kitchen.pdf
    • http://loaminoo.linkpc.net/9097092090093095/family-Mafia-Mafia-5-by-Nikki-Kitchen.pdf
    • http://loaminoo.linkpc.net/4098092098090/Agent-Zigzag-The-True-Wartime-Story-of-Eddie-Chapman-The-Most-Notorious-Double-Agent-of-World-War-II-by-Ben-Macintyre.pdf
    • http://loaminoo.linkpc.net/8096098090090/Polity-Agent-Agent-Cormac-4-by-Neal-Asher.pdf
    • http://loaminoo.linkpc.net/1091096093094090/Agent-21-Reloaded-Agent-21-2-by-Chris-Ryan.pdf
    • http://loaminoo.linkpc.net/3096092097092/Brick-Lane-by-Monica-Ali.pdf
    • http://loaminoo.linkpc.net/3091093093094095/Agent-A-To-Agent-Z-by-Andy-Rash.pdf
    • http://loaminoo.linkpc.net/4091099093094094/The-Golem-of-Brick-Lane-by-Jon-Sutherland.pdf
    • http://loaminoo.linkpc.net/4094097092091098/Brick-A-World-History-by-James-W-P-Campbell.pdf
    • http://loaminoo.linkpc.net/1099095098097095/You-Say-to-Brick-The-Life-of-Louis-Kahn-by-Wendy-Lesser.pdf
    • http://loaminoo.linkpc.net/1098091095090093/Mystery-over-the-Brick-Wall-by-Helen-Fuller-Orton.pdf
    • http://loaminoo.linkpc.net/3099098098092096/The-Brick-Testament-Stories-from-the-Book-of-Genesis-by-Brendan-Powell-Smith.pdf
    • http://loaminoo.linkpc.net/8095098091098093/Agent-Provocateur-69-Soixante-Neuf-by-Agent-Provocateur.pdf
    • http://loaminoo.linkpc.net/1099091094092099/A-Time-to-Betray-The-Astonishing-Double-Life-of-a-CIA-Agent-Ins