Malicious PDF — malware analysis report

Static analysis result for SHA-256 a8dcc40bfc636e4c…

MALICIOUS

PDF

18.7 KB Created: 2019-05-02 00:55:20 +01:00 Authoring application: mPDF 5.7
MD5: f1e03cc03b2b6935476d45161e48d7d8 SHA-1: 7e3b67624bd2501c712412a19d03113de08754b0 SHA-256: a8dcc40bfc636e4c38de5a01cf9e13cd77f1b24f075969e442d30c5a5c8d9fc0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a 'PDF_SEO_LINK_FARM' heuristic. While the URLs themselves are currently classified as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to act as a redirector to malicious sites. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7091092091096/Best-Ghost-Stories-of-Algernon-Blackwood-by-Algernon-Blackwood.pdf
    • http://loaminoo.linkpc.net/2093091097098096/The-Wolves-of-God-And-Other-Fey-Stories-by-Algernon-Blackwood.pdf
    • http://loaminoo.linkpc.net/3097091099093093/Algernon-Blackwood-by-Algernon-Blackwood.pdf
    • http://loaminoo.linkpc.net/4094092099090097/The-Wendigo-by-Algernon-Blackwood.pdf
    • http://loaminoo.linkpc.net/3091090098095096/Jimbo-A-Fantasy-by-Algernon-Blackwood.pdf
    • http://loaminoo.linkpc.net/1092099099094095/Algernon-Blackwood-An-Extraordinary-Life-by-Mike-Ashley.pdf
    • http://loaminoo.linkpc.net/7090096099097094/The-Masterpiece-Library-of-Short-Stories-The-Thousand-Best-Complete-Tales-of-all-Times-and-all-Countries-Volume-V-French-amp-Volume-VI-French-and-Belgian-by-John-Alexander-Hammerton.pdf
    • http://loaminoo.linkpc.net/1090094094093094090/Some-of-the-Silence-by-John-Elsberg.pdf
    • http://loaminoo.linkpc.net/3096097095096/Silence-Among-the-Weapons-by-John-Arden.pdf
    • http://loaminoo.linkpc.net/2095095098098093/Silence-on-the-Mountain-Stories-of-Terror-Betrayal-and-Forgetting-in-Guatemala-by-Daniel-Wilkinson.pdf
    • http://loaminoo.linkpc.net/9092093093096091/Breaking-the-Silence-The-Films-of-John-Pilger-by-Anthony-Hayward.pdf
    • http://loaminoo.linkpc.net/7098097097091091/Between-Silence-and-Light-Spirit-in-the-Architecture-of-Louis-I-Kahn-by-John-Lobell.pdf
    • http://loaminoo.linkpc.net/7098090091091098/Kate-Chopin-Complete-Novels-and-Stories-At-Fault-Bayou-Folk-A-Night-in-Acadie-The-Awakening-Uncollected-Stories-by-Kate-Chopin.pdf
    • http://loaminoo.linkpc.net/2094096099097097/Silence-Breaking-Storm-and-Silence-4-by-Robert-Thier.pdf
    • http://loaminoo.linkpc.net/3090098097098093/Silence-Part-Two-of-Echoes-amp-Silence-by-Angela-M-Hudson.pdf
    • http://loaminoo.linkpc.net/4098099095090/John-Le-Carr-Three-Complete-Novels-Tinker-Tailor-Soldier-Spy-The-Honourable-Schoolboy-Smiley-s-People-by-John-le-Carr-.pdf
    • http://loaminoo.linkpc.net/5097095096090/Broken-Silence-Silence-2-by-Natasha-Preston.pdf
    • http://loaminoo.linkpc.net/8092099094091/The-Complete-Stories-by-Bernard-Malamud.pdf
    • http://loaminoo.linkpc.net/2098097091096095/Complete-Stories-by-Dorothy-Parker.pdf
    • http://loaminoo.linkpc.net/1095094095/The-Complete-Stories-by-Clarice-Lispector.pdf
    • http://loaminoo.linkpc.net/1090094094093094090/Some-of-the-Silen