Malicious PDF — malware analysis report

Static analysis result for SHA-256 04e7809771f21803…

MALICIOUS

PDF

23.9 KB Created: 2019-05-02 00:19:30 +01:00 Authoring application: mPDF 5.7
MD5: dd627febc520e31bce4c1fae4b751c7e SHA-1: c05f88fd77b55490295e209a1ba0db61a8765675 SHA-256: 04e7809771f2180328bc3d9b3fd332a5782dae302fb912182bf805679ae07d3d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files hosted on the domain 'seasasac.lflinkup.com'. This is indicative of a link farm or SEO poisoning attack, designed to drive traffic to malicious or low-quality content. While no scripts were explicitly extracted, the heuristic 'PDF_SEO_LINK_FARM' strongly suggests this malicious intent. The ML classifier also flagged the PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/6da0da2da8da8da5/Humbert-Castle-Or-the-Romance-of-the-Rhone-Vol-I-by-Sarah-Sheriffe.pdf
    • http://seasasac.lflinkup.com/6da0da2da8da8da8/Humbert-Castle-Or-the-Romance-of-the-Rhone-Vol-III-by-Sarah-Sheriffe.pdf
    • http://seasasac.lflinkup.com/6da0da2da8da8da7/Humbert-Castle-Or-the-Romance-of-the-Rhone-Vol-IV-by-Sarah-Sheriffe.pdf
    • http://seasasac.lflinkup.com/8da2da5da5da4da9/Bouches-Du-Rhone-Gemeente-in-Bouches-Du-Rhone-Kanton-Van-Bouches-Du-Rhone-Plaats-in-Bouches-Du-Rhone-Spoorwegstation-in-Bouches-Du-Rhone-by-Source-Wikipedia.pdf
    • http://seasasac.lflinkup.com/1da1da9da0da5da9/Fugitive-Romance-The-Fictional-Memoir-of-a-Hollywood-Screenwriter-by-Harry-Castle.pdf
    • http://seasasac.lflinkup.com/1da1da0da0da3da9da6/Leif-A-Time-Travel-Romance-Dunskey-Castle-7-by-Jane-Stain.pdf
    • http://seasasac.lflinkup.com/8da5da4da3da4da3/MENAGE-ROMANCE-BOX-SET-Love-Triangle-7-Enthralling-MMF-Romance-Short-Stories-MMF-Romance-MMF-Menage-Romance-Menage-Romance-by-Marilou-Knox.pdf
    • http://seasasac.lflinkup.com/2da6da6da8da1da3/A-Timeless-Romance-Anthology-All-Hallows-Eve-by-Sarah-M-Eden.pdf
    • http://seasasac.lflinkup.com/4da5da6da8da7da1/ROMANCE-CONTEMPORARY-ROMANCE-Bounty-and-the-Beast-Billionaire-Bad-Boy-Heroine-Mystery-Romance-Contemporary-Mystery-and-Suspense-Mafia-Romance-Book-2-by-Portia-Paige.pdf
    • http://seasasac.lflinkup.com/4da5da6da8da3da7/Loyalty-Fight-New-Adult-Biker-Gang-Romance-Night-Horses-MC-Book-4-by-Sarah-Sorana.pdf
    • http://seasasac.lflinkup.com/8da5da4da3da3da6/MMF-Attracted-by-Bad-Boys-Romance-Bad-Boy-Military-Menage-Romance-New-Adult-Romance-by-Marilou-Knox.pdf
    • http://seasasac.lflinkup.com/9da6da7da7da4da3/Dolwyddelan-Castle---Dolbadarn-Castle---Castell-Y-Bere-by-Richard-Avent.pdf
    • http://seasasac.lflinkup.com/4da8da2da4da6da5/Castle-Spellbound-Castle-Perilous-7-by-John-DeChancie.pdf
    • http://seasasac.lflinkup.com/6da0da2da8da5da3/C-G-Jung-The-Fundamentals-of-Theory-and-Practice-by-Elie-G-Humbert.pdf
    • http://seasasac.lflinkup.com/3da0da9da8da7/Castle-to-Castle-by-Louis-Ferdinand-C-line.pdf
    • http://seasasac.lflinkup.com/6da0da2da8da4da7/Voice-of-the-Beastwoman-The-Apocalypse-of-Humbert-Pinrod-by-David-S-Nichols.pdf
    • http://seasasac.lflinkup.com/6da0da2da8da8da4/Season-of-the-Itch-A-Humbert-and-McGee-Adventure-Book-2-by-Charlie-Brown.pdf
    • http://seasasac.lflinkup.com/6da0da2da7da8da1/Story-of-Humbert-Mr-Firkin-and-the-Lord-Mayor-of-London-by-John-Burningham.pdf
    • http://seasasac.lflinkup.com/1da0da0da1da2da8da5/Effi-Briest-Fontanes-Versteckspiel-Mittels-Sprachgestaltung-Und-Matressenspuk-by-Humbert-Settler.pdf
    • http://seasasac.lflinkup.com/4da8da4da2da3da0/ROMANCE-SHIFTER-ROMANCE-Knocked-Up-By-The-Navy-Shifter-Navy-Seal-Pregnancy-Alpha-Male-Romance-Paranormal-Fantasy-Protector-Short-Stories-by-Silvia-Pierce.pdf