Malicious PDF — malware analysis report

Static analysis result for SHA-256 0ed49f6aff9b2a33…

MALICIOUS

PDF

20.6 KB Created: 2019-05-01 17:18:09 +01:00 Authoring application: mPDF 5.7
MD5: c5d3f322ce285b5df8c649e3e4d0a272 SHA-1: ef969ef6a6f83d3715a6a0b9b283715d19a5e7c8 SHA-256: 0ed49f6aff9b2a33d87427ae7139c3dc9d193f0206a38c3c249d4ec5e686db61
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document was flagged by a machine learning classifier and contains a large number of external links, indicating a potential link farm designed to distribute malicious content or phish users. The embedded links, such as http://seasasac.lflinkup.com/7da0da5da2da8da1/Grayscale-Spectrum-Book-1-by-Rebecca-Brochu.pdf, are likely part of this scheme. No scripts were extracted, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/7da0da5da2da8da1/Grayscale-Spectrum-Book-1-by-Rebecca-Brochu.pdf
    • http://seasasac.lflinkup.com/7da0da5da2da8da2/Love-In-the-Land-of-Fire-Shangri-La-1-by-Rebecca-Brochu.pdf
    • http://seasasac.lflinkup.com/7da0da5da2da6da7/The-Alpha-s-Ardor-Wolves-of-Flathead-1-by-Rebecca-Brochu.pdf
    • http://seasasac.lflinkup.com/1da6da2da5da0da7/Pick-Up-Women-Rise-of-the-Authentic-Lover---From-Your-First-Hi-To-The-Point-Of-Undressing-Her-Honest-Guide-To-21st-Century-Seduction-Pick-Up-Guide-Without-BS-by-Ignatz-Rajher.pdf
    • http://seasasac.lflinkup.com/3da9da5da6da4da1/Far-to-Go-by-Alison-Pick.pdf
    • http://seasasac.lflinkup.com/3da3da4da6da5da3/Pick-Up-the-Phone-by-Chris-Jackson.pdf
    • http://seasasac.lflinkup.com/3da4da8da2da8da4/Cowboy-Pick-up-by-Vonna-Harper.pdf
    • http://seasasac.lflinkup.com/5da4da9da3da7da1/Mommy-Pick-Me-Up-by-Soledad-Bravi.pdf
    • http://seasasac.lflinkup.com/1da5da1da6da6da7/Rebecca-and-the-Movies-American-Girls-Rebecca-4-by-Jacqueline-Dembar-Greene.pdf
    • http://seasasac.lflinkup.com/4da8da3da1da7/If-I-Had-My-Life-to-Live-Over-I-Would-Pick-More-Daisies-by-Sandra-Martz.pdf
    • http://seasasac.lflinkup.com/9da0da1da3da3/A-Bone-to-Pick-Aurora-Teagarden-2-by-Charlaine-Harris.pdf
    • http://seasasac.lflinkup.com/1da4da3da3da5da7/Rebecca-and-Ana-American-Girls-Rebecca-2-by-Jacqueline-Dembar-Greene.pdf
    • http://seasasac.lflinkup.com/2da5da1da3da1da5/Whatever-You-Want-We-Write-You-Decide-A-Pick-Your-Own-Ending-Escapade-by-Rachel-Timms.pdf
    • http://seasasac.lflinkup.com/2da6da3da6da2da8/A-Bone-to-Pick-Aurora-Teagarden-Mystery-2-by-Charlaine-Harris.pdf
    • http://seasasac.lflinkup.com/1da0da1da6da7da0da9/Faces-of-Degeneration-A-European-Disorder-1848-1918-by-Daniel-Pick.pdf
    • http://seasasac.lflinkup.com/7da4da3da7da9da2/Irrationally-yours-On-Missing-Socks-Pick-up-Lines-and-Other-Existential-Puzzles-by-Dan-Ariely.pdf
    • http://seasasac.lflinkup.com/1da0da9da9da4da3da1/The-Official-Parent-s-Sourcebook-on-Niemann-Pick-Disease-by-Philip-M-Parker.pdf
    • http://seasasac.lflinkup.com/2da5da0da7da2da5/The-Last-Pick-The-Boston-Marathon-Race-Director-s-Road-to-Success-by-David-J-McGillivray.pdf
    • http://seasasac.lflinkup.com/5da7da8da1da9da6/Pick-Another-Checkout-Lane-Honey-Save-BIG-Money-amp-Make-the-Grocery-Aisle-Your-Catwalk-by-Joanie-Demer.pdf
    • http://seasasac.lflinkup.com/5da7da8da2da0da3/Pick-Another-Checkout-Lane-Honey-Learn-Coupon-Strategies-to-Save-1000s-at-the-Grocery-Store-by-Joanie-Demer.pdf