Malicious PDF — malware analysis report

Static analysis result for SHA-256 10e65fd310269c1b…

MALICIOUS

PDF

17.4 KB Created: 2019-05-01 18:31:39 +01:00 Authoring application: mPDF 5.7
MD5: deeaf2a13f7d26a2c212f2fb624c6a0c SHA-1: 78742b54d7062a71dc6869d1a58023479ea885c1 SHA-256: 10e65fd310269c1b9aa400d29288b80c9fecb05c61554922db8ed28beea8e454
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently classified as benign, the sheer volume and the heuristic firing of PDF_SEO_LINK_FARM suggest a malicious intent, possibly to manipulate search engine results or to host further malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/8da4da6da3da2da6/The-Bark-Cutters-Gordon-1-by-Nicole-Alexander.pdf
    • http://seasasac.lflinkup.com/4da3da9da3da3/Solitary-Escape-from-Furnace-2-by-Alexander-Gordon-Smith.pdf
    • http://seasasac.lflinkup.com/1da1da6da0da5da3/Execution-Escape-from-Furnace-5-by-Alexander-Gordon-Smith.pdf
    • http://seasasac.lflinkup.com/2da4da3da7da3da1/Fugitives-Escape-from-Furnace-4-by-Alexander-Gordon-Smith.pdf
    • http://seasasac.lflinkup.com/2da4da3da7da7da3/Solitary-Escape-from-Furnace-2-by-Alexander-Gordon-Smith.pdf
    • http://seasasac.lflinkup.com/1da3da3da7da5da2/Lockdown-Escape-from-Furnace-1-by-Alexander-Gordon-Smith.pdf
    • http://seasasac.lflinkup.com/1da1da5da0da0da0/Death-Sentence-Escape-from-Furnace-3-by-Alexander-Gordon-Smith.pdf
    • http://seasasac.lflinkup.com/4da1da3da8da2da1/Cutters-Don-t-Cry-by-Christine-Dzidrums.pdf
    • http://seasasac.lflinkup.com/5da2da8da9da4da8/The-Peat-Cutters-by-Alphonse-de-Ch-teaubriant.pdf
    • http://seasasac.lflinkup.com/4da3da7da5da9da9/The-Inventors-The-Inventors-1-by-Alexander-Gordon-Smith.pdf
    • http://seasasac.lflinkup.com/1da1da1da3da2da0da6/Phineas-and-Ferb-Fanon---Angelina747-Characters-Characters-of-Miriam-Nicole-Gomez-Shapiro-an-Interview-with-Nicole-Emily-and-Sophie-Franziska-Gomez-Shapiro-Jacqueline-Leroy-Nicole-Gomez-Shapiro-Sahra-Graziano-Zwei-Kletten-Und-Ein-Schnabeltier-Com-by-Source-Wikia.pdf
    • http://seasasac.lflinkup.com/8da4da6da5da5da8/Bark-by-Ferris-Cook.pdf
    • http://seasasac.lflinkup.com/8da4da6da5da1da8/Bark-by-Darrell-Bain.pdf
    • http://seasasac.lflinkup.com/2da2da7da0da2da1/Bark-by-Lorrie-Moore.pdf
    • http://seasasac.lflinkup.com/5da6da7da3da6da4/Rise-of-the-Zelphire-Of-Bark-and-Sap-by-Karim-Friha.pdf
    • http://seasasac.lflinkup.com/8da4da6da4da0da9/Bark-Lost-Valkyries-MC-3-by-Esther-E-Schmidt.pdf
    • http://seasasac.lflinkup.com/8da4da0da7da6da2/Bark-Park-by-Karen-Gray-Ruelle.pdf
    • http://seasasac.lflinkup.com/1da0da9da6da2da1/The-Touch-of-Bark-the-Feel-of-Stone-by-R-I-Miller.pdf
    • http://seasasac.lflinkup.com/4da9da1da0da0da5/Jingle-Bell-Bark-by-Laurien-Berenson.pdf
    • http://seasasac.lflinkup.com/4da6da9da9da9da7/Central-Bark-at-Christmas-by-Jennifer-Conner.pdf