Malicious PDF — malware analysis report

Static analysis result for SHA-256 22554a2b1ec1f344…

MALICIOUS

PDF

20.4 KB Created: 2019-05-01 09:27:36 +01:00 Authoring application: mPDF 5.7
MD5: fdcbe0578ad27be7f882d61914716e4c SHA-1: 62739ff55e71711705e6cd47192e5f54d5d67460 SHA-256: 22554a2b1ec1f34448d9486fa27bfa4b303bd3f890b0852b0cec4262d86d84aa
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDFs, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the PDF structure and embedded URLs suggest a lure to a potentially malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/1da0da7da7da9da4da0/Norse-Myths-amp-Legends-World-Book-Myths-amp-Legends-Series-by-Philip-Ardagh.pdf
    • http://seasasac.lflinkup.com/1da0da7da7da9da4da2/Ancient-Egyptian-Myths-amp-Legends-World-Book-Myths-amp-Legends-Series-by-Philip-Ardagh.pdf
    • http://seasasac.lflinkup.com/1da0da7da7da9da8da3/South-American-Myths-amp-Legends-World-Book-Myths-amp-Legends-Series-by-Philip-Ardagh.pdf
    • http://seasasac.lflinkup.com/3da2da1da3da1da8/Myths-amp-Legends-An-Illustrated-Guide-to-Their-Origins-and-Meanings-by-Philip-Wilkinson.pdf
    • http://seasasac.lflinkup.com/3da1da3da7da8da8/The-Virago-Book-of-Erotic-Myths-and-Legends-by-Shahrukh-Husain.pdf
    • http://seasasac.lflinkup.com/3da0da5da4da3/Where-Did-the-Sun-Go-Myths-and-Legends-of-Solar-Eclipses-Around-the-World-Told-with-Poetry-and-Puppetry-by-Janet-Cameron-Hoult.pdf
    • http://seasasac.lflinkup.com/3da8da9da2da2da6/Egyptian-Myths-and-Legends-by-Donald-A-Mackenzie.pdf
    • http://seasasac.lflinkup.com/3da1da9da8da6da4/Myths-and-Legends-of-Japan-by-F-Hadland-Davis.pdf
    • http://seasasac.lflinkup.com/5da0da2da4da6da2/Myths-and-Legends-of-Ancient-Egypt-by-Joyce-A-Tyldesley.pdf
    • http://seasasac.lflinkup.com/3da0da2da6da6da1/Mermaids-The-Myths-Legends-and-Lore-by-Skye-Alexander.pdf
    • http://seasasac.lflinkup.com/3da9da4da7da1da9/The-E-T-Chronicles-What-Myths-and-Legends-Tell-Us-about-Human-Origins-by-Rita-Louise.pdf
    • http://seasasac.lflinkup.com/1da0da3da5da0da0/Legends-Lies-Cherished-Myths-of-American-History-by-Richard-Shenkman.pdf
    • http://seasasac.lflinkup.com/4da3da6da7da9da8/Word-Myths-Debunking-Linguistic-Urban-Legends-by-David-Wilton.pdf
    • http://seasasac.lflinkup.com/3da9da2da2da2da9/The-Egyptian-Myths-A-Guide-to-the-Ancient-Gods-and-Legends-by-Garry-J-Shaw.pdf
    • http://seasasac.lflinkup.com/2da2da1da7da5da2/Grimm-Fairy-Tales-Myths-amp-Legends-Volume-5-by-Raven-Gregory.pdf
    • http://seasasac.lflinkup.com/1da0da3da5da0da8da3/Lemmings-Don-t-Leap-180-Myths-Misconceptions-and-Urban-Legends-Exploded-by-Edwin-Moore.pdf
    • http://seasasac.lflinkup.com/6da3da3da2da4da8/Rock-n-Roll-Myths-The-True-Stories-Behind-the-Most-Infamous-Legends-by-Gary-Graff.pdf
    • http://seasasac.lflinkup.com/1da9da4da1da2da6/The-Norse-Myths-by-Kevin-Crossley-Holland.pdf
    • http://seasasac.lflinkup.com/3da2da1da5da7da5/Gods-of-Asgard-A-Graphic-Novel-Interpretation-of-the-Norse-Myths-by-Erik-Evensen.pdf
    • http://seasasac.lflinkup.com/1da2da9da7da1da3/Song-of-the-Vikings-Snorri-and-the-Making-of-Norse-Myths-by-Nancy-Marie-Brown.pdf
    • http://seasasac.lflinkup.com/3da0da5da4da3/Where-Did-the-Sun-Go-Myths-and-Legends-of-Solar-Eclipses-Around-th