Malicious PDF — malware analysis report

Static analysis result for SHA-256 2e294ca216a8a919…

MALICIOUS

PDF

19.2 KB Created: 2019-05-02 01:28:54 +01:00 Authoring application: mPDF 5.7
MD5: 1d05cac5f722daf65df4a28751071215 SHA-1: 17536d1326fc629d7d7f6e73feab0220ca9cb7d1 SHA-256: 2e294ca216a8a919110439100cff8486a888d8f7e3bfdf50448658b7e7c94140
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. While the specific URLs extracted appear benign, the sheer volume and the heuristic's name suggest a malicious intent, possibly for SEO spam or to redirect users to malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicates maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/8da9da1da5da7da0/Simple-Fortunetelling-with-Tarot-Cards-Corrine-Kenner-s-Complete-Guide-by-Corrine-Kenner.pdf
    • http://seasasac.lflinkup.com/8da9da1da5da2da4/Tarot-for-Writers-by-Corrine-Kenner.pdf
    • http://seasasac.lflinkup.com/8da9da1da5da6da9/Astrology-for-Writers-Spark-Your-Creativity-Using-the-Zodiac-by-Corrine-Kenner.pdf
    • http://seasasac.lflinkup.com/8da9da1da5da7da7/Tall-Dark-Stranger-Tarot-for-Love-amp-Romance-by-Corrine-Kenner.pdf
    • http://seasasac.lflinkup.com/8da9da1da5da3da0/Tarot-Journaling-Using-the-Celtic-Cross-to-Unveil-Your-Hidden-Story-by-Corrine-Kenner.pdf
    • http://seasasac.lflinkup.com/2da2da7da7da9da2/Strange-but-True-by-John-Searles.pdf
    • http://seasasac.lflinkup.com/1da0da5da7da4da7da9/the-Strange-Loyalist-----Inspired-by-True-Events-by-Mian-Mohsin-Zia.pdf
    • http://seasasac.lflinkup.com/2da2da7da8da2/Strange-But-True-America-Weird-Tales-from-All-50-States-by-John-Hafnor.pdf
    • http://seasasac.lflinkup.com/1da0da4da1da9da2/Selkirk-s-Island-The-True-and-Strange-Adventures-of-the-Real-Robinson-Crusoe-by-Diana-Souhami.pdf
    • http://seasasac.lflinkup.com/6da1da3da9da9da1/Marooned-The-Strange-but-True-Adventures-of-Alexander-Selkirk-the-Real-Robinson-Crusoe-by-Robert-Kraske.pdf
    • http://seasasac.lflinkup.com/1da0da0da4da0da0/The-Great-Shark-Hunt-Strange-Tales-from-a-Strange-Time-The-Gonzo-Papers-1-by-Hunter-S-Thompson.pdf
    • http://seasasac.lflinkup.com/2da1da9da6da2da1/Strange-Lies-Strange-Truth-2-by-Maggie-Thrash.pdf
    • http://seasasac.lflinkup.com/1da1da1da9da4da3da1/Mallory-of-Strange-Valley-Adult-Paranormal-Romance-Novelette-Strange-Valley-Immortals-1-by-Kassandra-Coley.pdf
    • http://seasasac.lflinkup.com/8da9da1da6da3da0/Bible-and-the-Tarot-by-Corrine-Heline.pdf
    • http://seasasac.lflinkup.com/8da9da1da5da7da2/The-bread-knife-ni-Corrine-by-MeanieG.pdf
    • http://seasasac.lflinkup.com/8da9da1da8da0da1/Way-To-Go-Jesus-Answered-I-Am-The-Way-by-Corrine-Vanderwerff.pdf
    • http://seasasac.lflinkup.com/8da9da1da7da9da0/When-I-m-In-His-Presence-by-Anita-Corrine-Donihue.pdf
    • http://seasasac.lflinkup.com/8da9da1da8da4da1/Corrine-or-Italy-by-Germaine-de-Sta-l.pdf
    • http://seasasac.lflinkup.com/8da9da1da7da9da5/Passionate-Latitudes-by-Corrine-Bryant.pdf
    • http://seasasac.lflinkup.com/8da9da1da8da5da4/Mae-Jemison-Out-of-This-World-by-Corrine-J-Naden.pdf
    • http://seasasac.lflinkup.com/1da0d