Malicious PDF — malware analysis report

Static analysis result for SHA-256 33e998a23fc93f66…

MALICIOUS

PDF

19.9 KB Created: 2019-04-30 05:02:19 +01:00 Authoring application: mPDF 5.7
MD5: d04188958451b0a84f26ff16218eb286 SHA-1: 64c68634ddaa5a11ab29ed15c5c4fcd40c396e8a SHA-256: 33e998a23fc93f6605b80e4f4040f7de842cd4572b1446505e77901c8a75ae71
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. The ML classifier strongly indicated maliciousness, and the heuristic firing confirms the presence of a link farm. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the exact payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/7da7da9da7da4/The-Imam-s-Daughter-by-Hannah-Shah.pdf
    • http://seasasac.lflinkup.com/1da1da4da8da7da3/The-Twelfth-Imam-The-Twelfth-Imam-1-by-Joel-C-Rosenberg.pdf
    • http://seasasac.lflinkup.com/7da0da0da2da3da0/Shah-Commission-Report-Lost-And-Regained-by-Justice-Jayantilal-Chhotalal-Shah.pdf
    • http://seasasac.lflinkup.com/1da2da8da9da4da4/Hannah-Waters-And-The-Daughter-Of-Johann-Sebastian-Bach-by-Barbara-Kathleen-Nickel.pdf
    • http://seasasac.lflinkup.com/9da1da0da4da2/The-Teaching-Story-The-Dermis-Probe-and-Evenings-with-Idries-Shah-by-Idries-Shah.pdf
    • http://seasasac.lflinkup.com/4da0da0da9da0da2/An-Uncommon-Woman---The-Empress-Frederick-Daughter-of-Queen-Victoria-Wife-of-the-Crown-Prince-of-Prussia-Mother-of-Kaiser-Wilhelm-by-Hannah-Pakula.pdf
    • http://seasasac.lflinkup.com/1da1da0da7da5da1da3/The-Demise-of-Imam-Faustus-by-Matthew-Wilkinson.pdf
    • http://seasasac.lflinkup.com/4da7da8da3da4da4/Imam-Ghazzali-and-the-robbers-of-khorasan-Meet-the-luminaries-1-by-Hasim-Nabeel.pdf
    • http://seasasac.lflinkup.com/5da8da3da4da2da0/de-L-Emir-Abdelkader-A-L-Imam-Chamyl-Le-Heros-Des-Tchetchenes-Et-Du-Caucase-by-Boualem-Bessaih.pdf
    • http://seasasac.lflinkup.com/6da8da1da8da9/Hinds-Feet-on-High-Places-Complete-and-Unabridged-by-Hannah-Hurnard-by-Hannah-Hurnard.pdf
    • http://seasasac.lflinkup.com/1da0da4da2da3da4da6/Between-Friends-The-Correspondence-of-Hannah-Arendt-and-Mary-McCarthy-1949-1975-by-Hannah-Arendt.pdf
    • http://seasasac.lflinkup.com/1da1da5da0da6da9/Eye-Spy-by-Tahir-Shah.pdf
    • http://seasasac.lflinkup.com/9da0da8da1da3da0/Collages-Hannah-Hoch-1889-1978-by-Hannah-H-ch.pdf
    • http://seasasac.lflinkup.com/3da8da1da2da2/The-Sufis-by-Idries-Shah.pdf
    • http://seasasac.lflinkup.com/8da0da7da8da7/Travels-With-Myself-by-Tahir-Shah.pdf
    • http://seasasac.lflinkup.com/1da1da9da6da6da2da2/The-Organ-s-Speech-by-U-F-Shah.pdf
    • http://seasasac.lflinkup.com/7da4da1da1/Daughter-of-the-Siren-Queen-Daughter-of-the-Pirate-King-2-by-Tricia-Levenseller.pdf
    • http://seasasac.lflinkup.com/1da4da7da6da4da1/Who-Killed-My-Daughter-The-True-Story-of-a-Mother-s-Search-for-Her-Daughter-s-Murderer-by-Lois-Duncan.pdf
    • http://seasasac.lflinkup.com/3da2da0da3da5da3/Read-Bottom-Up-by-Neel-Shah.pdf
    • http://seasasac.lflinkup.com/5da0da7da1da2da2/The-King-in-Exile-by-Sudha-Shah.pdf