Malicious PDF — malware analysis report

Static analysis result for SHA-256 37f4d68adf1d4cd0…

MALICIOUS

PDF

23.1 KB Created: 2019-05-03 05:44:29 +01:00 Authoring application: mPDF 5.7
MD5: 6fb80f3e642aa443e6b2439cd9061d63 SHA-1: 943d389094b64632242f1d86af43b7c329e3adb6 SHA-256: 37f4d68adf1d4cd0648564e98489534ce935d9b1f8ff091f009724c73c1dcf0f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm. While no scripts were extracted, the sheer volume of links and the heuristic firings suggest a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/1da0da2da6da9da0/The-Curse-of-Cash-by-Kenneth-S-Rogoff.pdf
    • http://seasasac.lflinkup.com/1da0da0da7da9da0da7/Making-Money-from-Mobile-Phones-Cash-from-Cell-Phones-Apps-amp-Web-Services-by-Kenneth-Woolfolk.pdf
    • http://seasasac.lflinkup.com/5da1da3da4da9da2/The-Cultural-Nature-of-Human-Development-by-Barbara-Rogoff.pdf
    • http://seasasac.lflinkup.com/1da2da9da9da2da7/Curse-of-the-Wolf-Veela-Curse-Series-1-by-Danica-Winters.pdf
    • http://seasasac.lflinkup.com/4da1da1da1da6da3/The-Curse-Breakers-The-Curse-Keepers-2-by-Denise-Grover-Swank.pdf
    • http://seasasac.lflinkup.com/1da7da3da6da0da0/The-Curse-Defiers-The-Curse-Keepers-3-by-Denise-Grover-Swank.pdf
    • http://seasasac.lflinkup.com/9da8da0da9da9da7/The-Tech-Entrepreneur-s-Survival-Guide-How-to-Bootstrap-Your-Startup-Lead-Through-Tough-Times-and-Cash-In-for-Success-How-to-Bootstrap-Your-Startup-Through-Tough-Times-and-Cash-In-for-Success-by-Bernd-Schoner.pdf
    • http://seasasac.lflinkup.com/9da2da3da1da8/A-Gypsy-Curse-2-Ending-the-Curse-by-Julie-Gamble.pdf
    • http://seasasac.lflinkup.com/1da3da0da1da7da6/Gifted-Curse-Curse-Trilogy-1-by-C-M-Owens.pdf
    • http://seasasac.lflinkup.com/9da8da0da9da4da5/The-Tech-Entrepreneur-s-Survival-Guide-How-to-Bootstrap-Your-Startup-Lead-Through-Tough-Times-and-Cash-in-for-Success-How-to-Bootstrap-Your-Startup-Lead-Through-Tough-Times-and-Cash-in-for-Success-by-Bernd-Schoner.pdf
    • http://seasasac.lflinkup.com/2da0da7da8da5da7/Curse-of-the-Alpha-The-Complete-Bundle-Curse-of-the-Alpha-serial-1-6-by-Tasha-Black.pdf
    • http://seasasac.lflinkup.com/2da5da8da5da3da1/The-Starr-Report-The-Findings-Of-Independent-Counsel-Kenneth-Starr-On-President-Clinton-And-The-Lewinsky-Affair-by-Kenneth-W-Starr.pdf
    • http://seasasac.lflinkup.com/3da1da4da6da7da1/The-Assassin-s-Curse-The-Assassin-s-Curse-1-by-Cassandra-Rose-Clarke.pdf
    • http://seasasac.lflinkup.com/2da1da3da6da8da4/The-Assassin-s-Curse-The-Assassin-s-Curse-1-by-Cassandra-Rose-Clarke.pdf
    • http://seasasac.lflinkup.com/1da2da5da8da2da2/Old-Custer-by-Eli-Cash.pdf
    • http://seasasac.lflinkup.com/6da2da4da9da3da3/Kenneth-Oppel-Airborn-Series-Three-Book-Bundle-Airborn-Skybreaker-and-Starclimber-by-Kenneth-Oppel.pdf
    • http://seasasac.lflinkup.com/1da3da7da0da6da4/The-Mind-of-the-South-by-W-J-Cash.pdf
    • http://seasasac.lflinkup.com/1da4da6da1da0da1/Worst-Kept-Secret-by-Sienna-Cash.pdf
    • http://seasasac.lflinkup.com/4da9da2da3da2da2/Pray-for-Death-by-Cash-Pawley.pdf
    • http://seasasac.lflinkup.com/1da6da1da9da1da6/Composed-A-Memoir-by-Rosanne-Cash.pdf
    • http://seasasac.lflinkup.com/9da8da0da9da9da7/The-Tech-Entrepreneur-s-Survival-Guide-How-to-Bootstrap-Your-Startup-Lead-Through-Tough-Times-and-Cash-In-for-Success-How-to-Bootstrap-Your-Startup-Through-Tough-Tim