Malicious PDF — malware analysis report

Static analysis result for SHA-256 41c2efc8c9587eb4…

MALICIOUS

PDF

20.9 KB Created: 2019-05-07 05:59:18 +01:00 Authoring application: mPDF 5.7
MD5: 867a1348b1cd25825218b2ca91370a9f SHA-1: a0b42e83862c3ccbaccfab3a68975d5796e7362f SHA-256: 41c2efc8c9587eb4009a652d6f8efa61a0a90aa04cc7cb8d50bd552ead74c878
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links. The primary heuristic indicates a 'PDF_SEO_LINK_FARM', suggesting the document's purpose is to generate traffic or distribute content through a mass of links. While no scripts were extracted, the sheer volume of links and the ML classification strongly suggest a malicious intent, likely related to SEO manipulation or potentially leading to further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/4da6da5da3da9da7/Mother-s-Milk-by-Andrew-Breslin.pdf
    • http://seasasac.lflinkup.com/3da5da9da7da3/Mother-s-Milk-by-Edward-St-Aubyn.pdf
    • http://seasasac.lflinkup.com/1da9da4da6da9/An-Archive-of-Hope-Harvey-Milk-s-Speeches-and-Writings-by-Harvey-Milk.pdf
    • http://seasasac.lflinkup.com/3da3da8da4da8da8/A-Man-and-His-Mother-One-Man-s-Search-for-His-Biological-Mother-and-an-Understanding-of-His-Adoptive-Mother-by-Tim-Green.pdf
    • http://seasasac.lflinkup.com/1da5da0da1da4da5/Divided-City-by-Theresa-Breslin.pdf
    • http://seasasac.lflinkup.com/2da8da2da7da5da7/Me-amp-Gus-on-the-Roof-of-the-World-by-Danny-Breslin.pdf
    • http://seasasac.lflinkup.com/3da1da8da7da4/Spy-for-the-Queen-of-Scots-by-Theresa-Breslin.pdf
    • http://seasasac.lflinkup.com/3da1da6da8da3/Whispers-in-the-Graveyard-by-Theresa-Breslin.pdf
    • http://seasasac.lflinkup.com/4da3da6da0da6da9/Not-Exactly-What-I-Had-in-Mind-An-Incurable-Love-Story-by-Rosemary-Breslin.pdf
    • http://seasasac.lflinkup.com/8da5da6da7da3da2/The-Unfair-Advantage-Kinsella-Novels-by-Mike-Breslin.pdf
    • http://seasasac.lflinkup.com/3da0da5da9da1da8/Can-t-Anybody-Here-Play-This-Game-The-Improbable-Saga-of-the-New-York-Mets-First-Year-by-Jimmy-Breslin.pdf
    • http://seasasac.lflinkup.com/2da5da1da2da5da7/Confessions-of-a-Cereal-Mother-True-Stories-to-Let-Every-Mother-Know-She-s-Not-Alone-in-the-Craziness-by-Rachel-McClellan.pdf
    • http://seasasac.lflinkup.com/2da9da6da3da7da7/My-Mother-s-Keeper-a-Daughter-s-Candid-portrait-of-Her-famous-Mother-by-B-D-Hyman.pdf
    • http://seasasac.lflinkup.com/1da3da0da7da2da8/Whatever-Mother-Says-A-True-Story-of-a-Mother-Madness-and-Murder-by-Wensley-Clarkson.pdf
    • http://seasasac.lflinkup.com/5da2da5da2da4/Me-and-My-Mate-Jeffrey-A-story-of-big-dreams-tough-realities-and-facing-my-demons-head-on-by-Niall-Breslin.pdf
    • http://seasasac.lflinkup.com/6da2da9da0da2da2/The-Mother-To-Mother-Postpartum-Depression-Support-Book-Real-Stories-from-Women-Who-Lived-Through-It-and-Recovered-by-Sandra-Poulin.pdf
    • http://seasasac.lflinkup.com/2da7da7da3da1da1/Mother-s-Heart-Mother-Earth-3-by-Alan-Tucker.pdf
    • http://seasasac.lflinkup.com/2da1da2da4da9da4/Mother-s-Heart-Mother-Earth-3-by-Alan-Tucker.pdf
    • http://seasasac.lflinkup.com/2da7da1da4da8da0/Mother-Mother-by-Koren-Zailckas.pdf
    • http://seasasac.lflinkup.com/1da0da1da1da4da6/Mother-to-Mother-by-Sindiwe-Magona.pdf
    • http://seasasac.lflinkup.com/4da3da6da0da6da9/Not-Exac