Malicious PDF — malware analysis report

Static analysis result for SHA-256 439cbda86e648125…

MALICIOUS

PDF

20.5 KB Created: 2019-04-30 04:07:40 +01:00 Authoring application: mPDF 5.7
MD5: a6f42c3dae2d569e574f769b9350c4aa SHA-1: e5b47ebe416ef8723e7fede7ae7b98110949404e SHA-256: 439cbda86e6481255073561f007b7ac6f13d697655353b2133863b92655ad913
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While most individual links are classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent to distribute or redirect users to potentially harmful content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicates maliciousness. No scripts were extracted from this sample, and the document body was heavily obfuscated, preventing a deeper analysis of the immediate user-facing content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/3da9da1da6da4da9/Anniversary-of-the-Veil-Epic-Fantasy-Series-Boxed-Set-3-Book-Bundle-Protector-Decision-Maker-Forever-Husband-by-Vanna-Smythe.pdf
    • http://seasasac.lflinkup.com/4da9da0da8da1da2/The-Husband-Maker-The-Husband-Maker-1-by-Karey-White.pdf
    • http://seasasac.lflinkup.com/3da6da8da3da7da7/The-Grower-s-Gift-Progeny-of-Time-1-by-Vanna-Smythe.pdf
    • http://seasasac.lflinkup.com/4da2da5da2da1da1/The-Odd-Thomas-Series-4-Book-Bundle-Odd-Thomas-Forever-Odd-Brother-Odd-Odd-Hours-Odd-Thomas-1-4-by-Dean-Koontz.pdf
    • http://seasasac.lflinkup.com/4da9da0da9da5da0/The-Match-Maker-The-Husband-Maker-2-by-Karey-White.pdf
    • http://seasasac.lflinkup.com/4da0da4da0da3da8/At-Water-s-Edge-An-Epic-Fantasy-The-Last-Elentrice-Book-1-by-S-McPherson.pdf
    • http://seasasac.lflinkup.com/1da0da9da3da2da3da2/Epic-Fantasy-Sword-of-the-Elves-The-Elven-Saga-Book-1-of-4-by-Emanuel-Fynn.pdf
    • http://seasasac.lflinkup.com/6da7da3da1da6da1/Confident-Decision-Maker-by-Roger-Dawson.pdf
    • http://seasasac.lflinkup.com/4da4da9da5da9da8/From-Husband-to-Futa-A-Gender-Swapping-Tale-of-Total-Submission-to-a-Billionaire-Domme-Futanari-Fantasy-Collection-Book-2-by-Beatrice-Evenmorne.pdf
    • http://seasasac.lflinkup.com/4da8da4da3da7da5/NOT-A-BOOK-Epic-of-the-Damned-The-Eclipse-Series---Book-One-by-NOT-A-BOOK.pdf
    • http://seasasac.lflinkup.com/3da5da8da4da0da4/kneel-the-action-series-Book-2-by-kaycee-veil.pdf
    • http://seasasac.lflinkup.com/1da8da7da9da4da2/Ascent-Of-Blood-The-Red-Veil-Series-Book-2-by-Elizabeth-Marx.pdf
    • http://seasasac.lflinkup.com/1da8da1da5da9da0/Descent-of-Blood-The-Red-Veil-Series-Book-1-by-Elizabeth-Marx.pdf
    • http://seasasac.lflinkup.com/2da9da3da7da1da7/Carrie-Me-Home-An-Epic-Comedy-Fantasy-Adventure-The-Carrie-Chronicles-Book-1-by-A-Holding.pdf
    • http://seasasac.lflinkup.com/4da0da9da4da8da2/The-Khan-Series-5-Book-Bundle-Conqueror-1-5-by-Conn-Iggulden.pdf
    • http://seasasac.lflinkup.com/4da0da8da3da8da9/The-Midnight-Breed-Series-9-Book-Bundle-by-Lara-Adrian.pdf
    • http://seasasac.lflinkup.com/9da6da1da1da4da0/The-FBI-Profiler-Series-6-Book-Bundle-Quincy-amp-Rainie-1-6-by-Lisa-Gardner.pdf
    • http://seasasac.lflinkup.com/1da5da6da8da9da3/Brother-Bewildered-Sequel-to-the-Smash-Epic-Fantasy-Brother-Bewitched-The-Shattered-Isles-Book-2-by-Taylor-Galen-Kadee.pdf
    • http://seasasac.lflinkup.com/2da4da9da8da7da4/Beyond-The-Veil-The-Veil-Series-1-by-Pippa-DaCosta.pdf
    • http://seasasac.lflinkup.com/4da8da2da8da2da3/Nether-After-The-Never-After-Dark-Fantasy-Series-Book-1-by-Jodi-Cox.pdf
    • http://seasasac.lflinkup.com/1da0da9da3