Malicious PDF — malware analysis report

Static analysis result for SHA-256 441648604c192195…

MALICIOUS

PDF

24.6 KB Created: 2019-04-30 02:23:13 +01:00 Authoring application: mPDF 5.7
MD5: 04a64ea227ae8ef32124c6552532dcc7 SHA-1: 0faf2ab6813143c769716f10d7ee4ab1a610b450 SHA-256: 441648604c192195b572ab9ba876490c1c6cccddc2db88e2131466a64113b76b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While the document body is unreadable, the presence of numerous links suggests a tactic to drive traffic or distribute further content. The ML_NYX_PDF_MALICIOUS heuristic also flags the document as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/4da8da2da8da2da3/Nether-After-The-Never-After-Dark-Fantasy-Series-Book-1-by-Jodi-Cox.pdf
    • http://seasasac.lflinkup.com/2da1da9da4da7da2/Nether-After-by-Jodi-L-Cox.pdf
    • http://seasasac.lflinkup.com/3da7da8da7da6da6/Dark-Path-Dark-Tales-Series-Book-8-by-Randall-L-Scott.pdf
    • http://seasasac.lflinkup.com/1da3da2da3da3da0/Dark-Digital-Sky-Dark-Pantheon-Series-Book-1-by-Carac-Allison.pdf
    • http://seasasac.lflinkup.com/4da3da5da9da6da6/Nether-Bound-Nether-1-by-Bonnie-Rae.pdf
    • http://seasasac.lflinkup.com/2da1da4da0da3da3/Escape-From-Samsara-A-Dark-Comedy-Fantasy-Adventure-Prophecy-Allocation-Book-1-by-Nicky-Blue.pdf
    • http://seasasac.lflinkup.com/5da0da5da8da0da1/Stronger-Than-Magic-An-Elemental-Fantasy-Series-House-of-Xannon-Book-1-by-Melinda-VanLone.pdf
    • http://seasasac.lflinkup.com/9da9da4da9da8da0/The-Sixth-Chalice-Busting-Ghosts-the-Jewish-Way-Book-1-of-The-Bar-Tahara-Series-Fantasy-thrillers-of-a-new-kind-by-Eran-Solomon.pdf
    • http://seasasac.lflinkup.com/1da2da5da0da9da8/Dark-Siege-The-Nightmare-Returns-Dark-Siege-Series-Book-2-by-Jason-McLeod.pdf
    • http://seasasac.lflinkup.com/3da9da1da6da4da9/Anniversary-of-the-Veil-Epic-Fantasy-Series-Boxed-Set-3-Book-Bundle-Protector-Decision-Maker-Forever-Husband-by-Vanna-Smythe.pdf
    • http://seasasac.lflinkup.com/3da2da3da3da5da2/Fantasy-Writers-Phrase-Book-Essential-Reference-for-All-Authors-of-Fantasy-Adventure-and-Medieval-Historical-Fiction-Writers-Phrase-Books-Book-4-by-Jackson-Dean-Chase.pdf
    • http://seasasac.lflinkup.com/4da6da8da4da1da6/J-D-Robb-4-Book-Series-Collection-Gift-Set-Indulgence-In-Death-Hardcover-Fantasy-In-Death-Kindred-In-Death-Promises-In-Death-In-Death-Series-by-J-D-Robb.pdf
    • http://seasasac.lflinkup.com/8da3da6da3da0da3/The-Getaway-What-Happens-in-Vegas-An-MFM-Vacation-Fantasy-The-Getaway-Series-Book-1-by-Sookie-Shepherd.pdf
    • http://seasasac.lflinkup.com/1da3da4da2da1da2/Bound-Dark-Horse-Series-Book-1-by-J-S-Scott.pdf
    • http://seasasac.lflinkup.com/2da9da5da6da1da6/Lili-s-First-Fantasy---a-U-Coeds-Novella-Can-She-Indulge-Her-Most-Intimate-Desire-The-U-Coeds-College-Erotica-Romance-Series-Book-1-by-Amie-Iser.pdf
    • http://seasasac.lflinkup.com/8da1da7da2da4da4/Dark-Billionaire-3-Stepbrother-Series-Book-2-by-Kristina-Royer.pdf
    • http://seasasac.lflinkup.com/8da8da2da9da7da3/Dark-Shattering-The-Ella-Reynolds-Series-Book-4-by-Liz-Schulte.pdf
    • http://seasasac.lflinkup.com/3da8da9da5da8da0/Dark-Minds-Class-5-Series-Book-3-by-Michelle-Diener.pdf
    • http://seasasac.lflinkup.com/1da1da0da8da0da1da6/Lorelei-and-Darin-Dark-Guardian-Series-Book-4-by-T-Walker.pdf
    • http://seasasac.lflinkup.com/5da0da5da4da9da1/Xoe-Meyers-Trilogy-Books-1-3-Xoe-Accidental-Ashes-and-Broken-Beasts-Xoe-Meyers-Young-Adult-Fantasy-Horror-Series-Book-0-by-Sara-C-Roethle.pdf
    • http://seasasac.lflinkup.com/5da0da