Malicious PDF — malware analysis report

Static analysis result for SHA-256 4a791f95e8b51dd7…

MALICIOUS

PDF

19.9 KB Created: 2019-05-02 01:22:52 +01:00 Authoring application: mPDF 5.7
MD5: fa22f66247be521b20245723f8b1a924 SHA-1: 152235efbc466a3b03631590b12f1300eed89c3c SHA-256: 4a791f95e8b51dd7a5726b58fdf24bcf76efc40baf267dd2ab41fabd5b4e152e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded links. The heuristic 'PDF_SEO_LINK_FARM' indicates that these links likely form a link farm, a common technique for SEO poisoning or directing users to malicious sites. While the specific intent of the links is unclear, the sheer volume and the ML classification suggest a malicious purpose, possibly leading to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/4da6da9da0da6da1/Marie-Antoinette-The-Journey-by-Antonia-Fraser.pdf
    • http://seasasac.lflinkup.com/4da0da3da5da7da2/Cromwell-by-Antonia-Fraser.pdf
    • http://seasasac.lflinkup.com/5da2da7da6da4da8/Maria-Antonieta-by-Antonia-Fraser.pdf
    • http://seasasac.lflinkup.com/2da1da7da9da8da1/Must-You-Go-My-Life-with-Harold-Pinter-by-Antonia-Fraser.pdf
    • http://seasasac.lflinkup.com/1da7da2da9da4da8/The-Wives-of-Henry-VIII-by-Antonia-Fraser.pdf
    • http://seasasac.lflinkup.com/1da5da9da0da1da2/Must-You-Go-My-Life-with-Harold-Pinter-by-Antonia-Fraser.pdf
    • http://seasasac.lflinkup.com/5da3da6da6da2/Kings-and-Queens-of-England-by-Antonia-Fraser.pdf
    • http://seasasac.lflinkup.com/2da5da2da5da1da6/Faith-and-Treason-The-Story-of-the-Gunpowder-Plot-by-Antonia-Fraser.pdf
    • http://seasasac.lflinkup.com/2da7da9da2da4da8/The-King-and-the-Catholics-The-Fight-for-Religious-Liberty-in-Georgian-England-by-Antonia-Fraser.pdf
    • http://seasasac.lflinkup.com/4da2da5da8da6da5/Marie-Th-r-se-Child-of-Terror-The-Fate-of-Marie-Antoinette-s-Daughter-by-Susan-Nagel.pdf
    • http://seasasac.lflinkup.com/7da7da7da4da1da9/The-Private-Realm-of-Marie-Antoinette-by-Marie-France-Boyer.pdf
    • http://seasasac.lflinkup.com/2da9da8da2da8da8/The-Pleasure-of-Reading-43-Writers-on-the-Discovery-of-Reading-and-the-Books-that-Inspired-Them-by-Antonia-Fraser.pdf
    • http://seasasac.lflinkup.com/4da8da6da8da4/Marie-Antoinette-by-Hilaire-Belloc.pdf
    • http://seasasac.lflinkup.com/5da6da2da3da0da7/Marie-Antoinette-The-Last-Queen-of-France-by-velyne-Lever.pdf
    • http://seasasac.lflinkup.com/4da6da0da8da7da5/Marie-Antoinette-s-Head-The-Royal-Hairdresser-the-Queen-and-the-Revolution-by-Will-Bashor.pdf
    • http://seasasac.lflinkup.com/1da0da7da7da5da0da4/A-Favor-for-Marie-Antoinette-1789-The-Revolution-Begins-by-Lindy-Vinke.pdf
    • http://seasasac.lflinkup.com/1da1da3da0da6da0/How-to-Ruin-a-Queen-Marie-Antoinette-and-the-Diamond-Necklace-Affair-by-Jonathan-Beckman.pdf
    • http://seasasac.lflinkup.com/3da7da0da7da5da3/Army-Letters-from-an-Officer-s-Wife-1871-1888-by-Frances-Marie-Antoinette-Mack-Roe.pdf
    • http://seasasac.lflinkup.com/5da7da2da9da2da2/Madame-Royale-daughter-of-Louis-XVI-and-Marie-Antoinette-her-youth-and-marriage-by-Ernest-Daudet.pdf
    • http://seasasac.lflinkup.com/6da4da6da5da9da3/The-Road-from-Versailles-Louis-XVI-Marie-Antoinette-and-the-Fall-of-the-French-Monarchy-by-Munro-Price.pdf
    • http://seasasac.lflinkup.com/4da2da5da8da6da5/Marie-Th-r-se-Chil