Malicious PDF — malware analysis report

Static analysis result for SHA-256 4d4c67a093cffd73…

MALICIOUS

PDF

18.9 KB Created: 2019-04-30 03:12:18 +01:00 Authoring application: mPDF 5.7
MD5: 5335417e9fc0fbb595f950fe35140ff1 SHA-1: 246b8213cd752f2247619d88d307eb12e908d52d SHA-256: 4d4c67a093cffd73cd48c1e573a1433546d03586b63c8a55883902b10090e1fe
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While most of the linked URLs are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO poisoning or to direct users to a compromised site. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9940

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/4da0da2da9da4/Reborn-Shadow-Falls-After-Dark-1-by-C-C-Hunter.pdf
    • http://seasasac.lflinkup.com/1da1da3da8da1/Unspoken-Shadow-Falls-After-Dark-3-by-C-C-Hunter.pdf
    • http://seasasac.lflinkup.com/4da7da9da9da6da9/Almost-Midnight-Shadow-Falls-After-Dark-3-5-by-C-C-Hunter.pdf
    • http://seasasac.lflinkup.com/1da9da4da8da5da0/Spellbinder-Shadow-Falls-After-Dark-2-5-by-C-C-Hunter.pdf
    • http://seasasac.lflinkup.com/4da3da7da8da1da1/Fighting-Back-Shadow-Falls-5-5-by-C-C-Hunter.pdf
    • http://seasasac.lflinkup.com/4da3da1da6da4da6/Awake-at-Dawn-Shadow-Falls-2-by-C-C-Hunter.pdf
    • http://seasasac.lflinkup.com/9da6da0da7da4da0/The-Shadow-Falls-Witch-Hunter-3-by-K-S-Marsden.pdf
    • http://seasasac.lflinkup.com/3da4da7da0da3/Chosen-at-Nightfall-Shadow-Falls-5-by-C-C-Hunter.pdf
    • http://seasasac.lflinkup.com/3da4da9da5da7/Dark-Side-of-the-Moon-Dark-Hunter-9-Were-Hunter-3-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/3da8da9da4da3/The-Guardian-Dark-Hunter-20-Dream-Hunter-5-Were-Hunter-6-Hellchaser-3-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/1da4da5da1da1da9/A-Dark-Hunter-Christmas-Dark-Hunter-3-6-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/4da0da5da3da5da9/The-Simi-s-ABCs-Adventures-with-Dark-Hunters-Dark-Hunter-30-Dark-Hunterverse-31-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/3da5da1da3da0/Bad-Moon-Rising-Dark-Hunter-17-Were-Hunter-4-Hellchaser-1-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/1da6da4da9da1da6/Bad-Moon-Rising-Dark-Hunter-18-Were-Hunter-4-Hellchaser-2-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/4da0da2da9da2da8/Bad-Moon-Rising-Dark-Hunter-14-Were-Hunter-6-Hellchaser-3-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/1da9da2da1da6da7/Upon-the-Midnight-Clear-Dark-Hunter-12-Dream-Hunter-2-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/3da3da5da2da1da4/Bad-Moon-Rising-Dark-Hunter-14-Were-Hunter-6-Hellchaser-3-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/3da4da1da7da7/Unleash-the-Night-Dark-Hunter-8-Were-Hunter-2-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/6da0da7da3da9/No-Mercy-Dark-Hunter-18-Were-Hunter-5-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/2da9da4da8da7da6/No-Mercy-Dark-Hunter-15-Were-Hunter-7-by-Sherrilyn-Kenyon.pdf
    • http://seasasac.lflinkup.com/1da4da5da1da1da9/A-Dark-Hunter-Christ