Malicious PDF — malware analysis report

Static analysis result for SHA-256 4f2ca3073359dd00…

MALICIOUS

PDF

20.3 KB Created: 2019-05-07 03:13:30 +01:00 Authoring application: mPDF 5.7
MD5: 76a4caf127b2bc390139b67216a07cfa SHA-1: cb402cb229e3cb4f72b4e5ad8e3549cc36a8a3f8 SHA-256: 4f2ca3073359dd00b5df73bfe6420e97d3fd2ae0a25b5ef68ccc8d2af58862fa
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier and contains a large number of embedded external links, indicative of a link farm or a distribution mechanism for further malicious content. While the document body is unreadable, the heuristic 'PDF_SEO_LINK_FARM' strongly suggests the intent is to manipulate search engine results or redirect users to potentially harmful sites. The presence of numerous benign-labeled URLs does not negate the suspicious nature of the link farm itself.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/4da9da5da4da3da8/The-Arabian-Nights-Tales-of-1001-Nights-Volume-2-by-Anonymous.pdf
    • http://seasasac.lflinkup.com/1da0da8da9da4da8da4/The-Arabian-Nights-Tales-from-a-Thousand-and-One-Nights-by-Anonymous.pdf
    • http://seasasac.lflinkup.com/1da8da7da4da4da2/The-Arabian-Nights-Tales-from-a-Thousand-and-One-Nights-by-Anonymous.pdf
    • http://seasasac.lflinkup.com/1da8da1da4da4da6/The-Arabian-Nights-by-Anonymous.pdf
    • http://seasasac.lflinkup.com/4da3da9da6da8da4/The-Arabian-Nights-by-Anonymous.pdf
    • http://seasasac.lflinkup.com/9da8da4da2da8da2/The-Arabian-Nights-Entertainment-by-Anonymous.pdf
    • http://seasasac.lflinkup.com/9da0da4da8da7da4/Tales-from-The-Arabian-Nights-by-Anonymous.pdf
    • http://seasasac.lflinkup.com/1da5da9da6da2da8/The-Arabian-Nights-Entertainments-by-Anonymous.pdf
    • http://seasasac.lflinkup.com/4da0da3da2da2da2/Aladdin-and-Other-Tales-from-the-Arabian-Nights-by-Anonymous.pdf
    • http://seasasac.lflinkup.com/4da6da3da2da9da5/The-Tale-of-Ali-Baba-and-the-Forty-Thieves-A-Story-from-the-Arabian-Nights-by-Anonymous.pdf
    • http://seasasac.lflinkup.com/4da3da9da4da4da3/1001-Arabian-Nights---The-Complete-Adventures-of-Sindbad-Aladdin-and-Ali-Baba---Special-Edition-by-Anonymous.pdf
    • http://seasasac.lflinkup.com/8da0da7da7da8da8/The-Arabian-nights-entertainments-carefully-revised-and-occaisionally-corrected-from-the-Arabic-To-which-is-added-a-selection-of-new-tales-now-first-translated-from-the-Arabic-originals-Also-an-introduction-and-notes-illustrative-of-the-religion-m-by-Anonymous.pdf
    • http://seasasac.lflinkup.com/1da6da9da0da8da8/Arabian-Nights-and-Days-by-Naguib-Mahfouz.pdf
    • http://seasasac.lflinkup.com/1da0da2da5da0da1/New-Arabian-Nights-by-Robert-Louis-Stevenson.pdf
    • http://seasasac.lflinkup.com/5da7da3da1da1da8/The-Arabian-Nights-Sixteen-Stories-from-Sheherazade-by-Neil-Philip.pdf
    • http://seasasac.lflinkup.com/2da1da0da6da7da0/The-Storyteller-s-Daughter-A-Retelling-of-The-Arabian-Nights-by-Cameron-Dokey.pdf
    • http://seasasac.lflinkup.com/2da0da3da1da8da2/Prince-of-the-Desert-Sheikh-s-Arabian-Nights-4-by-Penny-Jordan.pdf
    • http://seasasac.lflinkup.com/8da2da7da8da0da3/The-Thousand-and-One-Nights-Arabian-Legendary-Tales-by-Sultana-Scheherazade.pdf
    • http://seasasac.lflinkup.com/2da3da1da2da5da6/1001-Arabian-Nights-The-Adventures-of-Sinbad-Vol-1-Eyes-of-Fire-by-Dan-Wickline.pdf
    • http://seasasac.lflinkup.com/8da2da7da7da9da8/Scheherazade-s-Children-Global-Encounters-with-the-Arabian-Nights-by-Philip-F-Kennedy.pdf
    • http://seasasac.lflinkup.com/4da6da3da2da9da5/The-Tale-of-Ali-Baba-and-the-Forty-Thieves-A-Story-from-the-Arabian-Nights-by-Anonymous.pd