Malicious PDF — malware analysis report

Static analysis result for SHA-256 55e02f6b4320a582…

MALICIOUS

PDF

21.7 KB Created: 2019-05-07 04:13:40 +01:00 Authoring application: mPDF 5.7
MD5: cb013a54253dfdde882a5ba0448228aa SHA-1: d6e7e18abe52105b66e3242845786cc38cb1e58f SHA-256: 55e02f6b4320a5827ecd9aa5a1281a5e3aab08bbd32eeea9392254f644e53f3a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly flagged this PDF. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/7da7da2da9da6da6/The-Heart-of-Salvation-The-Life-and-Teachings-of-Saint-Theophian-the-Recluse-by-Theophan-the-Recluse.pdf
    • http://seasasac.lflinkup.com/6da1da6da3da0da4/The-Autobiography-of-Benjamin-Franklin-Complete-Prepared-for-Use-in-Schools-with-Introduction-Notes-and-a-Supplementary-Sketch-Concuding-the-Story-of-Franklin-s-Life-Presented-Mainly-in-His-Own-Words-by-Benjamin-Franklin.pdf
    • http://seasasac.lflinkup.com/1da0da1da6da7da3da6/Shakespeare-s-Insomnia-and-the-Causes-Thereof-by-Franklin-H-Franklin-Harvey-Head.pdf
    • http://seasasac.lflinkup.com/4da4da5da5da4da3/Randall-Jarrell-s-Book-of-Stories-by-Randall-Jarrell.pdf
    • http://seasasac.lflinkup.com/3da9da6da1da0da8/Franklin-Merrell-Wolffs-A-Personal-Record-of-Transformation-and-a-Discussion-of-Transcendental-Consciousness-Containing-His-by-Franklin-Merrell-Wolff.pdf
    • http://seasasac.lflinkup.com/6da1da5da5da0da4/Autobiography-Of-Benjamin-Franklin-And-The-Antigone-Color-Illustrated-Formatted-for-E-Readers-by-Benjamin-Franklin.pdf
    • http://seasasac.lflinkup.com/1da0da0da4da1da0da9/The-Autobiography-of-Benjamin-Franklin-starbooks-Classics-Editions-by-Benjamin-Franklin.pdf
    • http://seasasac.lflinkup.com/6da4da2da1da1da7/Autobiography-of-Benjamin-Franklin-with-an-introduction-by-Verner-W-by-Benjamin-Franklin.pdf
    • http://seasasac.lflinkup.com/7da7da2da9da0da2/Recluse-by-Lola-Allen.pdf
    • http://seasasac.lflinkup.com/7da7da2da9da3da6/Recluse-by-Kitty-Wakes.pdf
    • http://seasasac.lflinkup.com/7da7da2da7da8da2/The-Recluse-by-William-Wordsworth.pdf
    • http://seasasac.lflinkup.com/7da7da2da9da5da6/The-Recluse-by-Michael-Sutton.pdf
    • http://seasasac.lflinkup.com/7da7da2da9da5da5/The-Recluse-by-Editors-of-The-Atheneum.pdf
    • http://seasasac.lflinkup.com/6da2da9da8da3da5/Autobiography-of-Benjamin-Franklin-Illustrated-by-Benjamin-Franklin.pdf
    • http://seasasac.lflinkup.com/7da2da6da8da5da7/Memoirs-of-Benjamin-Franklin-Volume-02-by-Benjamin-Franklin.pdf
    • http://seasasac.lflinkup.com/7da7da2da8da9da3/Blinded-Recluse-Pemberley-3-by-Ayr-Bray.pdf
    • http://seasasac.lflinkup.com/7da7da2da9da6da8/The-Rapist-amp-The-Recluse-An-Anecdote-by-C-J-Sellers.pdf
    • http://seasasac.lflinkup.com/7da7da2da8da9da9/Thoughts-for-Each-Day-of-the-Year-by-Theophan-the-Recluse.pdf
    • http://seasasac.lflinkup.com/3da8da9da5da9da4/Beauty-and-the-Recluse-by-Ellie-Gray.pdf
    • http://seasasac.lflinkup.com/7da7da2da9da5da7/The-Recluse-by-Morgan-Jane-Mitchell.pdf
    • http://seasasac.lflinkup.com/3da9da6da1da0da8/Franklin-Merrell-Wolffs-A-Personal-Record-of-Transformation-and-a-Discussion-of-Transcendental-Consciousness-Containing-His-by-Franklin-Merrell-Wolff.pd