Malicious PDF — malware analysis report

Static analysis result for SHA-256 583c045d3b6e92ec…

MALICIOUS

PDF

20.5 KB Created: 2019-05-01 19:23:55 +01:00 Authoring application: mPDF 5.7
MD5: 155491b7ddb40f4e76ad18da603a5c6a SHA-1: 791868b58edd59870faa4d436775c1eeee9cd881 SHA-256: 583c045d3b6e92ec47d3ba14ee0fd7955275f962aec00efb8ae9b0d67a30dd67
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs were individually classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, likely for SEO manipulation or to redirect users to potentially harmful content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/2da1da4da2da7da1/Broadway-Nights-A-Romp-of-Life-Love-and-Musical-Theatre-by-Seth-Rudetsky.pdf
    • http://seasasac.lflinkup.com/2da7da3da9da4da3/My-Awesome-Awful-Popularity-Plan-Justin-Goldblatt-1-by-Seth-Rudetsky.pdf
    • http://seasasac.lflinkup.com/1da9da5da3da7da1/The-Rise-and-Fall-of-a-Theater-Geek-Justin-Goldblatt-2-by-Seth-Rudetsky.pdf
    • http://seasasac.lflinkup.com/1da1da5da2da2da6da9/Hairspray-The-Complete-Book-and-Lyrics-of-the-Hit-Broadway-Musical-by-Mark-O-39-Donnell.pdf
    • http://seasasac.lflinkup.com/1da3da9da6da7da1/Rodgers-amp-Hammerstein-s-Carousel-The-Complete-Book-and-Lyrics-of-the-Broadway-Musical-by-Richard-Rodgers.pdf
    • http://seasasac.lflinkup.com/2da7da4da5da6da3/The-Tax-Protest-Love-Romp-in-London-when-complaining-REALLY-pays-off-The-St-Jane-Sisters-Book-1-by-Lisa-McKnight.pdf
    • http://seasasac.lflinkup.com/1da0da6da7da5da6da7/Ah-One-Ah-Two-Life-with-My-Musical-Family-by-Lawrence-Welk.pdf
    • http://seasasac.lflinkup.com/3da7da3da3da0da7/Life-Or-Theatre-by-Charlotte-Salomon.pdf
    • http://seasasac.lflinkup.com/9da1da8da1da2/Go-Go-Live-The-Musical-Life-and-Death-of-a-Chocolate-City-by-Natalie-Hopkinson.pdf
    • http://seasasac.lflinkup.com/7da5da9da6da9/Love-And-Sleepless-Nights-Love-2-by-Nick-Spalding.pdf
    • http://seasasac.lflinkup.com/3da9da3da6da7da4/Wooden-A-Coach-s-Life-by-Seth-Davis.pdf
    • http://seasasac.lflinkup.com/2da5da2da3da4da2/It-s-a-Good-Life-If-You-Don-t-Weaken-A-Picture-Novella-by-Seth.pdf
    • http://seasasac.lflinkup.com/4da5da4da7da0da8/Shopping-for-Porcupine-A-Life-in-Arctic-Alaska-by-Seth-Kantner.pdf
    • http://seasasac.lflinkup.com/2da0da2da0da4da4/Daring-Her-Love-The-Bradens-Novellas-Collection-The-Bradens-9-Love-in-Bloom-23-1001-Dark-Nights-30-by-Melissa-Foster.pdf
    • http://seasasac.lflinkup.com/4da2da4da9da7da4/Chasing-Cherries-The-Tease-A-Sexy-Romp-Series-2-by-Roxie-Elms.pdf
    • http://seasasac.lflinkup.com/4da3da3da9da0da3/Designed-for-Love-Texas-Nights-4-by-Kelsey-Browning.pdf
    • http://seasasac.lflinkup.com/4da4da3da2da6/Forbidden-Nights-with-a-Vampire-Love-at-Stake-7-by-Kerrelyn-Sparks.pdf
    • http://seasasac.lflinkup.com/9da3da7da4da8da0/As-You-Like-It-edited-with-a-life-of-Shakespeare-an-account-of-the-theatre-in-his-time-and-numerous-aids-to-the-study-of-the-play-by-William-Shakespeare.pdf
    • http://seasasac.lflinkup.com/2da0da2da0da5da9/Tempting-Tristan-Harborside-Nights-3-Love-in-Bloom-57-by-Melissa-Foster.pdf
    • http://seasasac.lflinkup.com/2da0da2da1da1da0/Embracing-Evan-Harborside-Nights-6-Love-in-Bloom-60-by-Melissa-Foster.pdf
    • http://seasasac.lflinkup.com/2da7da4da5da6da3/The-Tax-Protest-Love-Romp-in-London-when-