Malicious PDF — malware analysis report

Static analysis result for SHA-256 5afa778ab86a6b74…

MALICIOUS

PDF

20.9 KB Created: 2019-04-30 09:00:56 +01:00 Authoring application: mPDF 5.7
MD5: f3f07004573f0d0a0697f91ba38dee8b SHA-1: 3608fb5ca24381149ee556c1b5ad32bfd9be16ae SHA-256: 5afa778ab86a6b746b4044f1a470f9968762b4c437ac90961a501e99ee05a591
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are labeled as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. The ML_NYX_PDF_MALICIOUS heuristic strongly supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/3da0da0da6da5da8/Bullseye-A-Billionaire-Stepbrother-With-Benefits-Romance-My-Stepbrother-s-Keeper-Book-3-by-Cynthia-Sharon.pdf
    • http://seasasac.lflinkup.com/3da0da0da5da7da0/QUARREL-A-Billionaire-Stepbrother-Romance-5-by-Cynthia-Sharon.pdf
    • http://seasasac.lflinkup.com/1da7da4da4da7da3/Seduced-by-Her-Stepbrother-The-Collection-Billionaire-Stepbrother-Romance-by-Taryn-James.pdf
    • http://seasasac.lflinkup.com/1da8da3da6da0da6/Stepbrother-With-Benefits-10-Stepbrother-with-Benefits---Second-Season-4-by-Mia-Clark.pdf
    • http://seasasac.lflinkup.com/1da8da3da6da1da6/Stepbrother-With-Benefits-14-Stepbrother-with-Benefits-Third-Season-2-by-Mia-Clark.pdf
    • http://seasasac.lflinkup.com/1da8da3da6da2da4/Stepbrother-With-Benefits-18-Stepbrother-with-Benefits-Third-Season-6-by-Mia-Clark.pdf
    • http://seasasac.lflinkup.com/1da8da3da6da0da3/Stepbrother-With-Benefits-7-Stepbrother-with-Benefits-Second-Season-1-by-Mia-Clark.pdf
    • http://seasasac.lflinkup.com/1da8da3da6da2da1/Stepbrother-With-Benefits-16-Stepbrother-with-Benefits-Third-Season-4-by-Mia-Clark.pdf
    • http://seasasac.lflinkup.com/1da8da3da6da0da9/Stepbrother-With-Benefits-11-Stepbrother-with-Benefits---Second-Season-5-by-Mia-Clark.pdf
    • http://seasasac.lflinkup.com/8da1da7da2da4da4/Dark-Billionaire-3-Stepbrother-Series-Book-2-by-Kristina-Royer.pdf
    • http://seasasac.lflinkup.com/1da7da7da6da2da3/Stepbrother-Bonding-Stepbrother-Bonding-Yearning-Exposed-Book-1-by-Kenzie-Haven.pdf
    • http://seasasac.lflinkup.com/3da4da7da1da9da6/His-Needs-Billionaire-Stepbrother-Alpha-1-by-Zoe-Reid.pdf
    • http://seasasac.lflinkup.com/1da8da3da4da9da5/Stepbrother-Billionaire-by-Colleen-Masters.pdf
    • http://seasasac.lflinkup.com/3da0da1da7da4da3/Stepbrother-Studs-Taboo-A-Z-Boxed-Set-Volume-2-Stepbrother-Studs-6-10-by-Selena-Kitt.pdf
    • http://seasasac.lflinkup.com/7da5da4da8da2da7/Billionaire-on-a-Boat-Stepbrother-Games-2-by-Cerise-Lush.pdf
    • http://seasasac.lflinkup.com/3da0da1da7da1da2/Surge-A-Stepbrother-Romance-by-Jenni-Smiles.pdf
    • http://seasasac.lflinkup.com/8da1da7da2da4da5/STEPBROTHER-ROMANCE-The-Complete-Collection-Boxed-Set-by-Kristina-Royer.pdf
    • http://seasasac.lflinkup.com/1da4da5da9da5da5/Stepbrother-Where-Art-Thou-Collection-Stepbrother-Where-Art-Thou-1-3-by-Aya-Fukunishi.pdf
    • http://seasasac.lflinkup.com/1da8da3da5da7da6/STEPBROTHER-A-Baby-Unexpected-Book-4-by-Ora-Wilde.pdf
    • http://seasasac.lflinkup.com/4da4da3da5da2da4/The-Billionaire-s-Temptation-Alpha-Billionaire-Romance-The-Billionaire-s-Touch-Book-1-by-L-N-Pearl.pdf