Malicious PDF — malware analysis report

Static analysis result for SHA-256 645cd2a13f7af7db…

MALICIOUS

PDF

19.5 KB Created: 2019-05-03 07:17:34 +01:00 Authoring application: mPDF 5.7
MD5: 4e20c4c04345b7f9f652dcb1c2fa0d9f SHA-1: 55131254448cdc204d0234cdada3b7e9c11c9eb7 SHA-256: 645cd2a13f7af7dbc9a52358e817e027120eadae3b0b915dd7bff35d25beec04
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the nature of the domain suggest a potential attempt to manipulate search engine results or to host malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/1da7da4da4da2da7/The-Alphabet-Game-Part-Two---F-to-K-The-Alpha-Series-1-2-by-Andie-M-Long.pdf
    • http://seasasac.lflinkup.com/4da4da8da2da5da3/Juice-An-Alpha-Male-Billionaire-Romance---Part-3-Juice-The-Series-by-Victoria-Starke.pdf
    • http://seasasac.lflinkup.com/1da0da3da8da4da6da1/AI-Game-Engine-Programming-Game-Development-Series-Charles-River-Media-Game-Development-by-Brian-Schwab.pdf
    • http://seasasac.lflinkup.com/5da6da4da5da6da5/Possessed---The-Complete-Series-Part-One-Part-Two-amp-Part-Three-Possessed-1-3-by-Coco-Cadence.pdf
    • http://seasasac.lflinkup.com/9da0da8da3da4/The-Lurid-Lady-Lockport-Alphabet-Series-4-by-Kasey-Michaels.pdf
    • http://seasasac.lflinkup.com/4da6da6da0da4/Fair-Game-Alpha-amp-Omega-3-by-Patricia-Briggs.pdf
    • http://seasasac.lflinkup.com/1da0da5da2da1da0da8/Bound-to-the-Alpha-Part-One-by-Viola-Rivard.pdf
    • http://seasasac.lflinkup.com/1da1da6da0da4da1/Ascension-Part-1-New-Alpha-Rising-1-by-A-T-Russell.pdf
    • http://seasasac.lflinkup.com/4da0da2da6da1da3/The-Alpha-s-Human-The-Complete-Series-The-Alpha-s-Human-1-by-D-J-Heart.pdf
    • http://seasasac.lflinkup.com/4da9da7da0da7da0/Fangs-of-Anarchy---Killing-the-Alpha-Part-1-by-Dakota-Cassidy.pdf
    • http://seasasac.lflinkup.com/7da5da0da5da0da6/The-Long-Game-How-Obama-Defied-Washington-and-Redefined-America-s-Role-in-the-World-by-Derek-Chollet.pdf
    • http://seasasac.lflinkup.com/5da0da5da4da0/Death-in-the-Long-Grass-A-Big-Game-Hunter-s-Adventures-in-the-African-Bush-by-Peter-Hathaway-Capstick.pdf
    • http://seasasac.lflinkup.com/2da4da9da2da5da4/Desired-Too-Loving-An-Alpha-Male-Series-4-by-S-K-Lessly.pdf
    • http://seasasac.lflinkup.com/4da2da7da7da6da7/Heart-of-an-Alpha-Wolf-Shifter-Series-1-by-G-A-Hurst.pdf
    • http://seasasac.lflinkup.com/3da4da7da1da1da9/Royal-Alpha-Jaxon-Trial-Series-1-by-Midika-Crane.pdf
    • http://seasasac.lflinkup.com/8da6da3da9da3da3/Alpha-s-Bane-Twin-City-Series-1-by-Katze-Snow.pdf
    • http://seasasac.lflinkup.com/4da6da8da0da8da8/Crossing-the-Line-Kismet-Series-1-by-Samantha-Long.pdf
    • http://seasasac.lflinkup.com/8da2da3da2da7/The-Warrior-s-Game-The-Warriors-Series-3-by-Denise-Domning.pdf
    • http://seasasac.lflinkup.com/2da6da7da6da6da7/The-Rush-The-End-Game-Series-Book-2-by-Piper-Westbrook.pdf
    • http://seasasac.lflinkup.com/2da2da9da1da2da3/The-Questing-Game-Firestaff-series-2-by-James-Galloway.pdf