Malicious PDF — malware analysis report

Static analysis result for SHA-256 719f300079166fd9…

MALICIOUS

PDF

19.6 KB Created: 2019-04-30 18:49:36 +01:00 Authoring application: mPDF 5.7
MD5: be03c43a1372b0bbb0a15bbb856cd287 SHA-1: f87bdadef2047b2ab4a4935d954ba33cbb8eda6d SHA-256: 719f300079166fd959c3a1353d0ba4d7b27eca9113d225d6faf37ea07bb70b4d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection scheme. While the document body is heavily obfuscated, the presence of numerous external links points towards a phishing or malicious redirection attempt. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/1da6da5da8da9da5/Einstein-s-God-by-Krista-Tippett.pdf
    • http://seasasac.lflinkup.com/1da8da8da5da9da0/A-Side-of-Faith-Sandwich-2-by-Krista-Phillips.pdf
    • http://seasasac.lflinkup.com/4da4da2da1da9da3/Speaking-of-Faith-Global-Perspectives-on-Women-Religion-amp-Social-Change-by-Diana-L-Eck.pdf
    • http://seasasac.lflinkup.com/9da7da6da6da7/This-Is-Your-Captain-Speaking-My-Fantastic-Voyage-Through-Hollywood-Faith-and-Life-by-Gavin-MacLeod.pdf
    • http://seasasac.lflinkup.com/9da3da8da4da4da4/GERMAN-TRAVEL-PHRASES-FOR-ENGLISH-SPEAKING-TRAVELERS-The-most-needed-1-000-phrases-when-traveling-in-German-speaking-countries-by-Sarah-Retter.pdf
    • http://seasasac.lflinkup.com/1da2da1da0da7da0/Made-in-British-Columbia-Eight-Ways-of-Making-Culture-by-Maria-Tippett.pdf
    • http://seasasac.lflinkup.com/8da4da6da5da2da8/The-Bark-Of-The-Dogwood-A-Tour-Of-Southern-Homes-And-Gardens-by-Jackson-Tippett-McCrae.pdf
    • http://seasasac.lflinkup.com/4da5da0da7da1da1/Faith-and-Reason-How-the-Two-Work-to-Build-a-Dynamic-Faith-by-William-Hemsworth.pdf
    • http://seasasac.lflinkup.com/1da0da1da8da8da0/Faith-Has-Its-Reasons-Integrative-Approaches-to-Defending-the-Christian-Faith-by-Kenneth-D-Boa.pdf
    • http://seasasac.lflinkup.com/9da4da7da2da6da0/Faith-and-the-Faith-The-Bohlen-Lectures-1914-by-Samuel-Hart.pdf
    • http://seasasac.lflinkup.com/3da6da3da0da2da0/Fed-Up-with-Flat-Faith-10-Ways-to-Pump-Up-Your-Faith-by-Kathy-Howard.pdf
    • http://seasasac.lflinkup.com/3da1da9da5da3da9/Losing-Faith-in-Faith-From-Preacher-to-Atheist-by-Dan-Barker.pdf
    • http://seasasac.lflinkup.com/9da9da3da2da4da2/Keeping-Faith-Reece-amp-Faith-4-by-T-J-Vertigo.pdf
    • http://seasasac.lflinkup.com/2da8da6da4da5da6/Saving-Faith-Faith-amp-Kung-Fu-2-by-T-M-Gaouette.pdf
    • http://seasasac.lflinkup.com/3da0da6da1da9da4/Angel-amp-Faith-Daddy-Issues-Part-3-Angel-amp-Faith-8-by-Christos-Gage.pdf
    • http://seasasac.lflinkup.com/3da0da5da9da9da3/Angel-amp-Faith-Family-Reunion-Part-2-Angel-amp-Faith-12-by-Christos-Gage.pdf
    • http://seasasac.lflinkup.com/3da0da4da3da8da8/Angel-amp-Faith-Daddy-Issues-Angel-amp-Faith-Volume-2-by-Christos-Gage.pdf
    • http://seasasac.lflinkup.com/3da0da6da1da4da1/Angel-amp-Faith-Family-Reunion-Part-3-Angel-amp-Faith-13-by-Christos-Gage.pdf
    • http://seasasac.lflinkup.com/3da1da5da9da8/Speaking-of-Murder-vol-1-by-Ed-Gorman.pdf
    • http://seasasac.lflinkup.com/9da6da1da0da7da3/Speaking-in-Tungs-by-Karla-M-Jay.pdf