Malicious PDF — malware analysis report

Static analysis result for SHA-256 731a6af0745dfb81…

MALICIOUS

PDF

18.8 KB Created: 2019-04-30 03:35:37 +01:00 Authoring application: mPDF 5.7
MD5: 07c9e5a2122cc4c9c9e9e531db474ced SHA-1: 2c00c7d20ed60834fc7c593bb8cf9f31858655eb SHA-256: 731a6af0745dfb81e497cad767ad64af153f4f328286ba1a3c457d85dcd629b0
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on the suspicious domain 'seasasac.lflinkup.com'. This behavior is indicative of a link farm or a method to distribute further malicious content. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/7da3da8da1da2da1/Quicklet-on-Ron-Suskind-s-A-Hope-in-the-Unseen-by-Lacey-Kohlmoos.pdf
    • http://seasasac.lflinkup.com/7da6da2da9da5/A-Hope-in-the-Unseen-An-American-Odyssey-from-the-Inner-City-to-the-Ivy-League-by-Ron-Suskind.pdf
    • http://seasasac.lflinkup.com/7da3da7da9da6da1/The-Way-of-the-World-A-Story-of-Truth-and-Hope-in-an-Age-of-Extremism-by-Ron-Suskind.pdf
    • http://seasasac.lflinkup.com/9da1da5da5da5da4/The-Unseen-The-Guardians-of-the-Unseen-1-by-Ben-Farrell.pdf
    • http://seasasac.lflinkup.com/9da1da5da5da4da8/Unseen-Unseen-1-by-Bel-Watson.pdf
    • http://seasasac.lflinkup.com/7da8da7da5da8da9/Lacey-Chabert-154-Success-Facts---Everything-You-Need-to-Know-about-Lacey-Chabert-by-Bruce-Hebert.pdf
    • http://seasasac.lflinkup.com/9da6da7da4da3da0/Quicklet-on-Casablanca-by-Elliot-Zanger.pdf
    • http://seasasac.lflinkup.com/5da9da4da7da1da6/Quicklet-on-Marjane-Satrapi-s-Persepolis-by-Natacha-Pavlov.pdf
    • http://seasasac.lflinkup.com/7da5da4da4da9da1/The-Ultimate-TED-Talks-Quicklet-Bundle---Dan-Pink-Dan-Gilbert-Chimamanda-Adichie-by-Karen-Lac.pdf
    • http://seasasac.lflinkup.com/1da1da7da3da3da9da4/Quicklet-on-R-B-Bernstein-s-The-Founding-Fathers-Reconsidered-CliffNotes-like-Book-Summary-by-Laura-Rensing.pdf
    • http://seasasac.lflinkup.com/7da3da8da1da3da3/The-Inner-Pasture-by-Sean-Suskind.pdf
    • http://seasasac.lflinkup.com/2da5da3da7da4da2/Perfume-by-Patrick-S-skind.pdf
    • http://seasasac.lflinkup.com/7da3da8da1da2da6/Do-You-Want-To-Live-Forever-by-Richard-Suskind.pdf
    • http://seasasac.lflinkup.com/7da3da8da0da5da2/Swords-Spears-And-Sandals-by-Suskind.pdf
    • http://seasasac.lflinkup.com/4da3da2da2da9/Perfume-The-Story-of-a-Murderer-by-Patrick-S-skind.pdf
    • http://seasasac.lflinkup.com/4da8da4da5da2da1/Perfume-The-Story-of-a-Murderer-by-Patrick-S-skind.pdf
    • http://seasasac.lflinkup.com/1da0da7da4da5da1da1/Perfume-The-Story-of-a-Murderer-by-Patrick-S-skind.pdf
    • http://seasasac.lflinkup.com/4da5da3da7da2da1/Ma-tre-Mussard-s-Bequest-by-Patrick-S-skind.pdf
    • http://seasasac.lflinkup.com/7da3da8da1da2da5/Men-in-Armor-The-Story-of-Knights-and-Knighthood-by-Richard-Suskind.pdf
    • http://seasasac.lflinkup.com/1da8da9da9da6da7/Know-Hope-Finding-Hope-in-Tragedy-by-Tammy-Conner-Stearns.pdf