Malicious PDF — malware analysis report

Static analysis result for SHA-256 7c2e46fd3d05ac52…

MALICIOUS

PDF

17.3 KB Created: 2019-05-01 19:24:15 +01:00 Authoring application: mPDF 5.7
MD5: af138f329337660fda8d104497246e0e SHA-1: ce6416c1ad30712e4876a426192a30710cd9170f SHA-256: 7c2e46fd3d05ac52e8bc6c41c0ae34461ca24159097bb4d7fca94082f36eac75
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently classified as benign, the sheer volume and the heuristic firing indicate a malicious intent, likely for SEO manipulation or to redirect users to malicious content. The ML classifier also flagged this PDF with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/2da9da6da5da2/Beginner-s-Guide-to-the-Western-Horse-by-Natlee-Kenoyer.pdf
    • http://seasasac.lflinkup.com/1da0da0da8da3da1da6/The-Horse-in-Blackfoot-Indian-Culture-With-Comparative-Material-from-Other-Western-Tribes-by-John-Canfield-Ewers.pdf
    • http://seasasac.lflinkup.com/1da1da6da7da9da1da2/Feminism-A-Beginner-s-Guide-by-Sally-J-Scholz.pdf
    • http://seasasac.lflinkup.com/4da8da0da3da9da1/A-Beginner-s-Guide-To-Salad-by-Jennifer-Joyce.pdf
    • http://seasasac.lflinkup.com/3da7da5da7da2da5/Israeli-Apartheid-A-Beginner-s-Guide-by-Ben-White.pdf
    • http://seasasac.lflinkup.com/8da1da1da0da6da7/Hamas-A-Beginner-s-Guide-by-Khaled-Hroub.pdf
    • http://seasasac.lflinkup.com/9da9da9da6da5da9/Beginner-s-Guide-to-Mountmellick-Embroidery-by-Pat-Trott.pdf
    • http://seasasac.lflinkup.com/2da9da0da4da7da6/Cloning-A-Beginner-s-Guide-by-Aaron-D-Levine.pdf
    • http://seasasac.lflinkup.com/6da2da9da6da9da8/A-Beginner-s-Guide-to-Communing-with-the-Dead-by-suspiciousflashlight.pdf
    • http://seasasac.lflinkup.com/9da2da2da5da7da7/Wikitravel-Hiroshima-And-Western-Japan-The-Free-Complete-Up-To-Date-And-Reliable-Guide-To-Hiroshima-And-Western-Japan-by-Marc-Heiden.pdf
    • http://seasasac.lflinkup.com/5da1da1da0da3da0/The-History-of-Medicine-A-Beginner-s-Guide-by-Mark-Jackson.pdf
    • http://seasasac.lflinkup.com/9da0da8da3da0da1/Preppers-amp-Survivalists-A-Beginner-s-Guide-by-Dave-Bronsky.pdf
    • http://seasasac.lflinkup.com/4da8da8da8da0da9/Philosophy-of-Mind-A-Beginner-s-Guide-by-Edward-Feser.pdf
    • http://seasasac.lflinkup.com/1da1da5da8da8da6da7/Apache-Solr-Beginner-s-Guide-by-Alfredo-Serafini.pdf
    • http://seasasac.lflinkup.com/4da0da6da3da0da5/A-Beginner-s-Guide-to-Invading-Earth-by-Gerhard-Gehrke.pdf
    • http://seasasac.lflinkup.com/1da1da1da7da1da0da2/Beginner-s-Guide-to-Solving-the-2X2-Cube-by-Dimitrios-Kalemis.pdf
    • http://seasasac.lflinkup.com/4da4da7da8da2da6/Life-in-the-Universe-A-Beginner-s-Guide-by-Lewis-Dartnell.pdf
    • http://seasasac.lflinkup.com/1da9da8da2da9da7/Beginner-s-Guide-Love-and-Other-Chemical-Reactions-by-Six-de-los-Reyes.pdf
    • http://seasasac.lflinkup.com/3da0da3da1da8da6/The-Beginner-s-Guide-to-Running-Away-from-Home-by-Jennifer-Larue-Huget.pdf
    • http://seasasac.lflinkup.com/9da9da5da8da5/For-Tibet-with-Love-A-Beginner-s-Guide-to-Changing-the-World-by-Isabel-Losada.pdf