Malicious PDF — malware analysis report

Static analysis result for SHA-256 7ed2a1622456b47e…

MALICIOUS

PDF

23.6 KB Created: 2019-11-22 12:47:44 +00:00 Authoring application: mPDF 5.7
MD5: d1f70fabcc3d625c668abd07c10741c8 SHA-1: 74bde13c0f538879c8e269004bd1d93345cf8fda SHA-256: 7ed2a1622456b47ec52a24852449e0c262620255c695470b13bddb6d39bffabe
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign content, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. The ML classifier also flagged the PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9726

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://leakscaioiobook.4dq.com/1d0c1d0c6d0c0d0c7d0c6d0c7/Eckhart-Tolle-39-Life-Changing-and-Inspirational-Lessons-from-Eckhart-Tolle-Eckhart-Tolle-Eckhart-Tolle-Book-Eckhart-Tolle-Guide-Eckhart-Tolle-Words-Eckhart-Tolle-Lessons-by-James-Derici.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c6d0c0d0c4d0c9d0c9/Eckhart-Tolle-Eckhart-Tolle-Greatest-Quotes-And-Life-Lessons-Eckhart-Tolle-Lessons-Book-1-by-Hugh-Jacklyn.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c6d0c0d0c4d0c9d0c5/Eckhart-Tolle-Understanding-the-Life-and-Teachings-of-Eckhart-Tolle-on-Consciousness-and-Spirituality-by-Ruth-Carr.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c6d0c0d0c4d0c7d0c2/Creating-a-New-Earth-Teachings-to-Awaken-Consciousness-The-Best-of-Eckhart-Tolle-TV-Season-One-by-Eckhart-Tolle.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c6d0c0d0c5d0c0d0c5/Who-Is-Asking-Who-Am-I-Eckhart-Tolle-and-Deepak-Chopra-Explore-the-Transcendent-Dimension-of-Who-You-Are-by-Eckhart-Tolle.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c6d0c0d0c4d0c6d0c5/Eckhart-Tolle-Eckhart-Tolle-99-Powerful-Lessons-and-Wisdom-of-Eckhart-Tolle-by-Lessons-and-Wisdom.pdf
    • http://leakscaioiobook.4dq.com/4d0c0d0c0d0c5d0c4d0c5/A-New-Earth-Create-a-Better-Life-by-Eckhart-Tolle.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c6d0c0d0c5d0c6d0c7/Doorway-Into-Now-by-Eckhart-Tolle.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c6d0c0d0c4d0c5d0c7/The-Journey-Into-Yourself-by-Eckhart-Tolle.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c6d0c0d0c4d0c5d0c3/The-Realization-of-Being-by-Eckhart-Tolle.pdf
    • http://leakscaioiobook.4dq.com/5d0c4d0c7d0c5d0c8d0c4/Entering-the-Now-by-Eckhart-Tolle.pdf
    • http://leakscaioiobook.4dq.com/8d0c3d0c6d0c1d0c9d0c6/The-Art-of-Presence-by-Eckhart-Tolle.pdf
    • http://leakscaioiobook.4dq.com/6d0c9d0c2d0c7d0c5/A-New-Earth-Awakening-to-Your-Life-s-Purpose-by-Eckhart-Tolle.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c6d0c0d0c5d0c0d0c2/The-Secret-Of-Self-Realization-by-Eckhart-Tolle.pdf
    • http://leakscaioiobook.4dq.com/9d0c4d0c3d0c4d0c5d0c8/De-kracht-van-het-nu-in-de-praktijk-by-Eckhart-Tolle.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c6d0c0d0c4d0c9d0c2/The-Illusion-Of-Time-by-Eckhart-Tolle.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c6d0c0d0c5d0c0d0c3/Choose-to-Awaken-Now-by-Eckhart-Tolle.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c6d0c0d0c4d0c5d0c5/Living-the-Liberated-Life-and-Dealing-with-the-Pain-Body-by-Eckhart-Tolle.pdf
    • http://leakscaioiobook.4dq.com/6d0c1d0c5d0c4d0c5d0c8/Lev-her-og-n-lev-i-n-et---f-ny-energi-og-balanse-by-Eckhart-Tolle.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c6d0c0d0c7d0c7d0c9/The-Terrorist-Within-Oct-20-2001-Los-Angeles-Ca-by-Eckhart-Tolle.pdf