Malicious PDF — malware analysis report

Static analysis result for SHA-256 7edc66d758c04fc6…

MALICIOUS

PDF

20.0 KB Created: 2019-05-01 18:28:36 +01:00 Authoring application: mPDF 5.7
MD5: 1a15e85bda1734300f734a0d8901d396 SHA-1: 3df25e9da5e45d4ebbb5a27e631486a023d6a176 SHA-256: 7edc66d758c04fc6d719cfdc3b4f237fa096d9db2adeec897a3a3160bd4a4aa1
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links. The heuristic 'PDF_SEO_LINK_FARM' indicates that the document is designed to host a mass of external links, likely to manipulate search engine results or distribute malicious content. No scripts were extracted from this sample, and the document body was unreadable, so the attack pattern is inferred from the link farm heuristic.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/4da4da8da8da1da0/Crystal-Clear-by-Nell-Dixon.pdf
    • http://seasasac.lflinkup.com/3da8da7da7da1da9/Crystal-Clear-A-Supernatural-Mystery-by-R-C-Drake.pdf
    • http://seasasac.lflinkup.com/1da1da1da6da3da3da4/Drei-mal-rot-dann-f-nfzehn-mal-gr-n-by-Crystal-Clear.pdf
    • http://seasasac.lflinkup.com/6da3da1da7da0da1/Dominic-Deegan-Crystal-Clear-Dominic-Deegan-Series-1-by-Michael-Terracciano.pdf
    • http://seasasac.lflinkup.com/4da1da5da1da3da7/The-Crystal-Healer-Crystal-prescriptions-that-will-change-your-life-forever-by-Philip-Permutt.pdf
    • http://seasasac.lflinkup.com/1da0da3da6da8da6da8/Crystal-Energy-A-Practical-Guide-to-the-Use-of-Crystal-Cards-for-Rejuvenation-and-Health-by-Monnica-Hackl.pdf
    • http://seasasac.lflinkup.com/1da0da8da6da9da4da0/Der-Aufstieg-by-Walter-Harich.pdf
    • http://seasasac.lflinkup.com/4da6da8da4da8da7/Crystal-Fire-Tales-of-the-Crystal-Book-One-by-R-L-Kiser.pdf
    • http://seasasac.lflinkup.com/4da3da3da8da4da3/Crystal-Traveler-Crystal-Message-Chronicles-1-by-R-B-Breighton.pdf
    • http://seasasac.lflinkup.com/1da5da9da6da5da0/Crystal-Line-Crystal-Singer-3-by-Anne-McCaffrey.pdf
    • http://seasasac.lflinkup.com/2da0da3da8da7da0/Zelda-and-the-Crystal-Slippers-The-Crystal-Adventures-1-by-R-W-Mitchell.pdf
    • http://seasasac.lflinkup.com/5da5da9da5da5da5/Zelda-and-the-Crystal-Lamp-The-Crystal-Adventures-2-by-R-W-Mitchell.pdf
    • http://seasasac.lflinkup.com/1da1da0da4da4da0da0/Die-Aeg-Aufstieg-Und-Niedergang-Einer-Industrielegende-by-Peter-Strunk.pdf
    • http://seasasac.lflinkup.com/8da0da5da5da1da6/Rockmusik-Und-Gruppenprozesse-Aufstieg-Und-Abstieg-Der-Petards-by-Florian-Tennstedt.pdf
    • http://seasasac.lflinkup.com/1da0da8da7da0da3da5/Der-Aufstieg-des-Vierten-Reiches---Geheime-Gesellschaften-bernehmen-die-Macht-in-den-USA-by-Jim-Marrs.pdf
    • http://seasasac.lflinkup.com/1da0da8da6da8da3da9/Lords-of-Chaos-Satanischer-Metal-Der-blutige-Aufstieg-aus-dem-Untergrund-by-Michael-Moynihan.pdf
    • http://seasasac.lflinkup.com/1da0da8da6da8da4da9/King-of-the-World-Der-Aufstieg-des-Cassius-Clay-oder-die-Geburt-des-Muhammad-Ali-by-David-Remnick.pdf
    • http://seasasac.lflinkup.com/1da1da1da9da4da9/Crystal-Doors-Crystal-Doors-1-by-Rebecca-Moesta.pdf
    • http://seasasac.lflinkup.com/2da5da0da3da0da8/Clear-by-Paige-Notaro.pdf
    • http://seasasac.lflinkup.com/1da6da1da6da6da8/From-a-Clear-Blue-Sky-by-Timothy-Knatchbull.pdf
    • http://seasasac.lflinkup.com/1da0da8da6da9da4da0/Der-Aufstieg-by-