Malicious PDF — malware analysis report

Static analysis result for SHA-256 952b5d58feb2f7de…

MALICIOUS

PDF

20.0 KB Created: 2019-04-30 04:24:36 +01:00 Authoring application: mPDF 5.7
MD5: e36fd723d007dbc88ca2b1450ddfd551 SHA-1: 539ab1b07ed4df20c1e44bef869aeb35ed3ded9f SHA-256: 952b5d58feb2f7dec2b546d4130461b0a27e6297f5ed637a6d4d1866e457d9a3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded URLs, forming a link farm. These links point to external PDF files, suggesting a social engineering tactic to direct users to potentially malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/1da8da6da2da7da7/Rock-Rod-Studios-Presents-Opening-Alex-Rock-Rod-2-by-Emory-Vargas.pdf
    • http://seasasac.lflinkup.com/2da7da5da7da6da0/Rock-Your-Plot-A-Simple-System-for-Plotting-Your-Novel-Rock-Your-Writing-1-by-Cathy-Yardley.pdf
    • http://seasasac.lflinkup.com/8da0da4da9da9da1/It-s-not-only-rock-n-roll-Sexe-drogues-et-sagesse-du-rock-by-Catherine-Viale.pdf
    • http://seasasac.lflinkup.com/4da9da8da2da0da7/Rock-of-Ages-The-Rolling-Stone-History-of-Rock-and-Roll-by-Ed-Ward.pdf
    • http://seasasac.lflinkup.com/7da2da2da9da0da9/Rock-Climbing-Desert-Rock-III-Moab-to-Colorado-National-Monument-by-Eric-Bjornstad.pdf
    • http://seasasac.lflinkup.com/7da7da4da4da8da6/The-Sound-and-the-Fury-40-Years-of-Classic-Rock-Journalism-A-Rock-s-Backpages-Reader-by-Barney-Hoskyns.pdf
    • http://seasasac.lflinkup.com/1da1da3da7da4da3da2/The-Rock-Star-s-Secret-Baby-Rock-Stars-in-Disguise-Book-5-Cadell-by-Blair-Babylon.pdf
    • http://seasasac.lflinkup.com/4da4da1da8da9da9/All-Roots-Lead-to-Rock-Legends-of-Early-Rock-n-Roll-A-Bear-Family-Reader-by-Colin-Escott.pdf
    • http://seasasac.lflinkup.com/4da4da1da8da6da6/Life-on-Planet-Rock-From-Guns-N-Roses-to-NIRVana-a-Backstage-Journey-Through-Rock-s-Most-Debauched-Decade-by-Lonn-Friend.pdf
    • http://seasasac.lflinkup.com/3da2da7da3da4da8/Rock-Addiction-Rock-Kiss-1-by-Nalini-Singh.pdf
    • http://seasasac.lflinkup.com/1da0da8da2da1da8da8/Lumpi-the-Sausage-Dog-and-Rock-Paper-Scissors-by-Alex-Planer.pdf
    • http://seasasac.lflinkup.com/6da2da8da0da8/Big-Rock-Big-Rock-1-by-Lauren-Blakely.pdf
    • http://seasasac.lflinkup.com/1da8da0da4da0da4/Rock-War-Rock-War-1-by-Robert-Muchamore.pdf
    • http://seasasac.lflinkup.com/1da8da2da3da8da0/The-Rock-Says-by-Dwayne-39-The-Rock-39-Johnson.pdf
    • http://seasasac.lflinkup.com/4da8da4da2/Rock-Chick-Reawakening-Rock-Chick-0-5-1001-Dark-Nights-52-by-Kristen-Ashley.pdf
    • http://seasasac.lflinkup.com/9da0da2da3da3da1/7th-Heaven-and-the-Rock-n-roll-Kids-Rock-n-roll-to-the-Rescue-Art-and-Introduction-by-Roy-Adorjan.pdf
    • http://seasasac.lflinkup.com/7da5da8da2da3/Rock-n-Roll-Promises-Rock-n-Roll-Paraphantasy-1-by-AmBear-Shellea.pdf
    • http://seasasac.lflinkup.com/4da4da1da9da0da6/Psychedelic-Renegades-With-Photographs-of-Syd-Barrett-by-Mick-Rock-by-Mick-Rock.pdf
    • http://seasasac.lflinkup.com/3da9da0da1da6da8/Rock-Chick-Regret-Rock-Chick-7-by-Kristen-Ashley.pdf
    • http://seasasac.lflinkup.com/2da1da9da9da3da0/Rock-Stars-Do-It-Forever-Rock-Stars-Do-It-3-by-Jasinda-Wilder.pdf
    • http://seasasac.lflinkup.com/7da7da4da4da8da6/The-Sound-and-the