Malicious PDF — malware analysis report

Static analysis result for SHA-256 96914829c56d4c45…

MALICIOUS

PDF

21.2 KB Created: 2019-04-30 02:11:10 +01:00 Authoring application: mPDF 5.7
MD5: 71690ea2794b83e7de99ce0a030f036f SHA-1: 93aee277c3106ab4e297c80ab7f0e01f73e9f60d SHA-256: 96914829c56d4c451ef83c02a0f9a7978d0ec51f7c0329abab164b35f2eaf72e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated, the presence of numerous links suggests a tactic to drive traffic to a large collection of documents, potentially for SEO poisoning or to host further malicious content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinku
    • http://seasasac.lflinkup.com/5da4da0da8da7da4/The-Universal-Baseball-Association-Inc-J-Henry-Waugh-Prop-by-Robert-Coover.pdf
    • http://seasasac.lflinkup.com/4da5da4da4da0da2/Ghost-Town-by-Robert-Coover.pdf
    • http://seasasac.lflinkup.com/2da0da3da7da1da6/Pricksongs-and-Descants-by-Robert-Coover.pdf
    • http://seasasac.lflinkup.com/4da5da0da0da0da1/The-Colonel-s-Daughter-by-Robert-Coover.pdf
    • http://seasasac.lflinkup.com/1da5da4da8da6/The-Public-Burning-by-Robert-Coover.pdf
    • http://seasasac.lflinkup.com/2da9da2da0da0da2/Briar-Rose-by-Robert-Coover.pdf
    • http://seasasac.lflinkup.com/4da2da7da0da0da8/Baseball-in-41-a-Celebration-of-the-quot-Best-Baseball-Season-Ever-quot-by-Robert-W-Creamer.pdf
    • http://seasasac.lflinkup.com/4da6da2da2da4/Antiquity-Calais-Standing-at-Armageddon-The-Universal-Life-Force-Series-Book-1-by-Jim-Henry.pdf
    • http://seasasac.lflinkup.com/4da2da6da0da7da4/The-Physics-of-Baseball-by-Robert-K-Adair.pdf
    • http://seasasac.lflinkup.com/8da4da9da3da4da7/Universal-War-One-Universal-War-One-1-6-by-Denis-Bajram.pdf
    • http://seasasac.lflinkup.com/3da0da5da4da7da3/The-Samurai-Way-of-Baseball-The-Impact-of-Ichiro-and-the-New-Wave-from-Japan-by-Robert-Whiting.pdf
    • http://seasasac.lflinkup.com/4da2da6da5da1da8/100-Years-of-Baseball-The-Intimate-and-Dramatic-Story-of-Modern-Baseball-by-Lee-Allen.pdf
    • http://seasasac.lflinkup.com/2da2da2da3da4da6/The-Baseball-Reader-Favorites-from-the-Fireside-Books-of-Baseball-by-Charles-Einstein.pdf
    • http://seasasac.lflinkup.com/2da2da4da7da4da9/Baseball-on-Trial-The-Origin-of-Baseball-s-Antitrust-Exemption-by-Nathaniel-Grow.pdf
    • http://seasasac.lflinkup.com/9da4da5da7da4da4/Association-Football-Players-Who-Committed-Suicide-Robert-Enke-Hughie-Gallacher-Justin-Fashanu-S-Ndor-Kocsis-Matthias-Sindelar-by-Source-Wikipedia.pdf
    • http://seasasac.lflinkup.com/3da6da0da0da1da5/The-Passed-Prop-The-Morelville-Cozies-1-by-Anne-Hagan.pdf
    • http://seasasac.lflinkup.com/5da8da3da8da0da0/Minutes-of-the-Fifth-Annual-Session-of-the-Haw-Ridge-Baptist-Association-Held-with-Ebenezer-Church-Dale-Conty-Alabama-October-11-and-12-1893-by-Haw-Ridge-Baptist-Association.pdf
    • http://seasasac.lflinkup.com/9da8da5da8da4da3/The-Diaries-Of-Evelyn-Waugh-by-Evelyn-Waugh.pdf
    • http://seasasac.lflinkup.com/1da1da3da5da5da9da6/American-Heart-Association-Healthy-Slow-Cooker-Cookbook-200-Low-Fuss-Good-for-You-Recipes-by-American-Heart-Association.pdf
    • http://seasasac.lflinkup.com/1da1da4da4da5da4da2/20th-Century-Baseball-Chronicle-A-Year-By-Year-History-of-Major-League-Baseball-by-David-Nemec.pdf