Malicious PDF — malware analysis report

Static analysis result for SHA-256 a12b3819e2244657…

MALICIOUS

PDF

19.3 KB Created: 2019-04-30 05:18:23 +01:00 Authoring application: mPDF 5.7
MD5: 637e708fc6b721b3bec013a6aac25705 SHA-1: 5af31eaac6669e2bf8377a155c35efe1cae21bfb SHA-256: a12b3819e2244657ca48137d1901ecc8134f249affdbc9fc73bb7f7b4b06d3ae
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection scheme. While the document body is heavily obfuscated, the presence of numerous external links points towards a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/1da1da4da7da9da1da1/Turner-The-Extraordinary-Life-and-Momentous-Times-of-J-M-W-Turner-by-Franny-Moyle.pdf
    • http://seasasac.lflinkup.com/5da0da4da9da7da1/The-Double-Life-of-Miranda-Turner-Vol-1-If-You-Have-Ghosts-The-Double-Life-of-Miranda-Turner-1-by-Jamie-S-Rich.pdf
    • http://seasasac.lflinkup.com/4da1da9da2da9da3/Turncoat-Turner-amp-Turner-2-by-Amber-Green.pdf
    • http://seasasac.lflinkup.com/7da7da1da4da5da6/Desperate-Romantics-The-Private-Lives-Of-The-Pre-Raphaelites-by-Franny-Moyle.pdf
    • http://seasasac.lflinkup.com/3da0da7da0da5da2/Ms-Paige-Turner-s-Complete-Guide-to-America-s-Gentlemen-s-Clubs-by-Paige-Turner.pdf
    • http://seasasac.lflinkup.com/1da1da4da7da9da1da3/The-Confessions-of-Nat-Turner-by-Nat-Turner.pdf
    • http://seasasac.lflinkup.com/2da9da3da1da1da0/New-Life-Baby-Makes-Three-2-by-Dawn-M-Turner.pdf
    • http://seasasac.lflinkup.com/4da9da5da1da0da4/The-Tinkerer-s-Accomplice-How-Design-Emerges-from-Life-Itself-by-J-Scott-Turner.pdf
    • http://seasasac.lflinkup.com/3da5da8da7da8da5/Samurai-Rising-The-Epic-Life-of-Minamoto-Yoshitsune-by-Pamela-S-Turner.pdf
    • http://seasasac.lflinkup.com/1da4da3da9da6da3/The-Man-Called-CASH-The-Life-Love-and-Faith-of-an-American-Legend-by-Steve-Turner.pdf
    • http://seasasac.lflinkup.com/5da1da7da6da7da1/A-Life-in-the-Wild-George-Schaller-s-Struggle-to-Save-the-Last-Great-Beasts-by-Pamela-S-Turner.pdf
    • http://seasasac.lflinkup.com/6da6da4da7da1da7/Endurance-The-Extraordinary-Life-and-Times-of-Emil-Z-topek-by-Rick-Broadbent.pdf
    • http://seasasac.lflinkup.com/4da1da5da7da0da0/Everyday-Stalinism-Ordinary-Life-in-Extraordinary-Times-Soviet-Russia-in-the-1930s-by-Sheila-Fitzpatrick.pdf
    • http://seasasac.lflinkup.com/8da9da1da2/Eliza-Hamilton-The-Extraordinary-Life-and-Times-of-the-Wife-of-Alexander-Hamilton-by-Tilar-J-Mazzeo.pdf
    • http://seasasac.lflinkup.com/3da2da1da9da5da3/I-Just-Play-One-on-TV-by-A-L-Turner.pdf
    • http://seasasac.lflinkup.com/2da1da3da1da7da7/Hard-Hit-by-Ann-Turner.pdf
    • http://seasasac.lflinkup.com/2da2da5da3da9da8/Turner-by-Karl-Drinkwater.pdf
    • http://seasasac.lflinkup.com/9da2da8da4da7/Cool-Cat-Hot-Dog-by-Sandy-Turner.pdf
    • http://seasasac.lflinkup.com/7da1da9da3da1/Sign-of-the-Sandman-by-Tom-Turner.pdf
    • http://seasasac.lflinkup.com/1da0da2da0da3/My-Name-Is-Resolute-by-Nancy-E-Turner.pdf
    • http://seasasac.lflinkup.com/2da9da3da1da1da0/New-Life-Baby-Makes-Three-2-by-Dawn-M-T