Malicious PDF — malware analysis report

Static analysis result for SHA-256 a1700db74a81321b…

MALICIOUS

PDF

20.3 KB Created: 2019-05-02 11:12:31 +01:00 Authoring application: mPDF 5.7
MD5: e124b4d04650ab7d56bc726b84c696e1 SHA-1: 98e6890024394feca0fa4a13fad90cd63147d242 SHA-256: a1700db74a81321bdaf3b23051f0325b90fbde5ad4ffddeabf7a2e0d546b8c54
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-sounding book titles, the sheer volume and the ML_NYX_PDF_MALICIOUS classification suggest a malicious intent, likely for SEO manipulation or to serve as a lure for further malicious activity. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/9da3da7da4da4da4/The-James-Thurber-Audio-Collection-Fables-and-Selected-Stories-by-James-Thurber-by-James-Thurber.pdf
    • http://seasasac.lflinkup.com/9da3da7da5da4da4/People-Have-More-Fun-Than-Anybody-A-Centennial-Celebration-of-Drawings-amp-Writings-by-James-Thurber-by-James-Thurber.pdf
    • http://seasasac.lflinkup.com/9da3da7da3da3da1/Thurber-and-Company-by-James-Thurber.pdf
    • http://seasasac.lflinkup.com/9da3da7da3da2da5/A-Thurber-Carnival-by-James-Thurber.pdf
    • http://seasasac.lflinkup.com/9da3da7da5da3da0/World-of-James-Thurber-by-James-Thurber.pdf
    • http://seasasac.lflinkup.com/9da3da7da4da7da8/Conversations-with-James-Thurber-by-James-Thurber.pdf
    • http://seasasac.lflinkup.com/3da8da4da6da4/The-13-Clocks-by-James-Thurber.pdf
    • http://seasasac.lflinkup.com/9da3da7da5da3da3/The-Night-the-Ghost-Got-in-by-James-Thurber.pdf
    • http://seasasac.lflinkup.com/9da3da7da5da7da4/Selected-Letters-by-James-Thurber.pdf
    • http://seasasac.lflinkup.com/9da3da7da4da7da9/Lanterns-amp-Lances-by-James-Thurber.pdf
    • http://seasasac.lflinkup.com/4da0da6da8da3da3/The-Tiger-Who-Would-be-King-by-James-Thurber.pdf
    • http://seasasac.lflinkup.com/9da3da7da5da8da5/Stories-and-Fables-for-Our-Time-by-James-Thurber.pdf
    • http://seasasac.lflinkup.com/4da4da2da2da7da8/The-Last-Flower-A-Parable-in-Pictures-by-James-Thurber.pdf
    • http://seasasac.lflinkup.com/9da3da7da5da4da7/The-Seal-in-the-Bedroom-and-Other-Predicaments-by-James-Thurber.pdf
    • http://seasasac.lflinkup.com/3da0da0da3da3da2/The-Middle-aged-Man-on-the-Flying-Trapeze-by-James-Thurber.pdf
    • http://seasasac.lflinkup.com/3da7da0da5da9da7/The-Secret-Life-of-Walter-Mitty-by-James-Thurber.pdf
    • http://seasasac.lflinkup.com/9da3da7da5da7da3/Collecting-Himself-James-Thurber-on-Writing-and-Writers-Humor-and-Himself-by-Michael-J-Rosen.pdf
    • http://seasasac.lflinkup.com/9da6da4da5da7/James-Harriot-s-5-Book-Set-All-Creatures-Great-and-Small-All-Things-Bright-and-Beautiful-All-Things-Wise-and-Wonderful-the-Lord-God-Made-Them-All-Every-Living-Thing-by-James-Herriot.pdf
    • http://seasasac.lflinkup.com/1da8da0da6da0da9/James-Herriot-All-Creatures-Great-and-Small-All-Things-Bright-and-Beautiful-All-Things-Wise-and-Wonderful-The-Lord-God-Made-Them-All-Boxed-Set-by-James-Herriot.pdf
    • http://seasasac.lflinkup.com/3da9da2da9da5da0/1-800-MICE-by-Matthew-Thurber.pdf
    • http://seasasac.lflinkup.com/9da3da7da5da3da3/The-Night-the-Ghost-Got-in-by-James-Thurber