Malicious PDF — malware analysis report

Static analysis result for SHA-256 a17d0cd90bd4538a…

MALICIOUS

PDF

13.4 KB Created: 2019-05-01 19:17:24 +01:00 Authoring application: mPDF 5.7
MD5: 254bab4212889b9da6e53569da975134 SHA-1: 9c1f7ed90709b5b7639d6e8bbb3bbb1268b7f76d SHA-256: a17d0cd90bd4538ae6bc2f3f2c618cfc4c6981f3003f09ec63476413c7c52bc7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF files, characteristic of a link farm. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the PDF structure and embedded URLs suggest a social engineering attack aimed at driving traffic to potentially malicious content. The primary attack pattern involves a "PDF SEO Link Farm" heuristic.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/4da1da0da7da3da0/Bound-by-Destiny-Ravage-MC-Bound-5-by-Ryan-Michele.pdf
    • http://seasasac.lflinkup.com/4da8da7da2da5da7/Bound-by-Desire-Ravage-MC-Bound-2-by-Ryan-Michele.pdf
    • http://seasasac.lflinkup.com/4da1da2da2da5da7/Bound-by-Family-Ravage-MC-Bound-1-by-Ryan-Michele.pdf
    • http://seasasac.lflinkup.com/3da6da6da3da5da7/Consume-Me-Ravage-MC-3-by-Ryan-Michele.pdf
    • http://seasasac.lflinkup.com/4da5da6da1da0da3/Satisfy-Me-Ravage-MC-3-5-by-Ryan-Michele.pdf
    • http://seasasac.lflinkup.com/4da8da0da2da0da4/Connected-in-Pain-Ravage-MC-Rebellion-1-by-Ryan-Michele.pdf
    • http://seasasac.lflinkup.com/3da0da2da3da5da2/Re-Bound-Doms-of-the-FBI-1-by-Michele-Zurlo.pdf
    • http://seasasac.lflinkup.com/2da1da7da1da2da7/Broken-Love-and-Forever-Bound-Bound-Series-1-by-Layla-Stevens.pdf
    • http://seasasac.lflinkup.com/4da6da6da4da0da6/Bound-by-Bliss-Bound-and-Determined-2-by-Lavinia-Kent.pdf
    • http://seasasac.lflinkup.com/2da9da9da1da8da6/Picture-Her-Bound-Bayou-Bound-1-by-Sidney-Bristol.pdf
    • http://seasasac.lflinkup.com/4da8da2da0da9da2/Forever-Bound-Bound-by-Darkness-1-by-Leanne-Scott.pdf
    • http://seasasac.lflinkup.com/4da6da9da3da3da2/Bound-by-Fate-Moon-Bound-1-by-Mandy-Lou-Dowson.pdf
    • http://seasasac.lflinkup.com/4da6da8da0da7da6/Raven-Bound-Crescent-Bound-2-by-Karli-Rush.pdf
    • http://seasasac.lflinkup.com/4da8da5da9da4/Bound-by-Blood-Bound-1-by-Cynthia-Eden.pdf
    • http://seasasac.lflinkup.com/7da2da7da2da9da3/Bound-Bound-Hearts-Book-1-by-S-N-Garza.pdf
    • http://seasasac.lflinkup.com/1da7da7da1da1da7/Bound-Bound-Trilogy-1-by-Kate-Sparkes.pdf
    • http://seasasac.lflinkup.com/1da2da5da5da6da8/Bound-by-Prophecy-Bound-3-by-Stormy-Smith.pdf
    • http://seasasac.lflinkup.com/4da6da2da2da3da3/Ice-Bound-Crescent-Bound-5-by-Karli-Rush.pdf
    • http://seasasac.lflinkup.com/2da0da6da0da0da4/Bound-by-Blood-Bound-1-by-Cynthia-Eden.pdf
    • http://seasasac.lflinkup.com/3da3da3da9da3da5/Bound-for-Life-Bound-to-the-Bad-Boy-1-by-Alexis-Abbott.pdf
    • http://seasasac.lflinkup.com/4da6da8da0da7da6/Raven-Bound-Crescent-Bound-2-by-Karli-Rush