Malicious PDF — malware analysis report

Static analysis result for SHA-256 a2494a86423aa6d3…

MALICIOUS

PDF

20.5 KB Created: 2019-05-03 06:00:40 +01:00 Authoring application: mPDF 5.7
MD5: 8c09741303ca3f79450ee749df443933 SHA-1: ab8ad3964cf3bd0779f2dc901a732bb759fc8b10 SHA-256: a2494a86423aa6d3b7656b11829490e3439a4c03387856cd4810ba484d8f213d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this document as malicious with high confidence. The embedded URLs, while many are marked as benign, are part of a link farm strategy, likely to direct users to malicious content or for SEO poisoning. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/4da0da4da8da8da7/Real-Men-Snarl-Real-Men-Shift-2-by-Celia-Kyle.pdf
    • http://seasasac.lflinkup.com/4da1da5da1da2da3/Chicken-Soup-for-the-Girl-s-Soul-Real-Stories-by-Real-Girls-About-Real-Stuff-by-Jack-Canfield.pdf
    • http://seasasac.lflinkup.com/5da0da1da4da2da9/Top-Tips-for-Girls-Real-Advice-from-Real-Women-for-Real-Life-by-Kate-Reardon.pdf
    • http://seasasac.lflinkup.com/2da3da7da8da7da3/The-Night-Shift-Real-Life-In-The-Heart-Of-The-E-R-by-Brian-Goldman.pdf
    • http://seasasac.lflinkup.com/1da0da5da7da2da8da3/A-Shift-in-Time-Finding-the-Real-Historical-Jesus-by-Lena-Einhorn.pdf
    • http://seasasac.lflinkup.com/5da0da3da0da7/The-Real-Grey-s-Anatomy-A-Behind-The-Scenes-Look-at-The-Real-Lives-of-Surgical-Residents-by-Andrew-Holtz.pdf
    • http://seasasac.lflinkup.com/7da8da9da7da5da8/Argus-Developer-in-Practice-Real-Estate-Development-Modeling-in-the-Real-World-by-Tim-Havard.pdf
    • http://seasasac.lflinkup.com/5da0da4da2da7da2/Real-Reading-Real-Writing-Content-Area-Strategies-by-Donna-Hooker-Topping.pdf
    • http://seasasac.lflinkup.com/5da7da5da4/Real-Sexy-Real-Dirty-Duet-2-by-Meghan-March.pdf
    • http://seasasac.lflinkup.com/4da8da6da3/Real-Good-Love-Real-Duet-2-by-Meghan-March.pdf
    • http://seasasac.lflinkup.com/4da2da6da7da9da7/Real-Grass-Real-Heroes-by-Dom-Dimaggio.pdf
    • http://seasasac.lflinkup.com/2da0da7da1da4da6/Real-Men-Don-t-Drink-Appletinis-Real-Men-1-by-Liz-Matis.pdf
    • http://seasasac.lflinkup.com/5da6da1da5da0da3/Krav-Maga-Real-World-Solutions-to-Real-World-Violence---Disrupt-Damage-Destroy-Disengage-by-Gershon-Ben-Keren.pdf
    • http://seasasac.lflinkup.com/2da6da0da3da0/The-Unreal-and-the-Real-Selected-Stories-Volume-Two-Outer-Space-Inner-Lands-The-Unreal-and-the-Real-2-by-Ursula-K-Le-Guin.pdf
    • http://seasasac.lflinkup.com/1da0da3da3da7/Real-Real-1-by-Katy-Evans.pdf
    • http://seasasac.lflinkup.com/3da6da4da0da7da0/One-Real-Man-Real-Men-3-by-Coleen-Kwan.pdf
    • http://seasasac.lflinkup.com/2da6da0da3da1/The-Unreal-and-the-Real-Selected-Stories-Volume-One-Where-on-Earth-The-Unreal-and-the-Real-1-by-Ursula-K-Le-Guin.pdf
    • http://seasasac.lflinkup.com/4da7da2da4da8da1/Practicing-My-First-Real-Kiss-My-First-Real-Kiss-1-by-Ciara-Jamie-Garcia.pdf
    • http://seasasac.lflinkup.com/5da5da1da3da3da6/Real-Mermaids-Don-t-Sell-Seashells-Real-Mermaids-4-by-Helene-Boudreau.pdf
    • http://seasasac.lflinkup.com/3da8da1da1da7da1/Real-Vampires-Do-It-in-the-Dark-Real-Vampires-Don-t-Sparkle-2-by-Amy-Fecteau.pdf
    • http://seasasac.lflinkup.com/7da8da9da7da5da8/Argus-Dev