Malicious PDF — malware analysis report

Static analysis result for SHA-256 b5408a3acdb069fa…

MALICIOUS

PDF

20.5 KB Created: 2019-05-05 14:34:44 +01:00 Authoring application: mPDF 5.7
MD5: 93a79389eefed443f0c4ce459906b338 SHA-1: 4290524362d6dc0904089bcbf62135cee74f4de2 SHA-256: b5408a3acdb069fa0d1ea5f3f0db9ead60d5b3653bd7ea5a3c4f533e620e67ba
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a critical heuristic for containing a large number of external links, suggesting a link farm or a method to distribute malicious content. The ML classifier also strongly indicated maliciousness. While no scripts were extracted, the sheer volume of embedded URLs points towards a malicious intent, likely to redirect users to compromised sites or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.l
    • http://seasasac.lflinkup.com/4da3da4da3da0da2/How-Firm-a-Foundation-Safehold-5-by-David-Weber.pdf
    • http://seasasac.lflinkup.com/4da3da4da3da0da1/A-Mighty-Fortress-Safehold-4-by-David-Weber.pdf
    • http://seasasac.lflinkup.com/1da4da2da5da7da9/By-Heresies-Distressed-Safehold-3-by-David-Weber.pdf
    • http://seasasac.lflinkup.com/6da0da2da8da0/The-Foundation-Novels-7-Book-Bundle-Foundation-Foundation-and-Empire-Second-Foundation-Foundation-s-Edge-Foundation-and-Earth-Prelude-to-Foundation-Forward-the-Foundation-by-Isaac-Asimov.pdf
    • http://seasasac.lflinkup.com/4da9da2da7da8da4/Getting-a-Grip-on-the-Basics-Building-a-Firm-Foundation-for-the-Victorious-Christian-Life-by-Beth-A-Jones.pdf
    • http://seasasac.lflinkup.com/1da5da9da9da7da3/Foundation-s-Triumph-Second-Foundation-Trilogy-3-by-David-Brin.pdf
    • http://seasasac.lflinkup.com/2da9da2da9da9da4/Articles-on-Foundation-Universe-Books-Including-I-Robot-Foundation-s-Edge-the-Caves-of-Steel-Prelude-to-Foundation-Foundation-and-Earth-Foundation-Series-Isaac-Asimov-s-Robot-Series-Isaac-Asimov-s-Galactic-Empire-Series-by-Hephaestus-Books.pdf
    • http://seasasac.lflinkup.com/2da5da7da7da2da8/Foundation-Foundation-and-Empire-Second-Foundation-by-Isaac-Asimov.pdf
    • http://seasasac.lflinkup.com/5da0da0da3da6da4/The-War-God-s-Own-War-God-2-by-David-Weber.pdf
    • http://seasasac.lflinkup.com/3da7da9da6da8da2/The-Warmasters-by-David-Weber.pdf
    • http://seasasac.lflinkup.com/2da5da6da4da3da4/In-Fury-Born-by-David-Weber.pdf
    • http://seasasac.lflinkup.com/3da0da2da2da6/A-Rising-Thunder-by-David-Weber.pdf
    • http://seasasac.lflinkup.com/6da1da0da2da0/Empire-From-the-Ashes-Dahak-1-3-by-David-Weber.pdf
    • http://seasasac.lflinkup.com/1da1da5da0da1da2/March-Upcountry-Empire-of-Man-1-by-David-Weber.pdf
    • http://seasasac.lflinkup.com/7da0da9da9da4/Mutineers-Moon-Dahak-1-by-David-Weber.pdf
    • http://seasasac.lflinkup.com/3da5da1da0da5da9/House-of-Steel-The-Honorverse-Companion-by-David-Weber.pdf
    • http://seasasac.lflinkup.com/2da1da9da7da1da3/Crown-of-Slaves-Honorverse-Wages-of-Sin-1-by-David-Weber.pdf
    • http://seasasac.lflinkup.com/2da1da9da7da0da7/Torch-of-Freedom-Honorverse-Wages-of-Sin-2-by-David-Weber.pdf
    • http://seasasac.lflinkup.com/4da3da5da0da2da6/Cauldron-of-Ghosts-Honorverse-Wages-of-Sin-3-by-David-Weber.pdf
    • http://seasasac.lflinkup.com/2da5da7da3da5da2/Field-of-Dishonor-Honor-Harrington-4-by-David-Weber.pdf