Malicious PDF — malware analysis report

Static analysis result for SHA-256 c59dc560fb89bcfb…

MALICIOUS

PDF

19.8 KB Created: 2019-05-01 20:06:16 +01:00 Authoring application: mPDF 5.7
MD5: 16769fda70d7142de2f4f0ed42631220 SHA-1: e1767f95fcf3e5a34822e25b1766819522a248b4 SHA-256: c59dc560fb89bcfbca0a365a2ecfd9a8ad20ba7bbc49fd6497adf946652f79c4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs themselves are classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, likely for SEO manipulation or to redirect users to potentially harmful content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/2da7da2da6da3da0/Alienor-in-Aquitaine-Book-1-of-The-History-of-Eleanor-of-Aquitaine-by-Roberta-Puleo.pdf
    • http://seasasac.lflinkup.com/8da7da8da1da2/The-Book-of-Eleanor-A-Novel-of-Eleanor-of-Aquitaine-by-Pamela-Kaufman.pdf
    • http://seasasac.lflinkup.com/1da0da7da3da3da0da2/Eleanor-of-Aquitaine-by-D-D-R-Owen.pdf
    • http://seasasac.lflinkup.com/3da9da4da7da6da3/Eleanor-of-Aquitaine-and-the-Four-Kings-by-Amy-Kelly.pdf
    • http://seasasac.lflinkup.com/4da5da2da5da6da7/Eleanor-Of-Aquitaine-by-Marion-Meade.pdf
    • http://seasasac.lflinkup.com/3da2da7da9da5da4/Duchess-of-Aquitaine-A-Novel-of-Eleanor-by-Margaret-Ball.pdf
    • http://seasasac.lflinkup.com/3da9da1da8da7/Eleanor-of-Aquitaine-A-Life-by-Alison-Weir.pdf
    • http://seasasac.lflinkup.com/3da4da4da7da5da1/Queen-Defiant-A-Novel-of-Eleanor-of-Aquitaine-by-Anne-O-39-Brien.pdf
    • http://seasasac.lflinkup.com/1da8da6da6da3da4/Time-and-Chance-Henry-II-amp-Eleanor-of-Aquitaine-2-by-Sharon-Kay-Penman.pdf
    • http://seasasac.lflinkup.com/3da8da2da8da3/Devil-s-Brood-Henry-II-amp-Eleanor-of-Aquitaine-3-by-Sharon-Kay-Penman.pdf
    • http://seasasac.lflinkup.com/3da9da3da4da5/Time-and-Chance-Henry-II-amp-Eleanor-of-Aquitaine-2-by-Sharon-Kay-Penman.pdf
    • http://seasasac.lflinkup.com/4da9da6da1da0da6/Devil-s-Brood-Henry-II-amp-Eleanor-of-Aquitaine-3-by-Sharon-Kay-Penman.pdf
    • http://seasasac.lflinkup.com/2da4da0da0da8da0/When-Christ-and-His-Saints-Slept-Henry-II-amp-Eleanor-of-Aquitaine-1-by-Sharon-Kay-Penman.pdf
    • http://seasasac.lflinkup.com/4da5da4da1da1da0/When-Christ-and-His-Saints-Slept-Henry-II-amp-Eleanor-of-Aquitaine-1-by-Sharon-Kay-Penman.pdf
    • http://seasasac.lflinkup.com/8da7da6da1da2/The-Royal-Diaries---Eleanor-Crown-Jewel-of-Aquitaine-Mary-Queen-of-Scots-Marie-Antoinette-Princess-of-Versailles-by-Kristiana-Gregory.pdf
    • http://seasasac.lflinkup.com/2da5da8da7da0da1/Queens-Consort-England-s-Medieval-Queens-from-Eleanor-of-Aquitaine-to-Elizabeth-of-York-by-Lisa-Hilton.pdf
    • http://seasasac.lflinkup.com/1da5da0da3da8da5/Wade-of-Aquitaine-by-Ben-Parris.pdf
    • http://seasasac.lflinkup.com/5da4da4da6da2da6/Sainte-V-ronique-Ap-tre-De-L-Aquitaine-Son-Tombeau-Et-Son-Culte-Soulac-Ou-Notre-Dame-De-Fin-Des-Terres-Archidioc-se-De-Bordeaux---Primary-Source-Edition-by-Aur-lien.pdf
    • http://seasasac.lflinkup.com/8da8da8da4da4/The-Book-of-Eleanor-by-Nat-Burns.pdf
    • http://seasasac.lflinkup.com/2da6da8da7da2da5/A-History-of-Us-War-Terrible-War-1855-1865-a-History-of-Us-Book-Six-by-Joy-Hakim.pdf
    • http://seasasac.lflinkup.com/4da9da6da1da0da6/Devil-s-Brood-Henry-II-amp-E