Malicious PDF — malware analysis report

Static analysis result for SHA-256 d85c329297e899ca…

MALICIOUS

PDF

20.4 KB Created: 2019-05-01 20:09:40 +01:00 Authoring application: mPDF 5.7
MD5: 4d78faed7cca6de16cd3b9bf7e654145 SHA-1: 7b2f4063c937f725fbb75f12e4a8c92eac928271 SHA-256: d85c329297e899ca6e1ca84bf36758f1d511058cb499ac0c70bc18db882e3ad6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a machine learning classifier as malicious and contains a large number of embedded external links. The primary heuristic indicates a 'PDF_SEO_LINK_FARM', suggesting the document's purpose is to host a large number of links, likely for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup
    • http://seasasac.lflinkup.com/4da0da3da8da3da5/Story-Thieves-Complete-Collection-Story-Thieves-The-Stolen-Chapters-Secret-Origins-Pick-the-Plot-Worlds-Apart-by-James-Riley.pdf
    • http://seasasac.lflinkup.com/5da5da9da2da2/The-Stolen-Chapters-Story-Thieves-2-by-James-Riley.pdf
    • http://seasasac.lflinkup.com/1da1da4/Story-Thieves-Story-Thieves-1-by-James-Riley.pdf
    • http://seasasac.lflinkup.com/1da4da4da5da8da0/Hot-Art-Chasing-Thieves-and-Detectives-Through-the-Secret-World-of-Stolen-Art-by-Joshua-Knelman.pdf
    • http://seasasac.lflinkup.com/4da6da3da2da9da5/The-Tale-of-Ali-Baba-and-the-Forty-Thieves-A-Story-from-the-Arabian-Nights-by-Anonymous.pdf
    • http://seasasac.lflinkup.com/4da4da2da1da0da1/Thieves-Till-We-Die-Thieves-Like-Us-2-by-Stephen-Cole.pdf
    • http://seasasac.lflinkup.com/2da3da8da8da3da3/The-Plot-The-Secret-Story-of-The-Protocols-of-the-Elders-of-Zion-by-Will-Eisner.pdf
    • http://seasasac.lflinkup.com/8da0da5da4/The-Smoke-Thieves-The-Smoke-Thieves-1-by-Sally-Green.pdf
    • http://seasasac.lflinkup.com/1da5da1da9da5da4/Thick-as-Thieves-Thick-as-Thieves-1-by-Tali-Spencer.pdf
    • http://seasasac.lflinkup.com/3da1da6da8da3da8/Jim-Morgan-and-the-King-of-Thieves-by-James-Matlack-Raney.pdf
    • http://seasasac.lflinkup.com/3da3da9da1da3da6/Honor-Among-Thieves-Star-Wars-Empire-and-Rebellion-2-by-James-S-A-Corey.pdf
    • http://seasasac.lflinkup.com/2da7da3da1da7da1/Rules-for-Thieves-Rules-for-Thieves-1-by-Alexandra-Ott.pdf
    • http://seasasac.lflinkup.com/1da8da5da3da8da0/Sufferings-in-Africa-The-Incredible-True-Story-of-a-Shipwreck-Enslavement-and-Survival-on-the-Sahara-by-James-Riley.pdf
    • http://seasasac.lflinkup.com/1da9da4da4da2da2/Goldfields-A-Ghost-Story-History-and-Horrors-short-story-collection-1-by-Johanna-Craven.pdf
    • http://seasasac.lflinkup.com/6da2da2da7da8da4/Children-s-Book-Fish-Also-Go-To-Heaven-value-tales-bedtime-story-kid-s-short-story-collection-by-Tammy-Brown-Elkeles.pdf
    • http://seasasac.lflinkup.com/2da5da2da5da1da6/Faith-and-Treason-The-Story-of-the-Gunpowder-Plot-by-Antonia-Fraser.pdf
    • http://seasasac.lflinkup.com/3da6da8da1da1da6/The-Information-Thieves-by-M-L-Katz.pdf
    • http://seasasac.lflinkup.com/2da5da3da1da6da9/Thieves-Emporium-by-Max-Hern-ndez.pdf
    • http://seasasac.lflinkup.com/4da6da3da5da8da7/Among-Thieves-by-David-Hosp.pdf
    • http://seasasac.lflinkup.com/3da5da7da9da6da5/Thieves-Fall-Out-by-Cameron-Kay.pdf