Malicious PDF — malware analysis report

Static analysis result for SHA-256 e17e88d622553025…

MALICIOUS

PDF

18.8 KB Created: 2019-04-30 10:44:33 +01:00 Authoring application: mPDF 5.7
MD5: bf1aa8a9c8314a9e5757a26ccbd79cb2 SHA-1: 4cfaeb54b172180f272b9514191498c1bb874ab1 SHA-256: e17e88d6225530258c69a699f7c3e6f10a6de473976f131f99aff6810d122b9d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While most of these URLs are currently classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content. The ML_NYX_PDF_MALICIOUS heuristic also strongly indicates maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/3da6da0da4da3da0/Black-amp-White-by-Dani-Shapiro.pdf
    • http://seasasac.lflinkup.com/2da1da3da6da2da6/Black-Dog-and-Rebel-Rose-by-Dani-Smith.pdf
    • http://seasasac.lflinkup.com/4da3da1da2da0da6/Black-Dog-and-Rebel-Rose-0-The-Road-To-Hell-by-Dani-Smith.pdf
    • http://seasasac.lflinkup.com/1da1da1da3da2da0da6/Phineas-and-Ferb-Fanon---Angelina747-Characters-Characters-of-Miriam-Nicole-Gomez-Shapiro-an-Interview-with-Nicole-Emily-and-Sophie-Franziska-Gomez-Shapiro-Jacqueline-Leroy-Nicole-Gomez-Shapiro-Sahra-Graziano-Zwei-Kletten-Und-Ein-Schnabeltier-Com-by-Source-Wikia.pdf
    • http://seasasac.lflinkup.com/4da2da7da2da5da8/Sol-White-s-History-of-Colored-Baseball-with-Other-Documents-on-the-Early-Black-Game-1886-1936-by-Sol-White.pdf
    • http://seasasac.lflinkup.com/1da0da8da9da8da4da8/Warwolves-of-the-Iron-Cross-Black-Wolf-White-Reich-Black-Nazis-Wehrwolf-Book-7-by-V-K-Clark.pdf
    • http://seasasac.lflinkup.com/7da1da8da4da8/White-Black-3-by-T-L-Smith.pdf
    • http://seasasac.lflinkup.com/9da6da9da7da2/Black-and-White-by-Paul-Volponi.pdf
    • http://seasasac.lflinkup.com/1da8da5da2da9/Black-and-White-Men-by-James-Spada.pdf
    • http://seasasac.lflinkup.com/7da2da2da1da1da6/My-Life-In-Black-And-White-by-Kim-Izzo.pdf
    • http://seasasac.lflinkup.com/2da1da5da8da6da5/Black-and-White-Vol-1-by-Taiyo-Matsumoto.pdf
    • http://seasasac.lflinkup.com/8da6da9da9da6da5/Black-on-White-by-Tana-Hoban.pdf
    • http://seasasac.lflinkup.com/4da5da9da6da7da8/Black-and-White-by-Gilbert-Sorrentino.pdf
    • http://seasasac.lflinkup.com/1da9da8da5da9da8/Not-Just-Black-and-White-by-Lesley-Williams.pdf
    • http://seasasac.lflinkup.com/4da0da5da4da6da7/Black-and-White-by-Tiffany-Madison.pdf
    • http://seasasac.lflinkup.com/6da9da7da7da3/Black-and-White-by-David-Macaulay.pdf
    • http://seasasac.lflinkup.com/4da4da8da4da3da9/Black-or-White-by-John-Aubrey-Anderson.pdf
    • http://seasasac.lflinkup.com/3da4da2da3da8da0/White-Cat-Curse-Workers-1-by-Holly-Black.pdf
    • http://seasasac.lflinkup.com/5da8da3da7da6/Black-Rock-White-City-by-A-S-Patric.pdf
    • http://seasasac.lflinkup.com/7da7da8da5da7da4/Shreveport-Sounds-in-Black-amp-White-by-Kip-Lornell.pdf
    • http://seasasac.lflinkup.com/1da0da8da9da8da4da8/Warwo