Malicious PDF — malware analysis report

Static analysis result for SHA-256 e341a9d7b84288f5…

MALICIOUS

PDF

21.8 KB Created: 2019-05-02 00:56:17 +01:00 Authoring application: mPDF 5.7
MD5: bfd8586c582902681303888f0fc5397f SHA-1: d86a816f467384fbb039a466d9c28158faa91e95 SHA-256: e341a9d7b84288f50d9b20018930efd34c44e95703b7cae1bd2fa0f52e473a5b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles, suggesting a lure to disguise the malicious intent. While the URLs themselves are currently flagged as benign, the sheer volume and the ML classifier's high confidence indicate a malicious purpose, likely SEO manipulation or redirection to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/2da7da8da6da2da2/Secrets-of-the-Heart-A-Christian-Suspense-Romance-Novel-The-Crystal-Cove-Series-1-by-Kelsey-MacBride.pdf
    • http://seasasac.lflinkup.com/7da9da3da7da6da2/Free-to-Love-Inspiration-Point-Series-1-by-Kelsey-MacBride.pdf
    • http://seasasac.lflinkup.com/4da5da6da8da7da1/ROMANCE-CONTEMPORARY-ROMANCE-Bounty-and-the-Beast-Billionaire-Bad-Boy-Heroine-Mystery-Romance-Contemporary-Mystery-and-Suspense-Mafia-Romance-Book-2-by-Portia-Paige.pdf
    • http://seasasac.lflinkup.com/1da1da4da1da8da5da9/Streams-of-Mercy-A-Christian-Romance-Mystery-Novel-Jenna-s-Creek-Series-Book-1-by-Teresa-Slack.pdf
    • http://seasasac.lflinkup.com/2da1da6da9da7da8/Crystal-Cove-by-Lisa-Kleypas.pdf
    • http://seasasac.lflinkup.com/4da4da0da8da4da5/Highland-Secrets-Revealed-Ladies-of-Dunmore-Series-A-Medieval-Scottish-Romance-Story-by-Bridget-Freya.pdf
    • http://seasasac.lflinkup.com/7da9da3da9da5da9/Heart-of-a-Rocky-by-Kelsey-Jordan.pdf
    • http://seasasac.lflinkup.com/1da7da7da7da2da8/Life-After-Death-A-Romance-Suspense-by-T-J-Graham.pdf
    • http://seasasac.lflinkup.com/2da0da6da9da9/Season-Of-Secrets-Lowcountry-Suspense-3-by-Marta-Perry.pdf
    • http://seasasac.lflinkup.com/9da6da0da7da3da4/A-Crystal-Angel-A-Marsden-Romance-1-5-by-Dawn-Brower.pdf
    • http://seasasac.lflinkup.com/3da6da6da4da7da0/Secrets-Of-The-Lighthouse-A-Dual-Series-of-Secrets-1-by-D-Raye-Spencer.pdf
    • http://seasasac.lflinkup.com/2da8da2da5da6da6/Out-Of-Her-League-Suspense-Series-1-by-Kaylea-Cross.pdf
    • http://seasasac.lflinkup.com/4da6da9da9da5da4/Cover-of-Darkness-Suspense-Series-2-by-Kaylea-Cross.pdf
    • http://seasasac.lflinkup.com/8da8da9da9da1/Attractions-of-the-Heart-by-Cheri-Crystal.pdf
    • http://seasasac.lflinkup.com/3da5da1da6da2da0/Special-Delivery-Valentine-An-Office-Romance-Short-Story-Lesbian-Office-Romance-Series-Book-2-by-Roz-Lee.pdf
    • http://seasasac.lflinkup.com/5da2da9da1da7da7/All-That-Remains-A-Missing-amp-Exploited-Suspense-Series-1-by-Hannah-Holborn.pdf
    • http://seasasac.lflinkup.com/5da8da8da1da9da5/The-Crystal-Heart-Enthralled-1-by-Prax-Venter.pdf
    • http://seasasac.lflinkup.com/7da1da3da2da6da9/The-Rakehell-Regency-Romance-Series-Boxed-Set-5-The-Rakehell-Regency-Romance-Series-Boxed-Sets-by-Sorcha-MacMurrough.pdf
    • http://seasasac.lflinkup.com/1da1da7da7da1da8da6/The-Admirer-s-Secret-The-Mental-Madness-Suspense-Series-by-Pamela-Crane.pdf
    • http://seasasac.lflinkup.com/4da1da5da4da7da0/Play-Your-Heart-Out-Sinful-Serenade-4-by-Crystal-Kaswell.pdf
    • http://seasasac.lflinkup.com/1da1da4da1da