Malicious PDF — malware analysis report

Static analysis result for SHA-256 e4d9aa6c49bf1197…

MALICIOUS

PDF

17.7 KB Created: 2019-05-01 20:08:39 +01:00 Authoring application: mPDF 5.7
MD5: f9c8589386c6308b7c7bd319575bca03 SHA-1: f86fdc873329e63bc0c5e6b32597998588a8041b SHA-256: e4d9aa6c49bf1197a6f12bd825d6f7bf0cad128ba5bdcbeb30d64c62c5c2bf9a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/1da0da9da3da2da1da6/edogawa-ranpo-zennshuu-ichi-shounenntannteidann-katuyakusu-by-Rampo-Edogawa.pdf
    • http://seasasac.lflinkup.com/1da1da8da4da4da8da7/The-world-of-Shakespeare-Hamlet-and-Julius-Caesar-by-shogo-kisaragi.pdf
    • http://seasasac.lflinkup.com/1da1da8da4da4da9da0/Play-of-the-child-1-by-shogo-kisaragi.pdf
    • http://seasasac.lflinkup.com/1da1da8da4da4da8da8/Desire-for-exchange-1-by-shogo-kisaragi.pdf
    • http://seasasac.lflinkup.com/1da1da8da4da4da2da8/Romeo-and-Juliet-of-Shakespeare-by-shogo-kisaragi.pdf
    • http://seasasac.lflinkup.com/1da1da8da4da4da3da2/Desire-for-exchange-Full-version-by-shogo-kisaragi.pdf
    • http://seasasac.lflinkup.com/1da1da8da4da4da3da0/Book-of-Five-Rings-by-Musashi-Miyamoto-full-version-by-shogo-kisaragi.pdf
    • http://seasasac.lflinkup.com/1da1da8da4da4da2da3/haiku-of-Shiki-MASAOKA-and-Picture-of-Fuji-of-Hokusai-KATSUSHIKA-by-shogo-kisaragi.pdf
    • http://seasasac.lflinkup.com/1da0da9da3da2da1da9/Edogawa-Ranpo-Sho-amp-X304-To-Nihon-No-Misuteri-amp-X304-by-Ensei-Sekiguchi.pdf
    • http://seasasac.lflinkup.com/3da6da9da0da6da6/The-Black-Lizard-and-Beast-in-the-Shadows-by-Rampo-Edogawa.pdf
    • http://seasasac.lflinkup.com/1da0da9da2da9da6da3/Edogawa-Ranposakuhinnshuu-zennsannjuugosakuhinnwoshuuroku-by-Rampo-Edogawa.pdf
    • http://seasasac.lflinkup.com/1da0da9da3da0da3da9/The-Edgar-Allan-Poe-of-Japan---Some-Tales-by-Edogawa-Rampo---With-Some-Stories-Inspired-by-His-Writings-by-Rampo-Edogawa.pdf
    • http://seasasac.lflinkup.com/1da0da9da2da9da6da1/The-Short-Stories-of-Rampo-Edogawa-by-Rampo-Edogawa.pdf
    • http://seasasac.lflinkup.com/2da0da4da9da2da6/No-Lie-I-Acted-Like-a-Beast-The-Story-of-Beauty-and-the-Beast-as-Told-by-the-Beast-by-Nancy-Loewen.pdf
    • http://seasasac.lflinkup.com/3da6da9da0da7da3/The-Edogawa-Rampo-Reader-by-Rampo-Edogawa.pdf
    • http://seasasac.lflinkup.com/2da7da6da3da3da1/Kill-the-Beast-Beast-Hunters-1-by-Michele-Israel-Harper.pdf
    • http://seasasac.lflinkup.com/3da1da3da4da2da3/Tartok-The-Ice-Beast-Beast-Quest-5-by-Adam-Blade.pdf
    • http://seasasac.lflinkup.com/3da8da3da3da1da4/Freeing-the-Beast-Taming-the-Beast-1-by-Tina-Donahue.pdf
    • http://seasasac.lflinkup.com/2da6da0da5da8da8/Blindness-by-Jos-Saramago.pdf
    • http://seasasac.lflinkup.com/8da2da4da9da9da6/Blindness-Seeing-by-Jos-Saramago.pdf
    • http://seasasac.lflinkup.com/1da0da9da3da2da1da9/Edogawa-Ranpo-Sho-amp-X304-To-Nihon-