Malicious PDF — malware analysis report

Static analysis result for SHA-256 f55022b11d88437b…

MALICIOUS

PDF

19.0 KB Created: 2019-05-01 21:22:34 +01:00 Authoring application: mPDF 5.7
MD5: df7288aa88500634203c77b01e3270a5 SHA-1: 0d54eb8c9edf8761a766398aa815eb6a8150da9f SHA-256: f55022b11d88437ba8e22ae4077df9bb54c2e0e280261d8be28ba21ced2448bf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier strongly indicated maliciousness. While the document body is heavily corrupted, the presence of numerous links to a single domain, 'seasasac.lflinkup.com', suggests a coordinated effort to drive traffic or distribute further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/2da4da4da2/Sword-and-Verse-Sword-and-Verse-1-by-Kathy-MacMillan.pdf
    • http://seasasac.lflinkup.com/3da7da2da5da0da2/Dagger-and-Coin-Sword-and-Verse-2-by-Kathy-MacMillan.pdf
    • http://seasasac.lflinkup.com/4da0da4da5da9da9/Voice-of-the-Sword-Sword-Mirror-Jewel-Trilogy-1-by-John-Paul-Catton.pdf
    • http://seasasac.lflinkup.com/1da5da6da5da0da4/Sword-amp-Illusion-Sword-of-Justice-Saga-1-by-Nancy-S-Brandt.pdf
    • http://seasasac.lflinkup.com/2da7da6da5da5da5/The-Destiny-of-the-Sword-The-Seventh-Sword-3-by-Dave-Duncan.pdf
    • http://seasasac.lflinkup.com/6da8da4da2da8da8/Spider-Man-Spider-Verse---Fearsome-Foes-Spider-Man-Enter-The-Spider-Verse-2018-Book-1-by-Stan-Lee.pdf
    • http://seasasac.lflinkup.com/3da9da9da9da0/The-Sword-of-Truth-Boxed-Set-I-Wizard-s-First-Rule-Blood-of-the-Fold-Stone-of-Tears-Sword-of-Truth-1-3-by-Terry-Goodkind.pdf
    • http://seasasac.lflinkup.com/1da0da2da8da1da6/The-Sun-Sword-The-Sun-Sword-6-by-Michelle-West.pdf
    • http://seasasac.lflinkup.com/2da0da9da2da4da0/Sword-Art-Online-Fairy-Dance-Vol-3-Sword-Art-Online-Manga-3-by-Tsubasa-Haduki.pdf
    • http://seasasac.lflinkup.com/2da0da8da9da0da6/Sword-Art-Online-Vol-04-Fairy-Dance-Sword-Art-Online-Light-Novel-4-by-Reki-Kawahara.pdf
    • http://seasasac.lflinkup.com/2da0da8da8da7da4/Sword-Art-Online-Vol-02-Aincrad-Sword-Art-Online-Light-Novel-2-by-Reki-Kawahara.pdf
    • http://seasasac.lflinkup.com/1da5da5da5da3da0/The-Sword-of-the-Spirits-Trilogy-The-Sword-of-the-Spirits-1-3-by-John-Christopher.pdf
    • http://seasasac.lflinkup.com/3da2da0da1/The-Bird-and-the-Sword-The-Bird-and-the-Sword-Chronicles-1-by-Amy-Harmon.pdf
    • http://seasasac.lflinkup.com/3da5da3da6da6da8/Sun-Bridge-amp-Sword-The-Final-War-Bridge-amp-Sword-10-by-J-C-Andrijeski.pdf
    • http://seasasac.lflinkup.com/2da0da9da2da2da5/Sword-Art-Online-Progressive-Vol-4-Sword-Art-Online-Progressive-Manga-4-by-Kiseki-Himura.pdf
    • http://seasasac.lflinkup.com/5da2da6da1da6da7/Spider-Verse-by-Dan-Slott.pdf
    • http://seasasac.lflinkup.com/6da3da5da5da6da3/Zoe-and-Verse-by-Jade-Jones.pdf
    • http://seasasac.lflinkup.com/1da1da3da8da5da3da8/Delete-This-Homework-Verse-3-by-nyxocity.pdf
    • http://seasasac.lflinkup.com/8da8da2da6da2/Beowulf-A-Verse-Translation-by-Unknown.pdf
    • http://seasasac.lflinkup.com/6da9da9da0da8da1/Beowulf-A-Verse-Translation-by-Unknown.pdf
    • http://seasasac.lflinkup.com/3da9da9da9da0/The-Sword