Malicious PDF — malware analysis report

Static analysis result for SHA-256 fa848619e964266b…

MALICIOUS

PDF

21.9 KB Created: 2019-04-30 03:30:30 +01:00 Authoring application: mPDF 5.7
MD5: 224d0058f3fef7da226ccae5bc7b5163 SHA-1: 8b38e62d26ae5beee98ef88bcca444f19c57dfc5 SHA-256: fa848619e964266b453563e783ff6f2faf2431453d24356580e09116f7177b1f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document contains a large number of embedded external links, disguised as book titles, which is indicative of a link farm or SEO poisoning attack. The primary heuristic firing, PDF_SEO_LINK_FARM, directly supports this observation. While the URLs themselves are currently marked as benign, the sheer volume and deceptive nature of the links suggest a malicious intent to redirect users to potentially harmful content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/1da7/Ghettoside-A-True-Story-of-Murder-in-America-by-Jill-Leovy.pdf
    • http://seasasac.lflinkup.com/4da0da8da7da9da9/Ghettoside-A-True-Story-of-Murder-in-America-by-Jill-Leovy.pdf
    • http://seasasac.lflinkup.com/8da0da7da8da6da9/Ghettoside-Investigating-a-Homicide-Epidemic-by-Jill-Leovy.pdf
    • http://seasasac.lflinkup.com/9da8da4da7da4da7/The-Homicide-Report-Understanding-Murder-in-America-by-Jill-Leovy.pdf
    • http://seasasac.lflinkup.com/1da5da8da6da8da8/Pointing-From-The-Grave-A-True-Story-of-Murder-and-DNA-by-Samantha-Weinberg.pdf
    • http://seasasac.lflinkup.com/1da7da1da2da6/Before-He-Wakes-A-True-Story-of-Money-Marriage-Sex-and-Murder-by-Jerry-Bledsoe.pdf
    • http://seasasac.lflinkup.com/7da7da5da0da3da5/Dark-Heart-A-True-Story-of-Sex-Manipulation-and-Murder-by-Kevin-Flynn.pdf
    • http://seasasac.lflinkup.com/2da7da9da2da7da7/Severed-The-True-Story-of-the-Black-Dahlia-Murder-by-John-Gilmore.pdf
    • http://seasasac.lflinkup.com/6da1da3da6da6da7/Fetal-Abduction-The-True-Story-of-Multiple-Personalities-and-Murder-by-Anne-Speckhard.pdf
    • http://seasasac.lflinkup.com/5da7da7da3da0da0/Disposable-Income-A-True-Story-of-Sex-Greed-and-Im-purr-fect-Murder-by-Tammy-Mal.pdf
    • http://seasasac.lflinkup.com/1da8da6da8da1da6/Never-Leave-Me-A-True-Story-of-Marriage-Deception-and-Brutal-Murder-by-John-Glatt.pdf
    • http://seasasac.lflinkup.com/2da0da9da4da0da1/A-Cast-of-Killers-The-True-Story-of-Hollywood-s-Most-Scandalous-Murder-by-Sidney-D-Kirkpatrick.pdf
    • http://seasasac.lflinkup.com/1da0da6da2da9da1da0/PSI-Spies-The-True-Story-of-America-s-Psychic-Warfare-Program-by-Jim-Marrs.pdf
    • http://seasasac.lflinkup.com/4da2da3da4da5da2/Just-Like-Us-The-True-Story-of-Four-Mexican-Girls-Coming-of-Age-in-America-by-Helen-Thorpe.pdf
    • http://seasasac.lflinkup.com/1da8da6da3da9da8/Such-Good-Boys-The-True-Story-of-a-Mother-Two-Sons-and-a-Horrifying-Murder-by-Tina-Dirmann.pdf
    • http://seasasac.lflinkup.com/1da1da4da0da9da4da2/The-Pyjama-Girl-Mystery-A-True-Story-of-Murder-Obsession-and-Lies-by-Richard--Evans.pdf
    • http://seasasac.lflinkup.com/6da8da1da9da2da6/Blood-of-Innocents-The-True-Story-of-Multiple-Murder-in-West-Memphis-Arkansas-by-Guy-Reel.pdf
    • http://seasasac.lflinkup.com/8da4da6da7da3/The-Daughters-of-Ju-rez-A-True-Story-of-Serial-Murder-South-of-the-Border-by-Teresa-Rodriguez.pdf
    • http://seasasac.lflinkup.com/2da0da9da6da0da6/Rough-Trade-A-Shocking-True-Story-of-Prostitution-Murder-and-Redemption-by-Steve-Jackson.pdf
    • http://seasasac.lflinkup.com/3da7da9da7da0da3/Simon-Says-A-True-Story-of-Boys-and-Murder-in-the-Rocky-Mountain-West-by-Kathryn-Eastburn.pdf