Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe9a29c7733f5a91…

MALICIOUS

PDF

20.2 KB Created: 2019-04-30 03:40:48 +01:00 Authoring application: mPDF 5.7
MD5: 543eef704bfccddd5947507439bfab97 SHA-1: 7c2ef11a4348e3e9e9af6579a6c4fb0d770361ea SHA-256: fe9a29c7733f5a919b5fc40fa736eaf52f27ee3d79528f82acf9e871c9d44c96
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded URLs, while individually marked as benign, collectively form a link farm, suggesting a tactic to distribute or obscure malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/4da5da7da7da0da9/Dead-Medium-by-Peter-John.pdf
    • http://seasasac.lflinkup.com/3da5da9da2da8da0/Do-Dead-People-Watch-You-Shower-And-Other-Questions-You-ve-Been-All-but-Dying-to-Ask-a-Medium-by-Concetta-Bertoldi.pdf
    • http://seasasac.lflinkup.com/6da0da4da5da7/Discovering-the-Medium-Within-Techniques-amp-Stories-from-a-Professional-Psychic-Medium-by-Anysia-Marcell-Kiel.pdf
    • http://seasasac.lflinkup.com/6da2da2da8da8/The-Medium-Emily-Chambers-Spirit-Medium-Trilogy-1-by-C-J-Archer.pdf
    • http://seasasac.lflinkup.com/1da0da2da2da5da1/One-Last-Time-A-Psychic-Medium-Speaks-to-Those-We-Have-Loved-and-Lost-by-John-Edward.pdf
    • http://seasasac.lflinkup.com/4da0da6da2da7da9/The-Priest-and-the-Medium-The-Amazing-True-Story-of-Psychic-Medium-B-Anne-Gehman-and-Her-Husband-Former-Jesuit-Priest-Wayne-Knoll-Ph-D-by-Suzanne-R-Giesemann.pdf
    • http://seasasac.lflinkup.com/4da3da2da5da6da8/Dead-Even-Dead-3-John-Mancini-5-by-Mariah-Stewart.pdf
    • http://seasasac.lflinkup.com/3da6da1da0da1da1/Still-Dead-Book-of-the-Dead-2-by-John-Skipp.pdf
    • http://seasasac.lflinkup.com/8da0da7da4da5da2/Psychic-Theresa-Caputo-quot-The-Long-Island-Medium-quot-Understanding-and-Exploring-the-Life-of-a-Psychic-Medium-by-Shanna-Lynn-Adams.pdf
    • http://seasasac.lflinkup.com/1da1da0da5da7da9da7/The-Long-Dead-DCI-John-Blizzard-1-by-John-Dean.pdf
    • http://seasasac.lflinkup.com/2da2da8da0da6da7/A-Salute-to-One-of-The-Few-The-Life-of-Flying-Officer-Peter-Cape-Beauchamp-St-John-RAF-by-Simon-St-John-Beer.pdf
    • http://seasasac.lflinkup.com/1da3da0da9da1da3/Not-Dead-Yet-Roy-Grace-8-by-Peter-James.pdf
    • http://seasasac.lflinkup.com/2da6da2da9da6da8/Dead-Like-You-Roy-Grace-6-by-Peter-James.pdf
    • http://seasasac.lflinkup.com/1da2da2da6da4da9/Dead-Like-You-Roy-Grace-6-by-Peter-James.pdf
    • http://seasasac.lflinkup.com/3da8da4da8da9/A-Requiem-For-Dead-Flies-by-Peter-N-Dudar.pdf
    • http://seasasac.lflinkup.com/7da1da9da5da1/Dead-Man-s-Time-Roy-Grace-9-by-Peter-James.pdf
    • http://seasasac.lflinkup.com/3da4da5da3da7da8/Love-You-Dead-Roy-Grace-12-by-Peter-James.pdf
    • http://seasasac.lflinkup.com/3da9da4da6da3/Dead-Simple-Roy-Grace-1-by-Peter-James.pdf
    • http://seasasac.lflinkup.com/2da0da8da3da8da6/Dead-Tomorrow-Roy-Grace-5-by-Peter-James.pdf
    • http://seasasac.lflinkup.com/3da3da4da1da9da0/Dead-Tomorrow-Roy-Grace-5-by-Peter-James.pdf
    • http://seasasac.lflinkup.com/4da0da6da2da7da9/The-Priest-and-the-Medium-The-Amazing-True-Story-of-Psychic-Medium-B-Anne-Gehman-and-Her-Husband-Former-Je