Malicious PDF — malware analysis report

Static analysis result for SHA-256 04681f136cc15477…

MALICIOUS

PDF

15.7 KB Created: 2020-03-19 00:16:02 +00:00 Authoring application: mPDF 5.7
MD5: d41ee0aa45cd456e05fdae28ebb32978 SHA-1: cf20ed5281f5dca5e20bee6ab39dbbaca15abf91 SHA-256: 04681f136cc15477a44d2541fd8d719d9706db64ddaaa6f8b705f450fcdbc16f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which suggests a malicious intent to redirect users or engage in SEO poisoning. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification. While no scripts were explicitly extracted, the nature of the embedded links and the PDF structure points towards a phishing or malicious redirection attack, likely delivered as a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kitasdyu.myhome.cx/1878873873878874/Dead-Meat-by-Sue-Coe.pdf
    • http://kitasdyu.myhome.cx/4870876875871879/Dead-Meat-Zombie-D-O-A-0-5-by-J-J-Zep.pdf
    • http://kitasdyu.myhome.cx/1873871877878874/The-One-from-the-Other-Bernard-Gunther-4-by-Philip-Kerr.pdf
    • http://kitasdyu.myhome.cx/9877874876876/A-Philosophical-Investigation-by-Philip-Kerr.pdf
    • http://kitasdyu.myhome.cx/9875870874877877/The-2007-2012-World-Outlook-for-Meat-Markets-and-Delicatessens-by-Philip-M-Parker.pdf
    • http://kitasdyu.myhome.cx/6873875875877875/Metropolis-Bernie-Gunther-0-5-by-Philip-Kerr.pdf
    • http://kitasdyu.myhome.cx/2874879870877878/A-Man-Without-Breath-Bernie-Gunther-9-by-Philip-Kerr.pdf
    • http://kitasdyu.myhome.cx/1873872876873873/Prague-Fatale-Bernard-Gunther-8-by-Philip-Kerr.pdf
    • http://kitasdyu.myhome.cx/1875877876874875/Prague-Fatale-Bernie-Gunther-8-by-Philip-Kerr.pdf
    • http://kitasdyu.myhome.cx/1873871871877874/The-Pale-Criminal-Bernie-Gunther-2-by-Philip-Kerr.pdf
    • http://kitasdyu.myhome.cx/9879871877877873/Sunny-Sweet-Is-So-Dead-Meat-by-Jennifer-Ann-Mann.pdf
    • http://kitasdyu.myhome.cx/9875870874877879/The-2007-Report-on-Meat-Markets-and-Delicatessens-World-Market-Segmentation-by-City-by-Philip-M-Parker.pdf
    • http://kitasdyu.myhome.cx/1875878873875875/Greeks-Bearing-Gifts-Bernie-Gunther-13-by-Philip-Kerr.pdf
    • http://kitasdyu.myhome.cx/6875873877871874/Greeks-Bearing-Gifts-Bernie-Gunther-13-by-Philip-Kerr.pdf
    • http://kitasdyu.myhome.cx/3878870879879875/Dead-Camp-One-Dead-Camp-1-by-Sean-Kerr.pdf
    • http://kitasdyu.myhome.cx/9879871879873872/Red-Meat-A-Collection-of-Red-Meat-Cartoons-From-the-Secret-Files-of-Max-Cannon-by-Max-Cannon.pdf
    • http://kitasdyu.myhome.cx/1870877875870870/Philip-K-Dick-is-Dead-Alas-by-Michael-Bishop.pdf
    • http://kitasdyu.myhome.cx/1871873877878875872/Dead-Man-Talking-and-Talking-and-Talking-by-Philip-Sorgen.pdf
    • http://kitasdyu.myhome.cx/9879871879873873/You-Don-t-Need-Meat-by-Peter-Cox.pdf
    • http://kitasdyu.myhome.cx/9879871876878877/Meat-Your-Maker-by-Sandman.pdf