Malicious PDF — malware analysis report

Static analysis result for SHA-256 0bd1b603086bd544…

MALICIOUS

PDF

22.6 KB Created: 2019-05-02 18:36:17 +01:00 Authoring application: mPDF 5.7
MD5: c53f39d444d7bdc98e7dfc269ec37ffd SHA-1: 2c55811de075ebc53c1b151e09ac86ca7d85e867 SHA-256: 0bd1b603086bd544af710956b20fd75a5dcf0bb01ec59e1f7dbcf71124bb76b5
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files hosted on the suspicious domain 'kiteeearpdf.myhome.cx'. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/4f218f212f213f210f212/A-Match-Made-in-Texas-Chatam-House-2-by-Arlene-James.pdf
    • http://kiteeearpdf.myhome.cx/6f212f216f216f216f218/His-Ideal-Match-by-Arlene-James.pdf
    • http://kiteeearpdf.myhome.cx/6f212f211f216f210/A-Texas-Made-Match-by-Noelle-Marchand.pdf
    • http://kiteeearpdf.myhome.cx/6f215f216f213f216f211/Speech-of-Hon-Jas-W-Throckmorton-of-Texas-In-the-House-of-Representatives-March-1-1877-Together-with-the-Report-of-the-Hon-L-Q-C-Lamar-of-Mississippi-Chairman-of-the-Committee-on-Pacific-Railroads-Made-to-the-House-of-Representatives-Janua-by-J-W-Throckmorton.pdf
    • http://kiteeearpdf.myhome.cx/6f215f216f213f216f219/Speech-of-Hon-Jas-W-Throckmorton-of-Texas-in-the-House-of-Representatives-March-1-1877-Together-with-the-Report-of-the-Hon-L-Q-C-Lamar-of-Mississippi-Chairman-of-the-Committee-on-Pacific-Railroads-Made-to-the-House-of-Representatives-Janua-by-J-W-1825-1894-Throckmorton.pdf
    • http://kiteeearpdf.myhome.cx/1f211f213f215f211f214/Match-Made-in-Manhattan-by-Amanda-Stauffer.pdf
    • http://kiteeearpdf.myhome.cx/1f216f212f215f212f217/How-to-Have-a-Match-Made-in-Heaven-by-Ariel-Kane.pdf
    • http://kiteeearpdf.myhome.cx/6f218f214f210f213f219/Infamous-Hearts-A-Match-Made-in-History-by-Yolanda-Olson.pdf
    • http://kiteeearpdf.myhome.cx/5f216f219f214f214f219/A-Match-Made-on-Main-Street-Briar-Creek-2-by-Olivia-Miles.pdf
    • http://kiteeearpdf.myhome.cx/5f211f218f217f215/A-Match-Made-in-Hell-The-Jewish-Boy-and-the-Polish-Outlaw-Who-Defied-the-Nazis-by-Larry-Stillman.pdf
    • http://kiteeearpdf.myhome.cx/1f212f217f213f216/The-Rogue-Who-Came-To-Stay-This-Side-of-Heaven-4-by-Arlene-James.pdf
    • http://kiteeearpdf.myhome.cx/3f217f213f214f215f219/The-Sheriff-s-Runaway-Bride-Rocky-Mountain-Heirs-2-by-Arlene-James.pdf
    • http://kiteeearpdf.myhome.cx/2f210f216f218f218f210/A-Match-Made-at-Christmas-Christmas-in-New-York-4-by-Patty-Blount.pdf
    • http://kiteeearpdf.myhome.cx/9f212f214f219f211f214/For-the-Love-of-Mike-Men-Made-in-America-43---Texas-by-Candace-Schuler.pdf
    • http://kiteeearpdf.myhome.cx/5f211f211f213f212f219/Lincoln-s-White-House-The-People-s-House-in-Wartime-by-James-B-Conroy.pdf
    • http://kiteeearpdf.myhome.cx/2f211f216f217f212f219/Game-Set-Match-Love-Match-1-by-Nana-Malone.pdf
    • http://kiteeearpdf.myhome.cx/5f210f215f212f218f215/Miss-Match-No-Match-for-Love-1-by-Lindzee-Armstrong.pdf
    • http://kiteeearpdf.myhome.cx/3f219f216f210f216f214/Joy-House-Texas-Kisses-4-by-Jenny-Schwartz.pdf
    • http://kiteeearpdf.myhome.cx/1f210f219f212f219f217/A-House-Made-of-Bricks-by-Penelope-Baldwin.pdf
    • http://kiteeearpdf.myhome.cx/1f215f216f214f212f211/The-False-House-The-High-House-2-by-James-Stoddard.pdf