Malicious PDF — malware analysis report

Static analysis result for SHA-256 0ecafec586e5f4f2…

MALICIOUS

PDF

22.8 KB Created: 2019-05-02 17:18:09 +01:00 Authoring application: mPDF 5.7
MD5: 51fbfa13727139156d77ebea3bec27cb SHA-1: 8d123e852e87da73dda1357a99df39c3e690c831 SHA-256: 0ecafec586e5f4f29243367945e43c5dceed236d8c38a2403d4075010e26485f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'kiteeearpdf.myhome.cx'. This is indicative of a link farm or SEO poisoning tactic, likely intended to drive traffic or distribute further malicious content. No scripts were extracted, and the document body was unreadable, but the heuristic 'PDF_SEO_LINK_FARM' strongly suggests this malicious intent. The ML classifier also flagged the PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/1f210f218f216f217f216f218/Last-Train-to-Memphis---Elvis-Presley-Sein-Aufstieg-1935-1958-by-Peter-Guralnick.pdf
    • http://kiteeearpdf.myhome.cx/8f218f213f214f218/Careless-Love-The-Unmaking-of-Elvis-Presley-by-Peter-Guralnick.pdf
    • http://kiteeearpdf.myhome.cx/4f211f218f218f210f217/Careless-Love-The-Unmaking-of-Elvis-Presley-by-Peter-Guralnick.pdf
    • http://kiteeearpdf.myhome.cx/7f218f215f213f210f216/Elvis-Close-Up-Rare-Intimate-Unpublished-Photographs-of-Elvis-Presley-in-1956-by-Jay-B-Leviton.pdf
    • http://kiteeearpdf.myhome.cx/1f211f215f217f219f210f218/It-Is-No-Secret-by-Elvis-Presley.pdf
    • http://kiteeearpdf.myhome.cx/1f214f211f218f212f213/Elvis-Presley-A-Life-by-Bobbie-Ann-Mason.pdf
    • http://kiteeearpdf.myhome.cx/4f219f217f210f213f218/Elvis-and-the-Memphis-Mafia-by-Alanna-Nash.pdf
    • http://kiteeearpdf.myhome.cx/3f211f216f213f211/Night-Train-to-Memphis-Vicky-Bliss-5-by-Elizabeth-Peters.pdf
    • http://kiteeearpdf.myhome.cx/4f219f218f212f213f217/The-Colonel-The-Extraordinary-Story-of-Colonel-Tom-Parker-and-Elvis-Presley-by-Alanna-Nash.pdf
    • http://kiteeearpdf.myhome.cx/3f219f211f213f213f219/Dr-Feelgood-The-Story-of-the-Doctor-Who-Influenced-History-by-Treating-and-Drugging-Prominent-Figures-Including-President-Kennedy-Marilyn-Monroe-and-Elvis-Presley-by-Richard-A-Lertzman.pdf
    • http://kiteeearpdf.myhome.cx/2f218f219f217f212f217/Sweet-Soul-Music-Rhythm-and-Blues-and-the-Southern-Dream-of-Freedom-by-Peter-Guralnick.pdf
    • http://kiteeearpdf.myhome.cx/9f212f214f211f211f214/Der-Aufstieg-und-noch-viel-gr-ere-Aufstieg-des-Cameron-Deeds-by-Guido-Galahan.pdf
    • http://kiteeearpdf.myhome.cx/4f215f215f219f210f212/Little-Memphis-Little-Memphis-MC-1-by-Bijou-Hunter.pdf
    • http://kiteeearpdf.myhome.cx/8f219f213f212f214f214/Thadd-Presley-Presents-Creature-Feature-by-Thadd-Presley.pdf
    • http://kiteeearpdf.myhome.cx/7f216f215f210f216f217/Alles-Zuviel-Wie-Man-Sein-Leben-Wieder-In-Den-Griff-Kriegt-by-Peter-Walsh.pdf
    • http://kiteeearpdf.myhome.cx/4f219f217f215f219f216/Ernest-Withers-The-Memphis-Blues-Again-Six-Decades-of-Memphis-Music-Photographs-by-Ernest-C-Withers.pdf
    • http://kiteeearpdf.myhome.cx/1f212f211f212f211f217/Morris-As-Elvis-The-World-s-Greatest-Elvis-Impersonator-by-Morris-Bates.pdf
    • http://kiteeearpdf.myhome.cx/9f219f212f212f211f219/Unternehmer-sein-hei-t-frei-sein-Mein-Weg-in-die-Unabh-ngigkeit-by-Theo-Lieven.pdf
    • http://kiteeearpdf.myhome.cx/2f215f216f216f218f214/The-Twentieth-Train-The-True-Story-of-the-Ambush-of-the-Death-Train-to-Auschwitz-by-Marion-Schreiber.pdf
    • http://kiteeearpdf.myhome.cx/9f214f219f212f215f217/Familienurlaub-k-nnte-so-sch-n-sein-wenn-blo-Mutter-nicht-mit-dabei-w-re-Frieder-Bergmann-taucht-mit-seiner-Familie-im-Urlaub-im-Bunker-ab-oder-Einmal-endg-ltig-Feierabend-sein-by-J-rn-Kolder.pdf