Malicious PDF — malware analysis report

Static analysis result for SHA-256 0f3c556b64cb17df…

MALICIOUS

PDF

16.8 KB Created: 2019-05-02 05:47:18 +01:00 Authoring application: mPDF 5.7
MD5: 906bdced0f86a65f19760da1bdf9a1ec SHA-1: 09f378b3d0a5ad7826d58ffcc112feda358fa303 SHA-256: 0f3c556b64cb17dfe19d1726338a29919678ec7994eb2b901c0e35e6405d662d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file exhibits a critical heuristic for a link farm, containing 32 external links, many of which point to other PDFs. The ML classifier also flagged it as malicious with high confidence. The embedded URLs suggest a potential attempt to distribute further malicious content or engage in SEO manipulation. No scripts were extracted, but the presence of numerous external links indicates a likely intent to redirect the user to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/1f216f213f215f215f218/Mars-Life-The-Grand-Tour-17-by-Ben-Bova.pdf
    • http://kiteeearpdf.myhome.cx/2f212f216f211f210f219/Farside-The-Grand-Tour-20-by-Ben-Bova.pdf
    • http://kiteeearpdf.myhome.cx/5f213f212f215f216f218/Powersat-The-Grand-Tour-1-by-Ben-Bova.pdf
    • http://kiteeearpdf.myhome.cx/3f218f219f219f216f214/The-Callahan-Kids-Tales-of-Life-on-Mars-by-Ben-Bova.pdf
    • http://kiteeearpdf.myhome.cx/3f215f218f215f215f211/Not-So-Fast-A-Grand-Tour-of-Europe-at-a-Mid-Life-Pace-by-Phebe-Hanson.pdf
    • http://kiteeearpdf.myhome.cx/1f218f212f212f219f211/Mars-by-Ben-Bova.pdf
    • http://kiteeearpdf.myhome.cx/4f210f218f215f211f219/The-Duke-s-Governess-Bride-Grand-Passion-on-the-Grand-Tour-3-by-Miranda-Jarrett.pdf
    • http://kiteeearpdf.myhome.cx/2f211f211f217f215/Seduction-of-an-English-Beauty-Grand-Passion-on-the-Grand-Tour-2-by-Miranda-Jarrett.pdf
    • http://kiteeearpdf.myhome.cx/1f216f213f217f213f213/The-Collected-John-Carter-of-Mars-A-Princess-of-Mars-The-Gods-of-Mars-The-Warlord-of-Mars-Barsoom-1-3-by-Edgar-Rice-Burroughs.pdf
    • http://kiteeearpdf.myhome.cx/6f217f216f218f214f214/Mars-Planet-Marsmeteorit-Mars-Trojaner-Darischer-Kalender-Mars-to-Stay-Marskolonisation-Bemannter-Marsflug-Mars-500-Phobos-by-Quelle-Wikipedia.pdf
    • http://kiteeearpdf.myhome.cx/2f219f215f213f212f217/The-Grand-Tour-by-Adam-O-39-Fallon-Price.pdf
    • http://kiteeearpdf.myhome.cx/5f211f213f212f217f219/George-s-Grand-Tour-by-Caroline-Vermalle.pdf
    • http://kiteeearpdf.myhome.cx/5f213f212f215f219f218/The-Grand-Tour-by-Adam-O-39-Fallon-Price.pdf
    • http://kiteeearpdf.myhome.cx/1f210f212f218f219f216f212/Paddington-and-the-Grand-Tour-by-Michael-Bond.pdf
    • http://kiteeearpdf.myhome.cx/2f211f212f216f217f211/The-Grand-Tour-Cecelia-and-Kate-2-by-Patricia-C-Wrede.pdf
    • http://kiteeearpdf.myhome.cx/1f212f218f210f212f216/Glamorous-Illusions-Grand-Tour-1-by-Lisa-Tawn-Bergren.pdf
    • http://kiteeearpdf.myhome.cx/1f212f215f210f213f213/Glittering-Promises-Grand-Tour-3-by-Lisa-Tawn-Bergren.pdf
    • http://kiteeearpdf.myhome.cx/3f214f213f216f217f214/The-English-Country-House-A-Grand-Tour-by-Gervase-Jackson-Stops.pdf
    • http://kiteeearpdf.myhome.cx/1f215f219f218f213f210/Red-Mars-Green-Mars-Mars-Trilogy-1-2-by-Kim-Stanley-Robinson.pdf
    • http://kiteeearpdf.myhome.cx/6f211f214f211f218f215/The-Best-of-Bova-Volume-1-by-Ben-Bova.pdf