Malicious PDF — malware analysis report

Static analysis result for SHA-256 1f26a2015ef41627…

MALICIOUS

PDF

16.8 KB Created: 2019-05-03 06:01:12 +01:00 Authoring application: mPDF 5.7
MD5: 7ce4c3a20f4a432cbbca4cc3561b7edf SHA-1: 48f313e666bd7e8c5382f2d14f4a63535bf23f7e SHA-256: 1f26a2015ef41627d0247d03ed3703f22717a00978bf50f3406f465df7b80e40
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to external PDF files hosted on kiteeearpdf.myhome.cx, suggesting a link farm or redirection scheme. The ML_NYX_PDF_MALICIOUS heuristic also flagged this document with high confidence. No scripts were extracted from this sample. The primary attack pattern appears to be social engineering through a deceptive link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/4f217f215f213f210f212/Steelheart-by-Kathryn-Le-Veque.pdf
    • http://kiteeearpdf.myhome.cx/3f215f212f212f218f215/Devil-s-Dominion-by-Kathryn-Le-Veque.pdf
    • http://kiteeearpdf.myhome.cx/4f217f215f211f212f217/Great-Protector-by-Kathryn-Le-Veque.pdf
    • http://kiteeearpdf.myhome.cx/8f216f210f211f212f216/Valiant-Chaos-by-Kathryn-Le-Veque.pdf
    • http://kiteeearpdf.myhome.cx/4f219f214f211f217f214/The-Dark-Lord-Titans-1-by-Kathryn-Le-Veque.pdf
    • http://kiteeearpdf.myhome.cx/3f219f219f216f213f215/Shadowmoor-de-Lohr-Dynasty-7-by-Kathryn-Le-Veque.pdf
    • http://kiteeearpdf.myhome.cx/5f215f217f210f219f214/Vestiges-of-Valor-House-of-de-Nerra-1-by-Kathryn-Le-Veque.pdf
    • http://kiteeearpdf.myhome.cx/3f219f216f219f218f218/Island-of-Glass-Dragonblade-Trilogy-2-by-Kathryn-Le-Veque.pdf
    • http://kiteeearpdf.myhome.cx/2f219f217f215f212f212/The-Darkland-The-Master-Knights-Of-Connaught-1-by-Kathryn-Le-Veque.pdf
    • http://kiteeearpdf.myhome.cx/2f217f212f214f212f212/Lord-of-War-Black-Angel-De-Russe-Legacy-1-by-Kathryn-Le-Veque.pdf
    • http://kiteeearpdf.myhome.cx/1f211f217f218f216f212f215/The-Iron-Knight-The-De-Russe-Legacy-Book-3-by-Kathryn-Le-Veque.pdf
    • http://kiteeearpdf.myhome.cx/1f211f212f215f211f216f213/Deep-Into-Darkness-The-Lore-Chronicles-2-Highland-Warriors-of-Munro-2-by-Kathryn-Le-Veque.pdf
    • http://kiteeearpdf.myhome.cx/4f212f213f210f218f213/The-Thunder-Knight-Book-Three-in-the-Lords-of-Thunder-The-de-Shera-Brotherhood-Trilogy-by-Kathryn-Le-Veque.pdf
    • http://kiteeearpdf.myhome.cx/2f210f214f216f213f215/Nighthawk-Sons-of-de-Wolfe-de-Wolfe-Pack-7-by-Kathryn-Le-Veque.pdf
    • http://kiteeearpdf.myhome.cx/3f219f216f219f219f210/Dragonblade-Dragonblade-Trilogy-1-by-Kathryn-Le-Veque.pdf
    • http://kiteeearpdf.myhome.cx/3f218f213f212f213f212/The-Hearts-We-Mend-Banister-Falls-2-by-Kathryn-Springer.pdf
    • http://kiteeearpdf.myhome.cx/2f213f213f217f218f214/The-Hearts-We-Mend-Banister-Falls-2-by-Kathryn-Springer.pdf
    • http://kiteeearpdf.myhome.cx/4f217f210f215f216f213/Love-in-Carson-Falls-The-Falls-Series-Book-1-by-Paisleigh-Aumack.pdf
    • http://kiteeearpdf.myhome.cx/6f217f219f214f212/Obsession-Falls-Virtue-Falls-2-by-Christina-Dodd.pdf
    • http://kiteeearpdf.myhome.cx/8f218f215f217f218f212/Home-to-Wickham-Falls-Wickham-Falls-Weddings-1-by-Rochelle-Alers.pdf