Malicious PDF — malware analysis report

Static analysis result for SHA-256 1fea8160b3e257e4…

MALICIOUS

PDF

22.5 KB Created: 2020-03-13 04:18:07 +00:00 Authoring application: mPDF 5.7
MD5: dc28825fe49eed2394896245fcde4dbc SHA-1: c9ac2cf5d86bd07bec73c0c6e0d184cda0e4dd1c SHA-256: 1fea8160b3e257e4bd6c19055accc69b807aa6a525990b2b1f5eef03c9569194
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded URLs, forming a link farm. These URLs likely lead to malicious content or phishing pages. The presence of numerous external links suggests an attempt to distribute malware or redirect users to fraudulent sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/1f211f218f212f213f219/The-Society-s-Traitor-The-Discoveries-of-Arthur-Grey-1-by-V-K-Finnish.pdf
    • http://kiteeearpdf.myhome.cx/9f216f217f215f215f216/The-Information-Society-and-the-Welfare-State-The-Finnish-Model-by-Manuel-Castells.pdf
    • http://kiteeearpdf.myhome.cx/1f219f213f211f214f219/Seeing-Further-Ideas-Endeavours-Discoveries-and-Disputes-The-Story-of-Science-Through-350-Years-of-the-Royal-Society-by-Bill-Bryson.pdf
    • http://kiteeearpdf.myhome.cx/5f219f210f215f210f215/The-Juliette-Society-Book-II-The-Janus-Chamber-The-Juliette-Society-2-by-Sasha-Grey.pdf
    • http://kiteeearpdf.myhome.cx/1f210f218f218f210f210f212/The-palace-of-Minos-a-comparative-account-of-the-successive-stages-of-the-early-Cretan-civilization-as-illustrated-by-the-discoveries-at-Knossos-by-Arthur-John-Evans.pdf
    • http://kiteeearpdf.myhome.cx/2f212f214f212f215/Ant-Farm-A-Novel-about-What-s-Bugging-Society-by-Stephen-Aaron-Grey.pdf
    • http://kiteeearpdf.myhome.cx/4f213f218f218f217f211/Voyages-and-Discoveries-Principal-Navigations-Voyages-Traffiques-and-Discoveries-of-the-English-Nation-by-Richard-Hakluyt.pdf
    • http://kiteeearpdf.myhome.cx/5f216f214f218/The-Traitor-s-Kiss-The-Traitor-s-Circle-1-by-Erin-Beaty.pdf
    • http://kiteeearpdf.myhome.cx/4f216f214f219f219/The-Disuniting-of-America-Reflections-on-a-Multicultural-Society-by-Arthur-M-Schlesinger-Jr-.pdf
    • http://kiteeearpdf.myhome.cx/7f214f213f214/The-Traitor-s-Game-The-Traitor-s-Game-1-by-Jennifer-A-Nielsen.pdf
    • http://kiteeearpdf.myhome.cx/3f211f219f210f216f214/Finnish-Weird-by-Toni-Jerrman.pdf
    • http://kiteeearpdf.myhome.cx/1f210f211f210f210f219/Grey-Fifty-Shades-of-Grey-as-Told-by-Christian-A-11-Minute-HOOOTTTT-summary-by-Bern-Bolo.pdf
    • http://kiteeearpdf.myhome.cx/8f211f212f211f214f211/The-Rowen-Grey-Omnibus-A-Collection-of-Kinky-Erotic-amp-Romantic-Erotic-Stories-by-Rowen-Grey-by-Rowen-Grey.pdf
    • http://kiteeearpdf.myhome.cx/2f215f215f213f218f219/How-to-Marry-a-Finnish-Girl-by-Phil-Schwarzmann.pdf
    • http://kiteeearpdf.myhome.cx/3f211f211f211f215f218/Natural-Cooking-the-Finnish-Way-by-Ulla-Kakonen.pdf
    • http://kiteeearpdf.myhome.cx/3f218f217f215f218f210/Miriam-Daughter-of-Finnish-Immigrants-by-Diane-Dettmann.pdf
    • http://kiteeearpdf.myhome.cx/8f211f214f217f210f212/It-Came-from-the-North-An-Anthology-of-Finnish-Speculative-Fiction-by-Desirina-Boskovich.pdf
    • http://kiteeearpdf.myhome.cx/3f211f211f215f210f210/Moomins-Cookbook-An-Introduction-to-Finnish-Cuisine-by-Sami-Malila.pdf
    • http://kiteeearpdf.myhome.cx/4f215f212f214f215/The-Opposite-of-Cold-The-Northwoods-Finnish-Sauna-Tradition-by-Michael-Nordskog.pdf
    • http://kiteeearpdf.myhome.cx/9f212f214f219f218f214/Shaping-The-Network-Society-The-New-Role-Of-Civil-Society-In-Cyberspace-by-Douglas-Schuler.pdf
    • http://kiteeearpdf.myhome.cx/1f210f218f218f210f210f212/The-palace-of-Minos-a-comparative-account-of-the-successive-stages-of-the-early-Cretan-civilization-as-illustrated-by-the-disco