Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a297d23055c0fe1…

MALICIOUS

PDF

17.3 KB Created: 2020-03-19 20:57:59 +00:00 Authoring application: mPDF 5.7
MD5: ded39822e048c925704ecfc37eefaa64 SHA-1: 4156b7863d00d2e1ca58d4a59a27ab0e63e7e027 SHA-256: 2a297d23055c0fe153f7f3b9b6d37c779f9e2ff7b0a3f1616124e8aa66fb98dc
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to a domain that appears to be used for SEO poisoning or distributing malicious content. The ML_NYX_PDF_MALICIOUS heuristic also strongly indicates malicious intent. The document body itself is heavily obfuscated and contains many of the same URLs, reinforcing the link-farming attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kitasdyu.myhome.cx/1870875878875878879/Someone-s-in-the-Kitchen-with-Dinah-by-Barbara-Pearson-Arau.pdf
    • http://kitasdyu.myhome.cx/8872878875871871/The-Goddesses-of-Kitchen-Avenue-by-Barbara-Samuel.pdf
    • http://kitasdyu.myhome.cx/3876878871876878/Slowing-Time-Seeing-the-Sacred-Outside-Your-Kitchen-Door-by-Barbara-Mahany.pdf
    • http://kitasdyu.myhome.cx/4879875874875870/Dinah-s-Dark-Desire-Dinah-s-Desire-1-by-Mechele-Armstrong.pdf
    • http://kitasdyu.myhome.cx/1870875878874877874/Dinah-Jefferies-3-Book-Collection-by-Dinah-Jefferies.pdf
    • http://kitasdyu.myhome.cx/1870873879870877879/The-Stress-Free-Diabetes-Kitchen-Over-150-Easy-and-Delicious-Diabetes-Recipes-Designed-for-No-Hassle-Cooking-by-Barbara-Seelig-Brown.pdf
    • http://kitasdyu.myhome.cx/1871877873870877874/Marie-Claire-Seasonal-Kitchen-Seasonal-Kitchen-Inspired-Recipes-And-Food-Ideas-by-Michele-Cranston.pdf
    • http://kitasdyu.myhome.cx/1870875878874877878/Dinah-s-Egg-by-Lee-Lorenz.pdf
    • http://kitasdyu.myhome.cx/2875878878877875/The-Complete-America-s-Test-Kitchen-TV-Show-Cookbook-2001-2010-by-America-39-s-Test-Kitchen.pdf
    • http://kitasdyu.myhome.cx/1870875878872878875/Before-the-Rains-by-Dinah-Jefferies.pdf
    • http://kitasdyu.myhome.cx/1870875878873877879/Touchstone-by-Dinah-McCall.pdf
    • http://kitasdyu.myhome.cx/1870875878873877872/Dinah-by-Bruce-Cassiday.pdf
    • http://kitasdyu.myhome.cx/1870875878875879877/Dinah-and-Virginia-by-Priscilla-C-Hallowell.pdf
    • http://kitasdyu.myhome.cx/1873877876873/Dinah-in-Love-by-Claudia-Mills.pdf
    • http://kitasdyu.myhome.cx/2874874876872873/The-King-s-Women-by-Dinah-Lampitt.pdf
    • http://kitasdyu.myhome.cx/1870875878873877878/Windwalker-The-Prophecy-1-by-Dinah-McCall.pdf
    • http://kitasdyu.myhome.cx/1872877871879/Jackson-Rule-by-Dinah-McCall.pdf
    • http://kitasdyu.myhome.cx/1873874870877877/Flight-from-the-Eagle-by-Dinah-Dean.pdf
    • http://kitasdyu.myhome.cx/3870876874875873/Left-in-the-Care-of-by-Dinah-Lee-K-ng.pdf
    • http://kitasdyu.myhome.cx/1875878873876871/The-Tea-Planter-s-Wife-by-Dinah-Jefferies.pdf
    • http://kitasdyu.myhome.cx/1870873879870877879/The-Stress-Free-Diabetes-Kit