Malicious PDF — malware analysis report

Static analysis result for SHA-256 2d4c31c1ec191117…

MALICIOUS

PDF

19.9 KB Created: 2019-05-02 17:43:52 +01:00 Authoring application: mPDF 5.7
MD5: 66b1fc291d1ade113e77e68e34fb161f SHA-1: bbc2b9d16402db6b2a6a808f4e22a428dcd1be13 SHA-256: 2d4c31c1ec1911177d1ff204e552a3c3b611b020534128b01fe3dadac43180f3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, consistent with a link farm or SEO poisoning attack. The primary heuristic identified a PDF_SEO_LINK_FARM, indicating the document's purpose is to host numerous links to other PDFs, likely for malicious redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/4f214f211f219f211f214/Runway-RunAway-A-Backstage-Pass-to-Fashion-Romance-amp-Rock-N-Roll-by-Lorelei-Shellist.pdf
    • http://kiteeearpdf.myhome.cx/1f213f215f211f212f212/Backstage-Pass-On-Tour-The-Backstage-Pass-Rock-Star-Romance-5-by-Elizabeth-Nelson.pdf
    • http://kiteeearpdf.myhome.cx/4f214f213f217f212f213/Backstage-Passes-An-Anthology-of-Rock-and-Roll-Erotica-from-the-Pages-of-Blue-Blood-by-Amelia-G.pdf
    • http://kiteeearpdf.myhome.cx/4f214f211f218f216f217/The-First-Rock-amp-Roll-Confidential-Report-Inside-the-Real-World-of-Rock-and-Roll-by-Dave-Marsh.pdf
    • http://kiteeearpdf.myhome.cx/2f211f213f217f219f212/Rock-and-Roll-Never-Forgets-Rock-and-Roll-Trilogy-1-by-Barbara-S-Stewart.pdf
    • http://kiteeearpdf.myhome.cx/6f219f211f212f219/Rock-and-Roll-Never-Forgets-Rock-and-Roll-Trilogy-1-by-Barbara-S-Stewart.pdf
    • http://kiteeearpdf.myhome.cx/7f215f218f212f213/Rock-n-Roll-Promises-Rock-n-Roll-Paraphantasy-1-by-AmBear-Shellea.pdf
    • http://kiteeearpdf.myhome.cx/3f214f210f215f214f217/Backstage-Pass-by-Gaby-Triana.pdf
    • http://kiteeearpdf.myhome.cx/1f210f219f210f218f214f218/Project-Runway-The-Show-That-Changed-Fashion-by-Eila-Mell.pdf
    • http://kiteeearpdf.myhome.cx/4f215f211f219f212f213/Anya-and-the-Shy-Guy-Backstage-Pass-4-by-Suze-Winegardner.pdf
    • http://kiteeearpdf.myhome.cx/3f214f210f219f211/Backstage-Pass-Sinners-on-Tour-1-by-Olivia-Cunning.pdf
    • http://kiteeearpdf.myhome.cx/1f218f211f210f217f212/Backstage-Pass-Sinners-on-Tour-1-by-Olivia-Cunning.pdf
    • http://kiteeearpdf.myhome.cx/2f213f212f214f212f214/Backstage-Pass-Sinners-on-Tour-1-by-Olivia-Cunning.pdf
    • http://kiteeearpdf.myhome.cx/8f218f217f214f212f217/Hijacking-the-Runway-How-Celebrities-Are-Stealing-the-Spotlight-from-Fashion-Designers-by-Teri-Agins.pdf
    • http://kiteeearpdf.myhome.cx/4f214f211f218f216f216/Life-on-Planet-Rock-From-Guns-N-Roses-to-NIRVana-a-Backstage-Journey-Through-Rock-s-Most-Debauched-Decade-by-Lonn-Friend.pdf
    • http://kiteeearpdf.myhome.cx/4f214f211f218f219f216/Rock-Toons-A-Cartoon-History-of-the-First-30-Years-of-Rock-n-Roll-by-Serge-Dutfoy.pdf
    • http://kiteeearpdf.myhome.cx/4f219f218f212f210f217/Rock-of-Ages-The-Rolling-Stone-History-of-Rock-and-Roll-by-Ed-Ward.pdf
    • http://kiteeearpdf.myhome.cx/4f219f215f217f218f218/Rock-Deadly-Rock-and-Roll-Mysteries-1-by-Kathryn-Lively.pdf
    • http://kiteeearpdf.myhome.cx/5f211f211f210f217f213/--4-Runway-de-Waratte-4-Smile-at-the-runway-4-by-Kotoba-Inoya.pdf
    • http://kiteeearpdf.myhome.cx/5f211f211f210f217f212/--5-Runway-de-Waratte-5-Smile-at-the-runway-5-by-Kotoba-Inoya.pdf
    • http://kiteeearpdf.myhome.cx/6f219f211f212f219/Rock-and-Roll-Never-Forgets-Rock-and-Roll-Trilogy-1-by-Barb