Malicious PDF — malware analysis report

Static analysis result for SHA-256 30d4c204f53d224d…

MALICIOUS

PDF

17.5 KB Created: 2019-05-02 05:07:59 +01:00 Authoring application: mPDF 5.7
MD5: f4776e12ba879609a1481050245ca9e9 SHA-1: 3dd99cb92f18d27cebdca3ff3a26b23ebe0ed75b SHA-256: 30d4c204f53d224d08f09cf189f264678c36d3362cc2da9383e92b8918951d38
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links pointing to external PDF files hosted on the suspicious domain 'kiteeearpdf.myhome.cx'. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/6f216f217f214f212f214/Gard-Gemeente-in-Gard-Kanton-Van-Gard-Plaats-in-Gard-Spoorwegstation-in-Gard-Lijst-Van-Gemeenten-in-Het-Departement-Gard-Nimes-by-Bron-Wikipedia.pdf
    • http://kiteeearpdf.myhome.cx/5f210f211f218f218f219/The-Chisholm-Trail-Trail-Drive-03-by-Ralph-Compton.pdf
    • http://kiteeearpdf.myhome.cx/6f216f217f214f219f215/Sam-Bass-by-Wayne-Gard.pdf
    • http://kiteeearpdf.myhome.cx/4f212f215f211f213f210/John-Wayne-My-Life-With-the-Duke-by-Pilar-Wayne.pdf
    • http://kiteeearpdf.myhome.cx/7f215f219f218f215f216/Riding-the-Hollywood-Trail-II-Blazing-the-Early-Television-Trail-by-Charlie-LeSueur.pdf
    • http://kiteeearpdf.myhome.cx/4f219f219f218f211f213/The-Oregon-Trail-Romance-Collection-9-Stories-of-Life-on-the-Trail-into-the-Western-Frontier-by-Amanda-Cabot.pdf
    • http://kiteeearpdf.myhome.cx/1f218f211f217f215/Trail-of-Hope-Story-of-the-Mormon-Trail-by-William-W-Slaughter.pdf
    • http://kiteeearpdf.myhome.cx/6f214f215f216f213f217/Trail-of-Dreams-Hot-on-the-Trail-4-by-Merry-Farmer.pdf
    • http://kiteeearpdf.myhome.cx/3f215f212f216f213f213/Trail-of-Kisses-Hot-on-the-Trail-1-by-Merry-Farmer.pdf
    • http://kiteeearpdf.myhome.cx/6f214f215f215f219f215/Trail-of-Longing-Hot-on-the-Trail-3-by-Merry-Farmer.pdf
    • http://kiteeearpdf.myhome.cx/5f210f212f218f213f215/A-Famine-of-Horses-by-P-F-Chisholm.pdf
    • http://kiteeearpdf.myhome.cx/7f217f216f215f210f210/Jocelyn-by-Gloria-Chisholm.pdf
    • http://kiteeearpdf.myhome.cx/4f211f210f216f215f219/A-Surfeit-of-Guns-Sir-Robert-Carey-3-by-P-F-Chisholm.pdf
    • http://kiteeearpdf.myhome.cx/7f217f216f215f215f215/Stampeded-Whitehorse-MT-Chisholm-Cattle-Co-4-by-B-J-Daniels.pdf
    • http://kiteeearpdf.myhome.cx/7f217f216f215f215f213/Lassoed-Whitehorse-MT-Chisholm-Cattle-Co-2-by-B-J-Daniels.pdf
    • http://kiteeearpdf.myhome.cx/1f211f210f215f216f217f219/Georgiana-Darcy-Matchmaker-by-Bronwen-Chisholm.pdf
    • http://kiteeearpdf.myhome.cx/7f217f216f215f215f217/Wrangled-Whitehorse-MT-Chisholm-Cattle-Co-6-by-B-J-Daniels.pdf
    • http://kiteeearpdf.myhome.cx/7f217f216f215f215f216/Corralled-Whitehorse-MT-Chisholm-Cattle-Co-5-by-B-J-Daniels.pdf
    • http://kiteeearpdf.myhome.cx/4f218f218f212f211f211/A-Plague-of-Angels-Sir-Robert-Carey-4-by-P-F-Chisholm.pdf
    • http://kiteeearpdf.myhome.cx/5f211f217f219f217f217/Shirley-Chisholm-Teacher-And-Congresswoman-by-Catherine-Scheader.pdf
    • http://kiteeearpdf.myhome.cx/4f219f219f218f211f213/The-Oregon-Trail-Romance-Collection-9-Stories-of-Life-on-the-