Malicious PDF — malware analysis report

Static analysis result for SHA-256 3554b9b634a61ec9…

MALICIOUS

PDF

25.8 KB Created: 2019-05-02 17:44:48 +01:00 Authoring application: mPDF 5.7
MD5: 4e4aea7941f07777f2574c3efd7356b2 SHA-1: 0734a27c7d6c6f9428d623abba288e052688d9be SHA-256: 3554b9b634a61ec94fb5ddb465feabb0511bd49f322682b0ed86861a8628df57
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'kiteeearpdf.myhome.cx'. This domain and the structure of the links suggest a link farm or SEO poisoning attack, designed to drive traffic to potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9896

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/8f214f211f218f210f210/Did-God-Kill-Jesus-Searching-for-Love-in-History-s-Most-Famous-Execution-by-Tony-Jones.pdf
    • http://kiteeearpdf.myhome.cx/2f217f210f214f212f215/Searching-for-Jesus-New-Discoveries-in-the-Quest-for-Jesus-of-Nazareth-and-How-They-Confirm-the-Gospel-Accounts-by-Robert-J-Hutchinson.pdf
    • http://kiteeearpdf.myhome.cx/4f213f217f213f213f218/Searching-for-the-Queen-s-Cowboys-by-Tony-Maxwell.pdf
    • http://kiteeearpdf.myhome.cx/4f218f213f217f214f218/Famous-in-Love-Famous-in-Love-1-by-Rebecca-Serle.pdf
    • http://kiteeearpdf.myhome.cx/1f218f210f214f219f214/Famous-in-Love-Famous-in-Love-1-by-Rebecca-Serle.pdf
    • http://kiteeearpdf.myhome.cx/8f214f211f218f217f217/Execution-A-History-of-Capital-Punishment-in-Britain-by-Simon-Webb.pdf
    • http://kiteeearpdf.myhome.cx/4f212f214f217f215f215/Is-Jesus-a-Republican-or-a-Democrat-And-14-Other-Polarizing-Issues-by-Tony-Campolo.pdf
    • http://kiteeearpdf.myhome.cx/2f212f219f210f218f213/The-History-of-Torture-and-Execution-From-Early-Civilization-through-Medieval-Times-to-the-Present-by-Jean-Kellaway.pdf
    • http://kiteeearpdf.myhome.cx/6f214f210f213f212/Big-AI-Jesus-and-Mo-4-by-Mohammed-Jones.pdf
    • http://kiteeearpdf.myhome.cx/1f210f219f216f214f217f217/The-Love-Teachings-of-Kama-Sutra-With-Extracts-from-Koka-Shastra-Anaga-Ranga-and-Other-Famous-Indian-Works-on-Love-by-Mallanaga-V-tsy-yana.pdf
    • http://kiteeearpdf.myhome.cx/6f215f212f212f217f214/The-Mammoth-Book-of-Women-Who-Kill-by-Richard-Glyn-Jones.pdf
    • http://kiteeearpdf.myhome.cx/9f216f213f216f216f217/Seeing-Jesus-by-Jeffrey-McClain-Jones.pdf
    • http://kiteeearpdf.myhome.cx/7f216f215f214f218f213/Scaramouche-by-Rafael-Sabatini-The-days-before-the-terror-Plus-The-Necklace-by-Guy-de-Maupssant-The-Midshipman-Escape-from-the-shark-Golden-Age-Famous-Stories-by-Famous-Authors-Illustrated-by-Golden-Age-Famous-Stories.pdf
    • http://kiteeearpdf.myhome.cx/4f211f217f213f212/Searching-for-Perfect-Searching-For-2-by-Jennifer-Probst.pdf
    • http://kiteeearpdf.myhome.cx/9f212f217/Searching-for-Beautiful-Searching-For-3-by-Jennifer-Probst.pdf
    • http://kiteeearpdf.myhome.cx/4f216f215f219f215f216/Searching-Love-Saints-Protection-amp-Investigations-11-by-Maryann-Jordan.pdf
    • http://kiteeearpdf.myhome.cx/5f215f216f218f215f213/The-History-of-the-Life-of-Our-Lord-Jesus-Christ-From-His-Incarnation-Until-His-Ascension-Denoting-and-Incorporating-the-Words-of-the-Sacred-Text-from-the-Vulgate-Also-the-History-of-the-Acts-of-the-Apostles-Connected-Explained-and-Blended-with-Refl-by-Francois-De-Ligny.pdf
    • http://kiteeearpdf.myhome.cx/3f216f219f218f212f218/Jesus-CEO-Using-Ancient-Wisdom-for-Visionary-Leadership-by-Laurie-Beth-Jones.pdf
    • http://kiteeearpdf.myhome.cx/8f210f216f216f214f215/A-Love-Worth-Searching-For-Oregon-Trail-Dreamin-Book-3-by-Kathleen-Ball.pdf
    • http://kiteeearpdf.myhome.cx/2f210f210f211f210f211/Robert-Love-s-Warnings-Searching-for-Strangers-in-Colonial-Boston-by-Cornelia-H-Dayton.pdf
    • http://kiteeearpdf.myhome.cx/2f212f219f210f218f213/The-History-of-Torture-and-Execution-From-Early-Civilization-through-Medieval-Times-to-the-Pr