Malicious PDF — malware analysis report

Static analysis result for SHA-256 374a7b097a5b55d2…

MALICIOUS

PDF

21.2 KB Created: 2019-05-02 17:18:15 +01:00 Authoring application: mPDF 5.7
MD5: 765e2f5cbc56b4e18c0be820c670eb5f SHA-1: 0f835996c1e83fa7dd459c5d70b1b9d7db51b3fd SHA-256: 374a7b097a5b55d2f07b283af25ca3be9a779c2c7e32b4d0f61377a7a05ae927
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded URLs, forming a link farm. These URLs likely lead to malicious content or phishing pages, suggesting a social engineering attack. No scripts were extracted, but the PDF structure itself is indicative of a malicious distribution method.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9939

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/2f210f216f219f216f215/iCon-Steve-Jobs-the-Greatest-Second-Act-in-the-History-of-Business-by-Jeffrey-S-Young.pdf
    • http://kiteeearpdf.myhome.cx/9f210f213f210f219/Options-The-Secret-Life-of-Steve-Jobs-by-Fake-Steve-Jobs.pdf
    • http://kiteeearpdf.myhome.cx/3f213f210f215f213f217/Steve-Jobs-Book-Things-You-Should-Learn-from-Steve-Jobs-by-Can-Akdeniz.pdf
    • http://kiteeearpdf.myhome.cx/6f214f210f210f213f218/Steve-Jobs-TOP-20-Secrets-In-Life-amp-Business-Edition-2016-The-Essential-Straight-To-The-Point-No-Fluff-by-Alan-Greenwich.pdf
    • http://kiteeearpdf.myhome.cx/4f210f211f217f212f216/Tied-In-The-Business-History-And-Craft-Of-Media-Tie-In-Writing-by-Jeffrey-J-Mariotte.pdf
    • http://kiteeearpdf.myhome.cx/8f218f219f216f219f212/Business-Brilliant-Surprising-Lessons-from-the-Greatest-Self-Made-Business-Icons-by-Lewis-Schiff.pdf
    • http://kiteeearpdf.myhome.cx/8f218f219f217f213f211/Business-Brilliant-Surprising-Lessons-from-the-Greatest-Self-Made-Business-Leaders-about-How-to-Build-Wealth-Manage-Your-Career-and-Take-Risks-by-Lewis-Schiff.pdf
    • http://kiteeearpdf.myhome.cx/6f210f216f216f213f218/Who-Was-Steve-Jobs-by-Pam-Pollack.pdf
    • http://kiteeearpdf.myhome.cx/6f219f219f216f212f212/Steve-Jobs-by-Walter-Isaacson.pdf
    • http://kiteeearpdf.myhome.cx/4f211f210f216f212f210/Steve-Jobs-by-Walter-Isaacson.pdf
    • http://kiteeearpdf.myhome.cx/2f219f214f213f212/Steve-Jobs-by-Walter-Isaacson.pdf
    • http://kiteeearpdf.myhome.cx/9f219f219f215f215f213/Steve-Jobs-Visionen-by-Leander-Kahney.pdf
    • http://kiteeearpdf.myhome.cx/4f214f215f216f219/Steve-Jobs-The-Man-Who-Thought-Different-by-Karen-Blumenthal.pdf
    • http://kiteeearpdf.myhome.cx/1f218f214f216f219f216/Steve-Jobs-The-Unauthorized-Autobiography-by-J-T-Owens.pdf
    • http://kiteeearpdf.myhome.cx/9f210f217f212f214f211/Becoming-Steve-Jobs-Vom-Abenteurer-zum-Vision-r-by-Brent-Schlender.pdf
    • http://kiteeearpdf.myhome.cx/9f212f218f212f218f210/Steve-Jobs-Think-different-die-Welt-anders-denken-by-Karen-Blumenthal.pdf
    • http://kiteeearpdf.myhome.cx/1f211f219f218f215f218f218/Playboy-Interview-Sammler-Edition-Steve-Jobs-by-David-Sheff.pdf
    • http://kiteeearpdf.myhome.cx/6f210f216f217f219/Finding-the-Next-Steve-Jobs-How-to-Find-Hire-Keep-and-Nurture-Creative-Talent-by-Nolan-Bushnell.pdf
    • http://kiteeearpdf.myhome.cx/1f218f214f218f210f213/Return-to-the-Little-Kingdom-Steve-Jobs-the-Creation-of-Apple-and-How-It-Changed-the-World-by-Michael-Moritz.pdf
    • http://kiteeearpdf.myhome.cx/1f210f212f219f216f215/iWoz-Computer-Geek-to-Cult-Icon-How-I-Invented-the-Personal-Computer-Co-Founded-Apple-and-Had-Fun-Doing-It-by-Steve-Wozniak.pdf