Malicious PDF — malware analysis report

Static analysis result for SHA-256 3760f45e155ecac8…

MALICIOUS

PDF

21.5 KB Created: 2019-05-02 02:18:43 +01:00 Authoring application: mPDF 5.7
MD5: 2dccf16fc24a650522b0dd0911ee0551 SHA-1: dc1e36af505f03409d6a922e01be18c365e12f61 SHA-256: 3760f45e155ecac8972cd41344939ffa108c9bb4430dee44700de7f13a8c75df
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier and contains a large number of embedded URLs, indicating a link farm designed to redirect users. The heuristic 'PDF_SEO_LINK_FARM' specifically calls out the mass external PDF link farm. The primary attack pattern involves luring users to potentially malicious websites through these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9900

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/1f211f219f215f212f218/Grave-Robber-for-Hire-Grave-Robber-Series-1-by-Cassandra-L-Shaw.pdf
    • http://kiteeearpdf.myhome.cx/7f216f218f211f210f219/Grave-Importance-Dr-Greta-Helsing-3-by-Vivian-Shaw.pdf
    • http://kiteeearpdf.myhome.cx/1f218f218f216f214f216/Grave-Intentions-Grave-1-by-Lori-Sjoberg.pdf
    • http://kiteeearpdf.myhome.cx/1f214f217f217f210f215/The-Robber-and-Me-by-Josef-Holub.pdf
    • http://kiteeearpdf.myhome.cx/1f216f212f216f213f213/The-Pious-Robber-by-Harriet-Richards.pdf
    • http://kiteeearpdf.myhome.cx/4f210f214f218f217f217/The-Robber-Bride-by-Margaret-Atwood.pdf
    • http://kiteeearpdf.myhome.cx/4f219f214f213f218f216/Sea-Robber-Hector-Lynch-3-by-Tim-Severin.pdf
    • http://kiteeearpdf.myhome.cx/9f218f217f217f217f210/The-Robber-Bride-by-Margaret-Atwood.pdf
    • http://kiteeearpdf.myhome.cx/1f211f213f218f212f212f216/Death-of-a-Robber-Baron-by-Charles-O-39-Brien.pdf
    • http://kiteeearpdf.myhome.cx/4f217f215f211f219f218/Robber-Bride-The-de-Burghs-3-by-Deborah-Simmons.pdf
    • http://kiteeearpdf.myhome.cx/9f211f215f211f213f217/Further-Adventures-of-the-Robber-Hotzenplotz-Knight-Books-by-Otfried-Preu-ler.pdf
    • http://kiteeearpdf.myhome.cx/6f212f210f217f212f216/The-Swamp-Robber-Sugar-Creek-Gang-1-by-Paul-Hutchens.pdf
    • http://kiteeearpdf.myhome.cx/3f213f215f211f212f218/The-Man-Who-Outgrew-His-Prison-Cell-Confessions-of-a-Bank-Robber-by-Joe-Loya.pdf
    • http://kiteeearpdf.myhome.cx/4f210f212f210f211f216/Gentleman-Train-Robber-The-Daring-Escapades-of-Bill-Miner-by-Stan-Sauerwein.pdf
    • http://kiteeearpdf.myhome.cx/2f212f217f215f212/Wanted-Gentleman-Bank-Robber-The-True-Story-of-Leslie-Ibsen-Rogge-One-of-the-FBI-s-Most-Elusive-Criminals-by-Dane-Batty.pdf
    • http://kiteeearpdf.myhome.cx/1f216f219f217f219/Ballad-of-the-Whiskey-Robber-A-True-Story-of-Bank-Heists-Ice-Hockey-Transylvanian-Pelt-Smuggling-Moonlighting-Detectives-and-Broken-Hearts-by-Julian-Rubinstein.pdf
    • http://kiteeearpdf.myhome.cx/3f213f214f218f216f211/Ballad-of-the-Whiskey-Robber-A-True-Story-of-Bank-Heists-Ice-Hockey-Transylvanian-Pelt-Smuggling-Moonlighting-Detectives-and-Broken-Hearts-by-Julian-Rubinstein.pdf
    • http://kiteeearpdf.myhome.cx/1f210f213f217f210f216f219/Articles-on-Swedish-Children-s-Literature-Including-Pippi-Longstocking-Ronia-the-Robber-s-Daughter-Karlsson-On-The-Roof-Bill-Bergson-the-Brothers-Lionheart-Mio-My-Son-Agaton-Sax-Emil-I-Lanneberga-Most-Beloved-Sister-Madicken-by-Hephaestus-Books.pdf
    • http://kiteeearpdf.myhome.cx/1f210f219f210f216f213f211/Psychopath-for-Hire-by-Matt-Shaw.pdf
    • http://kiteeearpdf.myhome.cx/2f217f212f210f210f218/Lives-for-Hire-Series-Book-1---Lives-For-Hire-by-Brianna-Bunn.pdf
    • http://kiteeearp