Malicious PDF — malware analysis report

Static analysis result for SHA-256 385ccd4c7322a386…

MALICIOUS

PDF

16.3 KB Created: 2019-05-01 18:46:33 +01:00 Authoring application: mPDF 5.7
MD5: 2628f45107d6b59f93e54ac19e499967 SHA-1: 9f960e72b14f0df140c92f06b8c52875504c07dd SHA-256: 385ccd4c7322a386dbe97d2f08964f18eafde284a0170a8653fb30728b0ca51a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to external PDF files. These links are likely part of an SEO poisoning or link farm strategy to drive traffic to potentially malicious content. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of this document. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/8f217f211f218f219f217/The-Complete-Peanuts-Vol-20-1989-1990-by-Charles-M-Schulz.pdf
    • http://kiteeearpdf.myhome.cx/1f211f211f218f210f212f210/The-Complete-Peanuts-1955-1958-by-Charles-M-Schulz.pdf
    • http://kiteeearpdf.myhome.cx/8f217f211f218f219f212/The-Complete-Peanuts-Vol-19-1987-1988-by-Charles-M-Schulz.pdf
    • http://kiteeearpdf.myhome.cx/8f217f211f219f210f212/The-Complete-Peanuts-Vol-16-1981-1982-by-Charles-M-Schulz.pdf
    • http://kiteeearpdf.myhome.cx/6f212f212f217f212f214/The-Complete-Peanuts-1971-1974-by-Charles-M-Schulz.pdf
    • http://kiteeearpdf.myhome.cx/2f219f217f214f219f217/The-Complete-Peanuts-Vol-6-1961-1962-by-Charles-M-Schulz.pdf
    • http://kiteeearpdf.myhome.cx/6f212f212f217f211f219/The-Complete-Peanuts-Vol-12-1973-1974-by-Charles-M-Schulz.pdf
    • http://kiteeearpdf.myhome.cx/2f219f214f216f215f210/The-Complete-Peanuts-Vol-17-1983-1984-by-Charles-M-Schulz.pdf
    • http://kiteeearpdf.myhome.cx/4f216f210f215f217f213/The-Complete-Peanuts-Vol-18-1985-1986-by-Charles-M-Schulz.pdf
    • http://kiteeearpdf.myhome.cx/6f210f210f211f215/The-Complete-Peanuts-Vol-4-1957-1958-by-Charles-M-Schulz.pdf
    • http://kiteeearpdf.myhome.cx/2f213f219f211f215/Peanuts-The-Art-of-Charles-M-Schulz-by-Chip-Kidd.pdf
    • http://kiteeearpdf.myhome.cx/2f214f211f219f210/Only-What-s-Necessary-Charles-M-Schulz-and-the-Art-of-Peanuts-by-Chip-Kidd.pdf
    • http://kiteeearpdf.myhome.cx/2f213f213f214f213f213/Charlie-Brown-and-Snoopy-Peanuts-Coronet-25-by-Charles-M-Schulz.pdf
    • http://kiteeearpdf.myhome.cx/5f215f214f218f211f211/Woodstock-Master-of-Disguise-PEANUTS-AMP-Series-Book-4-by-Charles-M-Schulz.pdf
    • http://kiteeearpdf.myhome.cx/8f217f211f218f219f210/Peanuts-Guide-to-Life-Wit-and-Wisdom-from-the-World-s-Best-Loved-Cartoon-Characters-by-Charles-M-Schulz.pdf
    • http://kiteeearpdf.myhome.cx/2f219f217f214f214f211/Peanuts-2000-The-50th-Year-of-the-World-s-Favorite-Comic-Strip-by-Charles-M-Schulz.pdf
    • http://kiteeearpdf.myhome.cx/8f217f211f218f216f211/Charlie-Brown-and-Charles-Schulz-by-Charles-M-Schulz.pdf
    • http://kiteeearpdf.myhome.cx/1f211f214f211f219f218f218/Standard-Lesson-Commentary-1989-1990-by-Jim-Fehl.pdf
    • http://kiteeearpdf.myhome.cx/1f210f217f218f218f216f211/Berlin-Journal-1989-1990-by-Robert-Darnton.pdf
    • http://kiteeearpdf.myhome.cx/8f217f211f216f211f215/Schulz-s-Youth-by-Charles-M-Schulz.pdf