Malicious PDF — malware analysis report

Static analysis result for SHA-256 41d3ad73310ec1a7…

MALICIOUS

PDF

22.8 KB Created: 2020-03-14 23:13:15 +00:00 Authoring application: mPDF 5.7
MD5: 84ec77d33a379d1194dbce1b56318767 SHA-1: 4527e9ef55f443e5f326cf5c76d15a0023055540 SHA-256: 41d3ad73310ec1a7b89b16a041e56be1c9f363859b8ddc69fbcfe31d577f8a3f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute further malicious content. The domain 'kiteeearpdf.myhome.cx' is highly suspicious and associated with a link farm. No scripts were extracted, and the document body was heavily obfuscated, but the heuristic firings strongly indicate a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/9f218f210f217f217/Oakshot-Complete-Works-of-Jane-Austen-Illustrated-Inline-Footnotes-Classics-Book-7-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/7f213f211f219f214f214/Sense-and-Sensibility-jane-austen-book-club-Illustrated-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/5f216f218f216f216f217/Emma-by-Jane-Austen-Fiction-Classics-Romance-Historical-Literary-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/5f215f210f219f219f219/Mansfield-Park-By-Jane-Austen-Illustrated---Original-amp-Unabridged-Free-Audiobook-Inside-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/5f212f219f213f214f215/Jane-Austen---Emma-Vollst-ndige-deutsche-Ausgabe-IDP-Classics-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/5f219f213f213f218f212/Sense-and-Sensibility-By-Jane-Austen-Illustrated-amp-Unabridged-Free-Bonus-Audiobook-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/5f218f217f219f215f214/Sense-and-Sensibility-By-Jane-Austen---Illustrated-And-Unabridged-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/5f210f212f213f215f214/The-Oxford-Illustrated-Jane-Austen-6-Volume-Set-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/5f214f210f219f217f218/Persuasion-Golden-Illustrated-Classics-Comes-with-a-Free-Audiobook-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/5f214f213f212f212f213/The-Complete-Novels-of-Jane-Austen-Volume-One-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/3f212f217f219f210f210/Jane-Austen-Complete-Novels-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/1f211f217f216f219f213f217/Jane-Austen-Collection-Seven-Novels-in-One-Pride-and-Prejudice-Persuasion-Mansfield-Park-Northanger-Abbey-Sense-and-Sensibility-Emma-Lady-Susan-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/1f211f217f216f219f212f218/Jane-Austen-Pride-and-Prejudice---Northanger-Abbey---Persuasion-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/5f215f218f214f216f215/The-Novels-of-Jane-Austen-Northanger-Abbey-In-Ten-Volumes-Vol-IX-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/1f210f216f213f212f210f218/Sense-and-Sensibility-With-an-Excerpt-from-Jane-and-Me-My-Austen-Heritage-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/1f211f217f217f211f210f216/NORTHANGER-ABBEY---JANE-AUSTEN-Author-of-Mansfield-Park-Persuasion-Sense-and-Sensibility-Northanger-Pride-and-Prejudice-Annotated-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/5f212f214f217f218f213/Jane-Austen---Le-Parc-de-Mansfield-ou-les-Trois-cousines---4-Tomes---annot-Titre-original-Mansfield-Park-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/6f212f219f218f212f214/The-Juvenilia-of-Jane-Austen-and-Charlotte-Bront-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/1f216f215f212f213f210/Rude-Awakenings-of-a-Jane-Austen-Addict-Jane-Austen-Addict-2-by-Laurie-Viera-Rigler.pdf
    • http://kiteeearpdf.myhome.cx/1f210f217f219f210f211f213/Persuasion-Heron-Classics-The-Collection-50-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/5f219f213f213f218f212/Sense-and-Sensibility