Malicious PDF — malware analysis report

Static analysis result for SHA-256 48487e87176d0857…

MALICIOUS

PDF

21.9 KB Created: 2019-05-01 17:17:58 +01:00 Authoring application: mPDF 5.7
MD5: 75c44c0afd2037fb213f573430ef6d0e SHA-1: 9f25e985f5d71bea4125483efacf423d810b36b4 SHA-256: 48487e87176d08573a9594309aa99901f0aaecad69d1ada3f3ef90f13514db6d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary attack pattern involves directing users to a suspicious domain hosting numerous files, likely as a distribution or redirection mechanism. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/4f217f211f216f217f214/Atlanta-Beer-A-Heady-History-of-Brewing-in-the-Hub-of-the-South-by-Ronald-Smith.pdf
    • http://kiteeearpdf.myhome.cx/9f218f217f214f219/Beer-Brewing-At-Home-Easy-Ways-of-Brewing-Homemade-Beer-by-Cheryl-Barnhart.pdf
    • http://kiteeearpdf.myhome.cx/1f210f212f218f215f219f216/Questions-on-Barley-Malting-and-Malt-in-the-Beer-Brewing-Process-by-Edward-H-Vogel.pdf
    • http://kiteeearpdf.myhome.cx/1f211f216f213f217f213f216/Follies-Fables-and-Fantasy-Animal-Adventures-and-Fairy-Tales-from-the-South-West-by-Endymion-Beer.pdf
    • http://kiteeearpdf.myhome.cx/4f215f212f216f214/Land-of-Amber-Waters-The-History-of-Brewing-in-Minnesota-by-Doug-Hoverson.pdf
    • http://kiteeearpdf.myhome.cx/6f216f214f217f214f217/The-Lion-and-the-Springbok-Britain-and-South-Africa-since-the-Boer-War-by-Ronald-Hyam.pdf
    • http://kiteeearpdf.myhome.cx/4f214f217f212f210f214/Peachtree-Creek-A-Natural-and-Unnatural-History-of-Atlanta-s-Watershed-by-David-R-Kaufman.pdf
    • http://kiteeearpdf.myhome.cx/6f219f213f212f210f218/The-Complete-Beer-Course-Boot-Camp-for-Beer-Geeks-From-Novice-to-Expert-in-Twelve-Tasting-Classes-by-Joshua-M-Bernstein.pdf
    • http://kiteeearpdf.myhome.cx/3f215f212f211f210/The-History-of-Joseph-Smith-by-His-Mother-by-Lucy-Mack-Smith.pdf
    • http://kiteeearpdf.myhome.cx/3f214f215f215f217/A-Different-Mirror-A-History-of-Multicultural-America-by-Ronald-Takaki.pdf
    • http://kiteeearpdf.myhome.cx/4f212f214f217f210f212/History-of-Joseph-Smith-by-His-Mother-Lucy-Mack-Smith-The-Unabridged-Original-Version-by-Lucy-Mack-Smith.pdf
    • http://kiteeearpdf.myhome.cx/4f212f218f212f211f213/Southbound-Surrender-South-Boys-1-by-Raen-Smith.pdf
    • http://kiteeearpdf.myhome.cx/2f218f211f217f219/Strangers-from-a-Different-Shore-A-History-of-Asian-Americans-by-Ronald-Takaki.pdf
    • http://kiteeearpdf.myhome.cx/4f210f212f215f213f216/The-Stations-of-the-Sun-A-History-of-the-Ritual-Year-in-Britain-by-Ronald-Hutton.pdf
    • http://kiteeearpdf.myhome.cx/1f214f210f213f212f211/The-Rebellion-of-Ronald-Reagan-A-History-of-the-End-of-the-Cold-War-by-James-Mann.pdf
    • http://kiteeearpdf.myhome.cx/5f210f212f219f216f217/Egyptomania-A-History-of-Fascination-Obsession-and-Fantasy-by-Ronald-H-Fritze.pdf
    • http://kiteeearpdf.myhome.cx/4f212f216f219f219f213/The-Beer-and-Whiskey-League-The-Illustrated-History-of-the-American-Association--Baseball-s-Renegade-Major-League-by-David-Nemec.pdf
    • http://kiteeearpdf.myhome.cx/2f213f212f216f218f216/Capturing-Jonathan-Pollard-How-One-of-the-Most-Notorious-Spies-in-American-History-Was-Brought-to-Justice-by-Ronald-J-Olive.pdf
    • http://kiteeearpdf.myhome.cx/3f213f218f218f210f217/In-Her-Own-Name-Women-In-South-Australian-History-by-Helen-Jones.pdf
    • http://kiteeearpdf.myhome.cx/6f218f216f211f218f217/A-History-of-Kershaw-County-South-Carolina-by-Joan-A-Inabinet.pdf
    • http://kiteeearpdf