Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b0f037328b75bc1…

MALICIOUS

PDF

22.2 KB Created: 2019-05-01 17:18:14 +01:00 Authoring application: mPDF 5.7
MD5: f0ce929e5a21fc86fd975173d293a5a7 SHA-1: 9e39191b25e19c69211f2d6b90a1be9a8798f345 SHA-256: 4b0f037328b75bc1a393058d38f95d33241b21fb8c0f35b311c379918121219b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded URLs point to a domain that appears to be used for distributing numerous PDF files, suggesting a link farm or a distribution point for malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/1f211f216f214f210f219f219/The-T-Graben-Discovery-and-Exploration-of-the-Mammalian-Graben-by-Joe-Duhon.pdf
    • http://kiteeearpdf.myhome.cx/9f215f216f211f215f212/Erfolgreich-beim-Kunden-in-der-digitalen-Welt-by-Peter-H-M-Vervest.pdf
    • http://kiteeearpdf.myhome.cx/9f210f214f215f210f213/Lectures-on-the-Philosophy-of-Religion-One-Volume-Edition---The-Lectures-of-1827-by-Georg-Wilhelm-Friedrich-Hegel.pdf
    • http://kiteeearpdf.myhome.cx/1f211f216f214f210f219f218/The-Revenge-of-Tom-Graben-by-Van-Holt.pdf
    • http://kiteeearpdf.myhome.cx/1f211f216f214f211f216f216/What-Don-t-We-Need-Anymore-by-Eric-K-Graben.pdf
    • http://kiteeearpdf.myhome.cx/6f219f214f218f217f211/J-ai-toujours-peur-de-ce-que-les-autres-pensent-de-moi-Comment-faire-pour-acqu-rir-la-fa-on-de-penser-de-ceux-qui-n-ont-pas-ou-n-ont-plus-cette-crainte-Neurosciences-t-1-by-Christian-S-n-caut.pdf
    • http://kiteeearpdf.myhome.cx/9f211f212f213f211f212/Modeling-In-The-Neurosciences-From-Ionic-Channels-To-Neural-Networks-by-Poznanski-Poznanski.pdf
    • http://kiteeearpdf.myhome.cx/1f211f216f214f211f216f218/Geology-of-the-Humber-Group-Central-Graben-amp-Moray-Firth-U-K-by-A-Hurst.pdf
    • http://kiteeearpdf.myhome.cx/1f211f216f214f212f217f214/Active-Tectonics-in-the-Upper-Rhine-Graben-Integration-of-Paleoseismology-Geomorphology-and-Geomechanical-Modeling-by-Gwendolyn-Peters.pdf
    • http://kiteeearpdf.myhome.cx/1f211f216f214f213f218f215/Wall-Und-Graben-Befestigungen-Von-Der-Steinzeit-Bis-Ins-Mittelalter-in-Schleswig-Und-Holstein-Vold-Og-Grav-Fstningsvrker-Fra-Oldtid-by-Volker-Arnold.pdf
    • http://kiteeearpdf.myhome.cx/1f211f216f214f213f217f219/Mechanism-of-Graben-Formation-Selected-Papers-of-an-Icg-Symposium-Held-During-the-17th-Iugg-General-Assembly-Canberra-Australia-December-5-1979-by-J-H-Illies.pdf
    • http://kiteeearpdf.myhome.cx/1f210f211f214f217f215f217/Hoppe-Hoppe-Reiter-Fallt-Er-in-Den-Graben-Dann-Fressen-Ihn-Die-Raben-by-Hartmut-Emrich.pdf
    • http://kiteeearpdf.myhome.cx/1f210f219f211f211f210f214/Gemini-84-by-Beim.pdf
    • http://kiteeearpdf.myhome.cx/1f210f219f211f212f210f215/Virgo-85-X-by-Beim.pdf
    • http://kiteeearpdf.myhome.cx/1f210f219f211f211f213f215/Pisces-85-X-by-Beim.pdf
    • http://kiteeearpdf.myhome.cx/1f210f219f211f212f210f211/Libra-84-by-Beim.pdf
    • http://kiteeearpdf.myhome.cx/1f210f219f211f212f210f217/Aries-85-X-by-Beim.pdf
    • http://kiteeearpdf.myhome.cx/1f210f219f211f211f214f219/Virgo-85-by-Beim.pdf
    • http://kiteeearpdf.myhome.cx/1f210f219f211f212f211f210/Scorpio-85-X-by-Beim.pdf
    • http://kiteeearpdf.myhome.cx/1f210f219f211f211f215f210/Taurus-85-X-by-Beim.pdf
    • http://kiteeearp