Malicious PDF — malware analysis report

Static analysis result for SHA-256 4c302ba7b886412e…

MALICIOUS

PDF

22.6 KB Created: 2019-05-02 17:42:59 +01:00 Authoring application: mPDF 5.7
MD5: 523022737e522961f28e55a55e7af1da SHA-1: d7e90ed5bcdfff1578902fe8ca16eee7a194aed2 SHA-256: 4c302ba7b886412e2eb89f66bc14e1271a44f439b177de5dfac225c6d9f60c67
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. The embedded URLs point to a domain that appears to be used for distributing or linking to numerous documents, suggesting a link farm or content distribution network. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/2f217f211f214f211f216/Ditching-the-Dream-amp-Not-In-My-Wildest-Dreams-The-Dream-Series-Books-1-amp-2-by-Isabelle-Peterson.pdf
    • http://kiteeearpdf.myhome.cx/3f218f219f217f219f216/Ditching-the-Dream-Dream-1-by-Isabelle-Peterson.pdf
    • http://kiteeearpdf.myhome.cx/2f217f215f216f210f214/Unexpected-Dreams-Dream-4-by-Isabelle-Peterson.pdf
    • http://kiteeearpdf.myhome.cx/3f210f212f219f210f213/Chasing-the-Dream-Dream-3-by-Isabelle-Peterson.pdf
    • http://kiteeearpdf.myhome.cx/6f210f219f217f213f214/The-Interpretation-of-Dreams-The-Dream-as-a-Fulfillment-of-a-Wish-Distortion-in-Dreams-The-Method-of-Dream-Interpretation-The-Sources-of-Dreams-amp-The-Psychology-of-the-Dream-Activities-by-Sigmund-Freud.pdf
    • http://kiteeearpdf.myhome.cx/1f218f215f214f217/Wildest-Dream-The-Biography-of-George-Mallory-by-Peter-Gillman.pdf
    • http://kiteeearpdf.myhome.cx/9f217f213f215f210f218/Pikcanon-Not---Canon-Treasures-Ancient-Ad-Series-Ancient-Secrets-Series-Blast-from-the-Past-Series-Cook-s-Arsenal-Series-Crystallized-Emotions-Series-Dream-Series-Explorer-s-Friend-Series-Frigid-Series-Gourmet-Series-Husband-s-Tears-Series-Mass-by-Source-Wikia.pdf
    • http://kiteeearpdf.myhome.cx/1f211f212f212/Dream-a-Little-Dream-Dream-a-Little-Dream-1-by-Giovanna-Fletcher.pdf
    • http://kiteeearpdf.myhome.cx/4f213f214f211f213f218/In-Dreams-The-Dream-1-by-J-Sterling.pdf
    • http://kiteeearpdf.myhome.cx/2f213f214f210f210f210/A-New-Dream-Dreams-1-by-Alex-C-Clarke.pdf
    • http://kiteeearpdf.myhome.cx/1f216f211f219f217f212/Peter-Wilson-s-Dream-Theater-The-Dream-Master-by-John-C-Archer.pdf
    • http://kiteeearpdf.myhome.cx/9f214f212f214f210f218/Living-the-Waking-Dream-We-Live-out-Our-Lives-in-the-Dream-by-Michael-Jean-Nystrom-Schut.pdf
    • http://kiteeearpdf.myhome.cx/4f219f210f217f216f219/Dream-a-Little-Scream-Dream-Club-Mystery-2-by-Mary-Kennedy.pdf
    • http://kiteeearpdf.myhome.cx/1f211f211f215f219/Dream-a-Little-Dream-Chicago-Stars-4-by-Susan-Elizabeth-Phillips.pdf
    • http://kiteeearpdf.myhome.cx/5f218f211f219f214/Dream-the-Impossible-Dream-Zen-Pencils-Volume-Two-by-Gavin-Aung-Than.pdf
    • http://kiteeearpdf.myhome.cx/2f212f212f214f215f219/Dream-a-Little-Dream-Chicago-Stars-4-by-Susan-Elizabeth-Phillips.pdf
    • http://kiteeearpdf.myhome.cx/2f218f213f216f218f218/Dream-a-Little-Dream-Chicago-Stars-4-by-Susan-Elizabeth-Phillips.pdf
    • http://kiteeearpdf.myhome.cx/8f212f218f219f218f218/The-Dream-Wizard-Dreams-Do-Come-True-by-T-C-Barillier.pdf
    • http://kiteeearpdf.myhome.cx/4f217f210f212f213f214/Finding-the-Dream-Dream-Trilogy-3-by-Nora-Roberts.pdf
    • http://kiteeearpdf.myhome.cx/1f211f215f215f211f211f216/Dream-Huntress-Dream-Seeker-1-by-Michelle-Sharp.pdf
    • http://kiteeearpdf