Malicious PDF — malware analysis report

Static analysis result for SHA-256 540174c87b58977c…

MALICIOUS

PDF

20.7 KB Created: 2019-05-01 17:24:48 +01:00 Authoring application: mPDF 5.7
MD5: a750cc112b3e4d78eebee712763255a8 SHA-1: d48bf59bd6e7584f00d08cc35bc78700dba0dbc4 SHA-256: 540174c87b58977c25481271a9455c593bf8b66c162fbe8d728945fa4689048e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, characteristic of a link farm designed to redirect users to potentially harmful content. The primary attack pattern involves luring users through these links, likely to a compromised website or a phishing page.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/9f219f215f212f216f217/Science-Fiction-Westerns-The-Adventures-of-Brisco-County-Jr-the-Wild-Wild-West-Jonah-Hex-Weird-West-Wild-West-C-O-W--Boys-of-Moo-Mesa-by-Source-Wikipedia.pdf
    • http://kiteeearpdf.myhome.cx/2f219f213f218f219/The-Real-Wild-West-The-101-Ranch-and-the-Creation-of-the-American-West-by-Michael-Wallis.pdf
    • http://kiteeearpdf.myhome.cx/3f210f210f217f215f216/Wild-West-Boys-Wild-West-Boys-1-2-by-Lorelei-James.pdf
    • http://kiteeearpdf.myhome.cx/7f217f216f218f213f210/All-New-Popular-Comics-Wild-Wild-West-Issue-by-David-Noe.pdf
    • http://kiteeearpdf.myhome.cx/6f210f218f213f215/Berlin-Wild-by-Elly-Welt.pdf
    • http://kiteeearpdf.myhome.cx/1f210f213f214f218f214f215/U-Bahnhof-in-Berlin-Bahnhof-Berlin-Zoologischer-Garten-Bahnhof-Berlin-Lichtenberg-Liste-Der-Berliner-U-Bahnhofe-Berlin-Hauptbahnhof-by-Quelle-Wikipedia.pdf
    • http://kiteeearpdf.myhome.cx/5f214f217f213f214f218/Streaks-of-Squatter-Life-and-Far-West-Scenes-Vol-1-A-Series-of-Humorous-Sketches-Descriptive-of-Incidents-and-Character-in-the-Wild-West-to-Which-Are-Added-Other-Miscellaneous-Pieces-by-Solitaire-Solitaire.pdf
    • http://kiteeearpdf.myhome.cx/8f214f210f215f214f211/Auden-and-Isherwood-The-Berlin-Years-by-Norman-Page.pdf
    • http://kiteeearpdf.myhome.cx/9f212f210f217f216f211/O-Jugend-o-West-Berlin-Reportagen-Essays-Kolumnen-by-Philip-Meinhold.pdf
    • http://kiteeearpdf.myhome.cx/1f213f219f218f214/Cowboys-of-the-Wild-West-by-Russell-Freedman.pdf
    • http://kiteeearpdf.myhome.cx/9f213f216f217f210f213/Schopenhauer-and-the-Wild-Years-of-Philosophy-by-Rudiger-Safranski.pdf
    • http://kiteeearpdf.myhome.cx/8f218f218f210f218f215/Schopenhauer-and-the-Wild-Years-of-Philosophy-by-R-diger-Safranski.pdf
    • http://kiteeearpdf.myhome.cx/2f218f211f217f213f214/The-Fall-of-Rome-Wild-West-3-by-Beth-Ciotta.pdf
    • http://kiteeearpdf.myhome.cx/9f219f213f219f218f215/The-Big-Book-of-the-Weird-Wild-West-by-John-Whalen.pdf
    • http://kiteeearpdf.myhome.cx/2f210f210f217f218f211/Good-Lies-Wild-Minds-1-by-Charlotte-West.pdf
    • http://kiteeearpdf.myhome.cx/8f213f216f218f214f215/The-West-of-Wild-Bill-Hickok-by-Joseph-G-Rosa.pdf
    • http://kiteeearpdf.myhome.cx/4f216f213f212f216f210/Wild-West-Wedding-River-s-End-Ranch-9-by-Caroline-Lee.pdf
    • http://kiteeearpdf.myhome.cx/2f218f211f217f214f219/Lasso-the-Moon-Wild-West-1-by-Beth-Ciotta.pdf
    • http://kiteeearpdf.myhome.cx/5f210f212f210f212f211/The-Cheyenne-Maiden-Wild-West-Passion-1-by-Robin-Gideon.pdf
    • http://kiteeearpdf.myhome.cx/5f210f211f213f219f217/Promised-by-Post-Wild-West-Weddings-2-by-Katy-Madison.pdf
    • http://kiteeearpdf.myhome.cx/1f210f213f214f218f214f215/U-Bahnhof-in-Berlin-Bahnhof-Berlin-Zoologischer-Garten-Bahnhof-Berlin-Lichtenberg-List