Malicious PDF — malware analysis report

Static analysis result for SHA-256 563632c85caa1d16…

MALICIOUS

PDF

22.3 KB Created: 2019-05-01 17:11:11 +01:00 Authoring application: mPDF 5.7
MD5: 53e6ed5feff4e037c635f1aaa72c3c81 SHA-1: bd6d5369f83e9477b5344fecc49e4c5e8b6c9c17 SHA-256: 563632c85caa1d16fac196f7cc28d6d102173ec9928416792ba15c9605f81d3f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, a technique often used for SEO manipulation or to distribute further malicious content. The primary heuristic identified this as a PDF_SEO_LINK_FARM, indicating a likely attempt to drive traffic or distribute malware through a link farm. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/2f212f214f214f218f210/The-Cold-War-and-Soviet-Insecurity-The-Stalin-Years-by-Vojtech-Mastny.pdf
    • http://kiteeearpdf.myhome.cx/5f211f218f219f210f219/A-Failed-Empire-The-Soviet-Union-in-the-Cold-War-from-Stalin-to-Gorbachev-by-Vladislav-M-Zubok.pdf
    • http://kiteeearpdf.myhome.cx/9f213f213f210f219f219/On-Stalin-s-Team-The-Years-of-Living-Dangerously-in-Soviet-Politics-by-Sheila-Fitzpatrick.pdf
    • http://kiteeearpdf.myhome.cx/3f213f216f210f211f211/The-Haunted-Wood-Soviet-Espionage-in-America---The-Stalin-Era-by-Allen-Weinstein.pdf
    • http://kiteeearpdf.myhome.cx/1f216f219f211f213f212/Stalin-and-the-Bomb-The-Soviet-Union-and-Atomic-Energy-1939-1956-by-David-Holloway.pdf
    • http://kiteeearpdf.myhome.cx/1f216f211f219f214f215/How-the-Cold-War-Began-The-Gouzenko-Affair-and-the-Hunt-for-Soviet-Spies-by-Amy-Knight.pdf
    • http://kiteeearpdf.myhome.cx/4f210f212f215f213f218/Soviet-Fates-and-Lost-Alternatives-From-Stalinism-to-the-New-Cold-War-by-Stephen-F-Cohen.pdf
    • http://kiteeearpdf.myhome.cx/9f212f219f217f218f218/After-Stalingrad-Seven-Years-as-a-Soviet-Prisoner-of-War-by-Adelbert-Holl.pdf
    • http://kiteeearpdf.myhome.cx/5f212f212f214f210f212/Moscow-Prime-Time-How-the-Soviet-Union-Built-the-Media-Empire-That-Lost-the-Cultural-Cold-War-by-Kristin-Roth-Ey.pdf
    • http://kiteeearpdf.myhome.cx/3f211f219f212f212f213/The-Essential-Stalin-Major-Theoretical-Writings-1905-52-by-Joseph-Stalin.pdf
    • http://kiteeearpdf.myhome.cx/5f211f218f219f210f215/Reconstructing-the-Cold-War-The-Early-Years-1945-1958-by-Ted-Hopf.pdf
    • http://kiteeearpdf.myhome.cx/2f213f217f212f212f215/Hot-Lights-Cold-Steel-Life-Death-and-Sleepless-Nights-in-a-Surgeon-s-First-Years-by-Michael-J-Collins.pdf
    • http://kiteeearpdf.myhome.cx/1f210f214f211f217f211f210/Decades-of-Reconstruction-Postwar-Societies-State-Building-and-International-Relations-from-the-Seven-Years-War-to-the-Cold-War-by-Ute-Planert.pdf
    • http://kiteeearpdf.myhome.cx/7f216f212f214f210f218/Prisoners-Sentenced-to-Death-by-the-Soviet-Union-People-Executed-by-the-Soviet-Union-Grigory-Zinoviev-Lev-Kamenev-Aleksandr-Kolchak-by-Source-Wikipedia.pdf
    • http://kiteeearpdf.myhome.cx/4f215f212f214f213f219/So-long-insecurity-by-Beth-Moore.pdf
    • http://kiteeearpdf.myhome.cx/5f219f211f214f217f217/The-Politics-of-Protection-Sites-of-Insecurity-and-Political-Agency-by-Jef-Huysmans.pdf
    • http://kiteeearpdf.myhome.cx/8f213f212f213f218f217/National-Insecurity-The-Cost-of-American-Militarism-by-Melvin-A-Goodman.pdf
    • http://kiteeearpdf.myhome.cx/7f212f210f217f213f214/Punishing-the-Poor-The-Neoliberal-Government-of-Social-Insecurity-by-Lo-c-Wacquant.pdf
    • http://kiteeearpdf.myhome.cx/1f212f211f218f216f210/A-Cold-Day-in-Hell-Cold-Case-Investigation-1-by-Lissa-Marie-Redmond.pdf
    • http://kiteeearpdf.myhome.cx/8f218f212f213f213f213/Glass-Houses-Privacy-Secrecy-and-Cyber-Insecurity-in-a-Transparent-World-by-Joel-Brenner.pdf
    • http://kiteeearpdf.myhome.cx/1f216f211f219f214f2