Malicious PDF — malware analysis report

Static analysis result for SHA-256 5ee50a40729fd288…

MALICIOUS

PDF

20.3 KB Created: 2020-03-13 01:59:14 +00:00 Authoring application: mPDF 5.7
MD5: cb240348d266b6b678ec399f87fc3d40 SHA-1: a6904411775af036ebd05a3b15b52c6240714a5b SHA-256: 5ee50a40729fd288425d1a549f2fd1e3ac71a0be62e3d48240a79b5a2df6c28e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links pointing to external PDF files hosted on the domain 'kiteeearpdf.myhome.cx'. This behavior is indicative of a link farm or a phishing lure designed to redirect users to potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/2f210f215f210f213f212/Forest-Fairies-by-Marion-St-John-Webb.pdf
    • http://kiteeearpdf.myhome.cx/2f210f215f210f212f219/The-Water-Fairies-by-Marion-St-John-Webb.pdf
    • http://kiteeearpdf.myhome.cx/2f210f215f210f213f218/Seashore-Fairies-by-Marion-St-John-Webb.pdf
    • http://kiteeearpdf.myhome.cx/2f210f215f210f213f215/The-House-Fairies-by-Marion-St-John-Webb.pdf
    • http://kiteeearpdf.myhome.cx/2f210f215f210f210f213/The-Twilight-Fairies-by-Marion-St-John-Webb.pdf
    • http://kiteeearpdf.myhome.cx/3f216f213f210f216f219/Healing-With-The-Fairies-Messages-Manifestations-and-Love-from-the-World-of-the-Fairies-How-Nature-s-Angels-Can-Help-You-in-Every-Area-of-Your-Life-by-Doreen-Virtue.pdf
    • http://kiteeearpdf.myhome.cx/1f214f211f211f211f216/The-Hunt-in-the-Forest-by-John-Burnside.pdf
    • http://kiteeearpdf.myhome.cx/1f211f217f216f218f214f212/Hansel-and-Florian-in-the-Black-Forest-by-John-Christy.pdf
    • http://kiteeearpdf.myhome.cx/1f217f214f219f219f215/The-Forest-of-Adventures-Knight-Trilogy-1-by-Katie-M-John.pdf
    • http://kiteeearpdf.myhome.cx/4f214f216f216f215f214/A-Forest-Journey-The-Story-of-Wood-and-Civilization-by-John-Perlin.pdf
    • http://kiteeearpdf.myhome.cx/1f219f217f217f214f213/Nordic-Fairies-Part-1-Nordic-Fairies-by-Saga-Berg.pdf
    • http://kiteeearpdf.myhome.cx/2f215f215f210f210f212/Miss-Ravenel-s-Conversion-from-Secession-to-Loyalty-by-John-William-De-Forest.pdf
    • http://kiteeearpdf.myhome.cx/4f219f214f216f214f214/Forest-Primeval-The-Natural-History-of-an-Ancient-Forest-by-Chris-Maser.pdf
    • http://kiteeearpdf.myhome.cx/7f216f211f213f218f219/Murder-in-the-Forest-Forest-Murders-Book-1-by-Louise-Hodkin.pdf
    • http://kiteeearpdf.myhome.cx/6f214f210f218f213/The-Forest-Carpet-New-Zealand-s-Little-Noticed-Forest-Plants-Mosses-Lichens-Liverworts-Hornworts-Fork-Ferns-and-Lycopods-by-Bill-Malcolm.pdf
    • http://kiteeearpdf.myhome.cx/1f211f216f211f217f218/Which-Native-Forest-Plant-A-Simple-Guide-to-the-Identification-of-New-Zealand-Native-Forest-Shrubs-Climbers-and-Flowers-by-Andrew-Crowe.pdf
    • http://kiteeearpdf.myhome.cx/1f210f210f210f216f218f215/The-Works-of-F-Marion-Crawford-Volume-2-The-Children-Of-The-King-A-Cigarette-Maker-s-Romance-Corleone-Doctor-Claudius-Don-Orsino-by-F-Marion-Crawford.pdf
    • http://kiteeearpdf.myhome.cx/1f219f219f215f218f213/Amiranda-Princess-Amiranda-and-the-Tale-of-the-Deciduous-Forest-by-John-P-Adamo.pdf
    • http://kiteeearpdf.myhome.cx/7f216f217f216f214f214/Borlase-Smart-St-Ives-Artist-Marion-Whybrow-by-Marion-Whybrow.pdf
    • http://kiteeearpdf.myhome.cx/1f214f219f216f217f213/Like-Water-Like-Bread-Poems-by-Joyce-Webb-Kohler-by-Joyce-Webb-Kohler.pdf