Malicious PDF — malware analysis report

Static analysis result for SHA-256 6025272733cabb66…

MALICIOUS

PDF

13.4 KB Created: 2020-03-19 18:48:31 +00:00 Authoring application: mPDF 5.7
MD5: b3a0fad3828bcfcae3a34b05c302aa05 SHA-1: 1a3de082cce49834dd911a8303573f552803ba11 SHA-256: 6025272733cabb66bc07e7f8c279eb3d3d0e3d6f61558d86827074c3b8027f1f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files, hosted on the domain kitasdyu.myhome.cx. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier also flagged this document as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kitasdyu.myhome.cx/4870876875871879/Dead-Meat-Zombie-D-O-A-0-5-by-J-J-Zep.pdf
    • http://kitasdyu.myhome.cx/3876871872874874/Zombie-The-Other-Fright-Meat-by-Matt-Nord.pdf
    • http://kitasdyu.myhome.cx/3876871872879872/The-Last-Zombie-Dead-New-World-The-Last-Zombie-1-by-Brian-Keene.pdf
    • http://kitasdyu.myhome.cx/1878873873878874/Dead-Meat-by-Sue-Coe.pdf
    • http://kitasdyu.myhome.cx/9879871876878878/Dead-Meat-by-Philip-Kerr.pdf
    • http://kitasdyu.myhome.cx/9879871877877873/Sunny-Sweet-Is-So-Dead-Meat-by-Jennifer-Ann-Mann.pdf
    • http://kitasdyu.myhome.cx/3877875876874874/Charlie-Dead-and-the-Seeds-of-Zombie-Chaos-Charlie-Dead-2-by-Geoff-Camphire.pdf
    • http://kitasdyu.myhome.cx/4871878874878873/The-Dead-Can-t-Die-Zombie-D-O-A-6-by-J-J-Zep.pdf
    • http://kitasdyu.myhome.cx/4870877876871878/Dead-On-Arrival-Zombie-D-O-A-4-by-J-J-Zep.pdf
    • http://kitasdyu.myhome.cx/4870877874875870/Dead-On-My-Feet-Zombie-D-O-A-2-by-J-J-Zep.pdf
    • http://kitasdyu.myhome.cx/4870877877876875/Return-To-Dead-City-Zombie-D-O-A-5-by-J-J-Zep.pdf
    • http://kitasdyu.myhome.cx/3876871872876872/Dead-Reaping-Zombie-Armageddon-5-by-Ian-Woodhead.pdf
    • http://kitasdyu.myhome.cx/7878870876875872/Zombie-s-Birthday-Apocalypse-Diary-of-a-Minecraft-Zombie-9-by-Zack-Zombie.pdf
    • http://kitasdyu.myhome.cx/4870877872876876/Zombie-Tales-from-Dead-Worlds-by-Rhiannon-Frater.pdf
    • http://kitasdyu.myhome.cx/2873874876871875/Dead-Endz-Zombie-Games-3-by-Kristen-Middleton.pdf
    • http://kitasdyu.myhome.cx/4870877874874876/The-Zombie-Whisperer-Living-with-the-Dead-4-by-Jesse-Petersen.pdf
    • http://kitasdyu.myhome.cx/2879877879877873/Wanted-Dead-or-Undead-Zombie-West-1-by-Angela-Scott.pdf
    • http://kitasdyu.myhome.cx/3876870873879877/Dead-Guy-Spy-Nathan-Abercrombie-Accidental-Zombie-2-by-David-Lubar.pdf
    • http://kitasdyu.myhome.cx/1870878877878871/Charlie-Dead-and-the-So-Called-Zombie-Apocalypse-by-Geoff-Camphire.pdf
    • http://kitasdyu.myhome.cx/2878875872871/Wanted-Dead-or-Undead-Zombie-West-1-by-Angela-Scott.pdf