Malicious PDF — malware analysis report

Static analysis result for SHA-256 6386082155da2cb6…

MALICIOUS

PDF

22.5 KB Created: 2019-05-02 05:10:51 +01:00 Authoring application: mPDF 5.7
MD5: 0f411d115a97aebbeac6fd638f75d563 SHA-1: 1369bfb934922b41c09a9aab997ec0b8f6012b09 SHA-256: 6386082155da2cb63bd6a3b08ca6595c000f9d932552741b1cace41b9efbb808
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links likely serve as a lure to direct users to potentially malicious websites. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/1f216f212f218f214/William-Faulkner-by-Irving-Howe.pdf
    • http://kiteeearpdf.myhome.cx/9f214f211f216f219f211/Harvard-Classics-Shelf-of-Fiction-Vol-18-Crime-and-Punishment-by-Fyodor-Dostoyevsky.pdf
    • http://kiteeearpdf.myhome.cx/3f213f211f213f215f212/The-Watcher-by-the-Threshold-Shorter-Scottish-Fiction-Canongate-Classics-by-John-Buchan.pdf
    • http://kiteeearpdf.myhome.cx/6f214f216f219f216f211/Frankenstein---Phoenix-Science-Fiction-Classics-with-notes-and-critical-essays-by-Mary-Wollstonecraft-Shelley.pdf
    • http://kiteeearpdf.myhome.cx/6f212f210f211f215f214/Classics-of-Modern-Political-Theory-Machiavelli-to-Mill-by-Steven-M-Cahn.pdf
    • http://kiteeearpdf.myhome.cx/9f218f216f217f211f216/The-Good-Parts-The-Best-Erotic-Writing-in-Modern-Fiction-by-J-H-Blair.pdf
    • http://kiteeearpdf.myhome.cx/6f219f216f213f214f217/The-Seventh-Science-Fiction-Megapack-25-Modern-and-Classic-Stories-by-Robert-Silverberg.pdf
    • http://kiteeearpdf.myhome.cx/6f210f212f219f217/Master-and-Man-by-Leo-Tolstoy-Fiction-Classics-by-Leo-Tolstoy.pdf
    • http://kiteeearpdf.myhome.cx/3f219f218f217f211f214/A-Certain-Persuasion-Modern-LGBTQ-fiction-inspired-by-Jane-Austen-s-novels-by-Julie-Bozza.pdf
    • http://kiteeearpdf.myhome.cx/4f212f211f219f212f218/Modern-Mythmakers-35-Interviews-with-Horror-amp-Science-Fiction-Writers-and-Filmmakers-by-Michael-McCarty.pdf
    • http://kiteeearpdf.myhome.cx/2f219f211f210f210f216/The-Mad-Scientist-s-Guide-to-World-Domination-Original-Short-Fiction-for-the-Modern-Evil-Genius-by-John-Joseph-Adams.pdf
    • http://kiteeearpdf.myhome.cx/8f214f215f211f217f216/A-Connecticut-Yankee-in-King-Arthur-s-Court-by-Mark-Twain-Fiction-Classics-Fantasy-amp-Magic-by-Mark-Twain.pdf
    • http://kiteeearpdf.myhome.cx/5f216f218f216f216f217/Emma-by-Jane-Austen-Fiction-Classics-Romance-Historical-Literary-by-Jane-Austen.pdf
    • http://kiteeearpdf.myhome.cx/7f218f211f218f219f210/St-John-s-Eve-by-Nikolai-Vasil-evich-Gogol-Fiction-Classics-Literary-by-Nikolai-Gogol.pdf
    • http://kiteeearpdf.myhome.cx/2f217f211f218f212f212/Washington-Irving-A-Treasury-Rip-Van-Winkle-The-Legend-of-Sleepy-Hollow-Old-Christmas-by-Washington-Irving.pdf
    • http://kiteeearpdf.myhome.cx/1f210f218f217f213f212f217/Modern-Domestic-Fiction-Popular-Feminism-Mass-Market-Magazines-and-Middle-Class-Culture-1905-1925-by-Birte-Christ.pdf
    • http://kiteeearpdf.myhome.cx/1f210f217f216f216f219f214/Irving-Wishbutton-and-the-Questing-Academy-Irving-Wishbutton-1-by-Brian-Clopper.pdf
    • http://kiteeearpdf.myhome.cx/8f218f215f216f214f217/The-Bluffer-s-Guide-to-the-Classics-Bluff-Your-Way-in-the-Classics-by-Ross-Leckie.pdf
    • http://kiteeearpdf.myhome.cx/3f218f215f212f210f216/Graphic-Classics-Volume-19-Christmas-Classics-by-Tom-Pomplun.pdf
    • http://kiteeearpdf.myhome.cx/3f212f214f219f218f212/Old-Christmas-From-the-Sketch-Book-of-Washington-Irving-by-Washington-Irving.pdf