Malicious PDF — malware analysis report

Static analysis result for SHA-256 6a842860f6a1f685…

MALICIOUS

PDF

19.3 KB Created: 2019-05-02 17:42:50 +01:00 Authoring application: mPDF 5.7
MD5: 42cf61eaa3588c098c7e7d9ced03e8b1 SHA-1: 49d746ecd8e17c611460f8f5417974b1d408bb9a SHA-256: 6a842860f6a1f685de1e483910b4692b621e6be4439886ae4232886ada1cd6b2
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to a single domain, indicating a link farm or SEO poisoning attempt. The ML classifier also flagged this PDF as malicious. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/3f217f213f214f214f218/Mary-Todd-Lincoln-by-Jean-H-Baker.pdf
    • http://kiteeearpdf.myhome.cx/7f211f213f216f218f215/Mary-Todd-Lincoln-A-Biography-by-Jean-H-Baker.pdf
    • http://kiteeearpdf.myhome.cx/5f219f212f212f216f219/Loving-Mr-Lincoln-The-Personal-Diaries-of-Mary-Todd-Lincoln-by-M-Kay-duPont.pdf
    • http://kiteeearpdf.myhome.cx/2f217f214f219f219f213/Just-a-Few-Words-Mr-Lincoln-by-Jean-Fritz.pdf
    • http://kiteeearpdf.myhome.cx/1f210f213f214f216f212f214/James-Buchanan-by-Jean-H-Baker.pdf
    • http://kiteeearpdf.myhome.cx/1f210f218f210f215f213/Mary-Baker-and-The-Eye-of-the-Tiger-by-D-M-Cherubim.pdf
    • http://kiteeearpdf.myhome.cx/6f212f214f217f215f211/Margaret-Sanger-A-Life-of-Passion-by-Jean-H-Baker.pdf
    • http://kiteeearpdf.myhome.cx/5f219f214f217f219f213/Mary-Baker-Eddy-by-Gillian-Gill.pdf
    • http://kiteeearpdf.myhome.cx/7f210f212f216f212f216/Senator-Bailey-and-Abraham-Lincoln-Inviting-Bailey-to-Speak-at-the-Lincoln-Banquet-Was-a-Disgrace-to-the-State-of-Illinois-and-an-Insult-to-the-Memory-of-Abraham-Lincoln-by-Harold-C-Kessinger.pdf
    • http://kiteeearpdf.myhome.cx/2f216f212f219f213f219/The-House-at-Baker-Street-Mrs-Hudson-and-Mary-Watson-Investigation-1-by-Michelle-Birkby.pdf
    • http://kiteeearpdf.myhome.cx/1f211f217f212f211f216f216/Lincoln-Cents-1959-2009-Collector-s-Lincoln-Cent-Folder-by-Warman-39-s.pdf
    • http://kiteeearpdf.myhome.cx/2f215f215f214f216f216/Did-Lincoln-Own-Slaves-And-Other-Frequently-Asked-Questions-About-Abraham-Lincoln-by-Gerald-J-Prokopowicz.pdf
    • http://kiteeearpdf.myhome.cx/1f211f217f212f211f216f217/Lincoln-Cents-1909-1958-Collector-s-Lincoln-Cent-Folder-by-Warman-39-s.pdf
    • http://kiteeearpdf.myhome.cx/3f216f219f211f212f216/Lincoln-s-Men-How-President-Lincoln-Became-Father-to-an-Army-and-a-Nation-by-William-C-Davis.pdf
    • http://kiteeearpdf.myhome.cx/8f214f211f212f213f216/Postcolonial-Subjects-Francophone-Women-Writers-by-Mary-Jean-Matthews-Green.pdf
    • http://kiteeearpdf.myhome.cx/2f219f213f215f214f211/Baker-s-Bad-Boys-by-Dean-J-Baker.pdf
    • http://kiteeearpdf.myhome.cx/1f216f213f219f210f213/Todd-And-Brad-Reed-s-Michigan-Wednesdays-in-the-Mitten-by-Todd-Reed.pdf
    • http://kiteeearpdf.myhome.cx/4f216f218f219f214f212/Royal-Road-to-Fotheringhay-Stuart-Saga-1-Mary-Stuart-1-by-Jean-Plaidy.pdf
    • http://kiteeearpdf.myhome.cx/5f219f216f210f210f216/Speeches-and-Letters-of-Abraham-Lincoln-by-Abraham-Lincoln.pdf
    • http://kiteeearpdf.myhome.cx/4f213f217f215f218f219/Abraham-Lincoln-Great-Speeches-by-Abraham-Lincoln.pdf