Malicious PDF — malware analysis report

Static analysis result for SHA-256 6c7bcad7500e7619…

MALICIOUS

PDF

23.7 KB Created: 2019-05-01 17:35:43 +01:00 Authoring application: mPDF 5.7
MD5: 27fd235d53d28b032299a3b2820918ca SHA-1: 797a84168b51cb72e09abf6a03e11055b8c7b353 SHA-256: 6c7bcad7500e761999bb1680201a8f53e413183ff09f636ff2a4b77dd4323edf
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the embedded URLs suggest a phishing or SEO poisoning attempt to redirect users to potentially malicious content. The primary attack pattern involves leveraging embedded links to direct users away from the document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/2f215f210f214f211f219/Strangers-in-Their-Own-Land-Anger-and-Mourning-on-the-American-Right-by-Arlie-Russell-Hochschild.pdf
    • http://kiteeearpdf.myhome.cx/9f217f213f216f212f217/Fremd-in-ihrem-Land-Eine-Reise-ins-Herz-der-amerikanischen-Rechten-by-Arlie-Russell-Hochschild.pdf
    • http://kiteeearpdf.myhome.cx/8f211f215f211f212/The-Second-Shift-by-Arlie-Russell-Hochschild.pdf
    • http://kiteeearpdf.myhome.cx/4f212f211f210f219f210/Land-of-Enchantment-Memoirs-of-Marian-Russell-Along-the-Santa-Fe-Trail-by-Marion-Sloan-Russell.pdf
    • http://kiteeearpdf.myhome.cx/2f219f211f218f210f214/Anger-Strategies-Practical-Tools-for-Professionals-Treating-Anger-by-Claudia-Black.pdf
    • http://kiteeearpdf.myhome.cx/8f211f216f212f214f219/Anger-Management-A-Grandiosity-Mind-Trapped-in-Anger-by-Haytham-Al-Fiqi.pdf
    • http://kiteeearpdf.myhome.cx/1f211f219f210f217f216f218/The-Secret-Alchemy-of-Anger-An-Essay-on-Anger-by-Monique-Lucette-Cardell.pdf
    • http://kiteeearpdf.myhome.cx/1f211f215f212f210f217f216/The-Anger-Volcano---A-Book-About-Anger-for-Kids-by-Amanda-Greenslade.pdf
    • http://kiteeearpdf.myhome.cx/4f214f214f215f216/Land-of-Savagery-Land-of-Promise-The-European-Image-of-the-American-Frontier-by-Ray-Allen-Billington.pdf
    • http://kiteeearpdf.myhome.cx/7f210f216f213f213f211/Strangers-in-a-Strange-Land-Living-the-Catholic-Faith-in-a-Post-Christian-World-by-Charles-J-Chaput.pdf
    • http://kiteeearpdf.myhome.cx/1f210f210f213f217f213/Strangers-from-a-Secret-Land-The-Voyages-of-the-Brig-Albion-and-the-Founding-of-the-First-Welsh-Settlements-in-Canada-by-Peter-Thomas.pdf
    • http://kiteeearpdf.myhome.cx/1f210f213f214f212f210/The-Roots-Of-American-Order-by-Russell-Kirk.pdf
    • http://kiteeearpdf.myhome.cx/4f218f210f218f211f213/Johnny-Appleseed-An-American-Legend-by-Solveig-Paulson-Russell.pdf
    • http://kiteeearpdf.myhome.cx/2f211f217f211f215/King-Leopold-s-Ghost-by-Adam-Hochschild.pdf
    • http://kiteeearpdf.myhome.cx/5f217f214f214f210f214/The-Apartisan-American-Dealignment-and-the-Transformation-of-Electoral-Politics-by-Russell-J-Dalton.pdf
    • http://kiteeearpdf.myhome.cx/1f215f217f210f218/Land-Above-the-Trees-A-Guide-to-American-Alpine-Tundra-by-Ann-Zwinger.pdf
    • http://kiteeearpdf.myhome.cx/3f212f214f213f212/Trace-Memory-History-Race-and-the-American-Land-by-Lauret-Savoy.pdf
    • http://kiteeearpdf.myhome.cx/1f211f214f218f215f217f210/Not-Yet-a-Placeless-Land-Tracking-an-Evolving-American-Geography-by-Wilbur-Zelinsky.pdf
    • http://kiteeearpdf.myhome.cx/1f216f210f218f217f212/Special-Providence-American-Foreign-Policy-and-How-It-Changed-the-World-by-Walter-Russell-Mead.pdf
    • http://kiteeearpdf.myhome.cx/1f210f212f217f216f212/The-Boom-How-Fracking-Ignited-the-American-Energy-Revolution-and-Changed-the-World-by-Russell-Gold.pdf