Malicious PDF — malware analysis report

Static analysis result for SHA-256 7c207e2358b9964f…

MALICIOUS

PDF

21.5 KB Created: 2019-05-02 17:29:43 +01:00 Authoring application: mPDF 5.7
MD5: 63f6ba1b084614e06c9f351a8f5f0457 SHA-1: a9cda2704e1b08751d76774dfa3ae9d8836f7f9f SHA-256: 7c207e2358b9964f5cd6ab252210242dff7fae54c0ed28c8586f90c2a067c80d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF was flagged by a machine learning classifier and a critical heuristic for containing a large number of external links. These links, such as http://kiteeearpdf.myhome.cx/1f210f214f219f210f214f211/Q-Phaze---Realit-t-anders-by-Roland-Roth.pdf, are likely used to redirect users to malicious sites. The document body was unreadable, but the link farm strongly suggests a phishing or content-luring attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/1f210f214f219f210f214f211/Q-Phaze---Realit-t-anders-by-Roland-Roth.pdf
    • http://kiteeearpdf.myhome.cx/8f210f217f210f218f215/Roth-Time-A-Dieter-Roth-Retrospective-by-Dieter-Roth.pdf
    • http://kiteeearpdf.myhome.cx/1f211f216f215f219f213f216/Wandlungen-Aufbruch-in-die-Jahre-50-plus-by-Irene-Kummer.pdf
    • http://kiteeearpdf.myhome.cx/9f211f218f214f214f215/Joseph-Roth---Gesammelte-Werke-Romane-Erz-hlungen-Journalistische-Schriften-mehr-als-30-Titel-in-einem-E-Book---Radetzkymarsch-Hiob-Die-Kapuzinergruft-Trinker-Das-falsche-Gewic-by-Joseph-Roth.pdf
    • http://kiteeearpdf.myhome.cx/1f210f215f214f215f212f215/Iran-Stillstand-Oder-Aufbruch-Standstill-or-Awakening-by-Ulla-Kimmig.pdf
    • http://kiteeearpdf.myhome.cx/9f211f215f216f214f213/Broadway-Ecke-Canal-New-York---Stadt-im-Aufbruch-by-Andrian-Kreye.pdf
    • http://kiteeearpdf.myhome.cx/1f211f212f217f218f211/The-World-of-Veronica-Roth-s-Divergent-Series-by-Veronica-Roth.pdf
    • http://kiteeearpdf.myhome.cx/9f219f215f214f213f213/Aufbruch-ins-Land-der-unbegrenzten-M-glichkeiten-Arbeiten-Leben-und-Studieren-in-den-USA-Tipps-f-r-Neuank-mmlinge-by-Gisela-Spallek.pdf
    • http://kiteeearpdf.myhome.cx/9f213f218f215f212f210/K-nnen-Tomaten-tr-umen-Von-der-Intelligenz-der-Erde---Aufbruch-zu-einem-neuen-Naturverst-ndnis-by-Mathias-Br-ckers.pdf
    • http://kiteeearpdf.myhome.cx/1f210f212f218f212f213f213/Vom-Unbekannten-gefickt-by-Nicole-Kirschberg.pdf
    • http://kiteeearpdf.myhome.cx/1f210f212f218f212f218f213/Nachtzug---Rendezvous-mit-einem-Unbekannten-by-Tim-Langner.pdf
    • http://kiteeearpdf.myhome.cx/1f210f212f218f212f217f218/Vom-Unbekannten-auf-dem-Parkplatz-gefickt-by-Marie-Verhoren.pdf
    • http://kiteeearpdf.myhome.cx/1f210f212f216f216f217f215/Verliebt-in-einen-Unbekannten-by-Lucy-Robinson.pdf
    • http://kiteeearpdf.myhome.cx/1f210f212f218f212f213f214/Die-Spur-des-unbekannten-Bruders-by-Winfried-Paarmann.pdf
    • http://kiteeearpdf.myhome.cx/1f210f212f218f210f217f219/Bildnis-einer-Unbekannten-by-Stella-LaFemme.pdf
    • http://kiteeearpdf.myhome.cx/1f210f212f218f210f218f218/Angewandte-Analysis-in-Einer-Unbekannten-by-Donald-Estep.pdf
    • http://kiteeearpdf.myhome.cx/1f210f212f218f212f219f210/The-Stranger---Jagd-nach-dem-Unbekannten---Roadmovie-Western-by-Kai-Uwe-Conrad.pdf
    • http://kiteeearpdf.myhome.cx/1f211f219f218f216f218f213/Dramen-Der-Russischen-Moderne-in-Unbekannten-Uebersetzungen-Henry-Von-Heiselers-by-Fedor-B-Poljakov.pdf
    • http://kiteeearpdf.myhome.cx/1f211f219f218f216f218f214/Dramen-Der-Russischen-Moderne-in-Unbekannten-Uebersetzungen-Henry-Von-Heiselers-by-Fedor-B-Poljakov.pdf
    • http://kiteeearpdf.myhome.cx/9f218f216f210f216f211/Der-Krieg-der-Welten-by-H-G-Wells.pdf
    • http://kiteeearpdf.myh