Malicious PDF — malware analysis report

Static analysis result for SHA-256 8601c0c1f945cb2a…

MALICIOUS

PDF

21.7 KB Created: 2019-05-02 17:52:24 +01:00 Authoring application: mPDF 5.7
MD5: 765c82ae49d663867a98d93576be496b SHA-1: 99b67cccb8a0562953908d70fadbe9be361c7cb0 SHA-256: 8601c0c1f945cb2aee6a0d632af97547697088b4a31d6fe745ddfaa408d6c4e8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS heuristic also flagged this file with high confidence. The embedded URLs, such as http://kiteeearpdf.myhome.cx/1f210f216f216f218f215f211/An-Early-Victorian-Market-Town-Market-Rasen-In-The-Eighteen-Fifties-by-Market-Rasen-Branch-Workers-39-Educational-Association.pdf, are likely used to redirect users to malicious websites or to manipulate search engine results.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/1f210f216f216f218f215f211/An-Early-Victorian-Market-Town-Market-Rasen-In-The-Eighteen-Fifties-by-Market-Rasen-Branch-Workers-39-Educational-Association.pdf
    • http://kiteeearpdf.myhome.cx/1f210f216f216f218f214f216/Landranger-113-Grimsby-Louth-amp-Market-Rasen-OS-Landranger-Map-by-Ordnance-Survey.pdf
    • http://kiteeearpdf.myhome.cx/6f213f210f212f215f217/Predict-the-Next-Bull-or-Bear-Market-and-Win-How-to-Use-Key-Indicators-to-Profit-in-Any-Market-by-Michael-Sincere.pdf
    • http://kiteeearpdf.myhome.cx/9f215f213f212f217f218/Market-liberalization-an-analysis-of-the-Austrian-electricity-market-by-Natascha-Ljubic.pdf
    • http://kiteeearpdf.myhome.cx/6f215f217f218f210f215/Day-Trading-the-Currency-Market-Technical-and-Fundamental-Strategies-to-Profit-from-Market-Swings-by-Kathy-Lien.pdf
    • http://kiteeearpdf.myhome.cx/7f211f212f213f212/You-Can-Be-a-Stock-Market-Genius-Uncover-the-Secret-Hiding-Places-of-Stock-Market-Profits-by-Joel-Greenblatt.pdf
    • http://kiteeearpdf.myhome.cx/8f210f219f212f212f211/Stock-Market-Investing-for-Beginners-Understand-the-Basics-of-Stock-Market-within-2-Hours-by-Tyler-Yamazaki.pdf
    • http://kiteeearpdf.myhome.cx/1f210f217f214f212f212f217/Strong-Governments-Precarious-Workers-Labor-Market-Policy-in-the-Era-of-Liberalization-by-Philip-Rathgeb.pdf
    • http://kiteeearpdf.myhome.cx/1f210f217f214f212f218f211/Strong-Governments-Precarious-Workers-Labor-Market-Policy-in-the-Era-of-Liberalization-by-Philip-Rathgeb.pdf
    • http://kiteeearpdf.myhome.cx/1f210f216f216f216f211f210/RASEN-SHIKI-DORAMAROGY-NYUUMON-Kindle-BAN-by-KAGURAZAKA-RASEN.pdf
    • http://kiteeearpdf.myhome.cx/2f216f212f211f210f219/To-Market-by-Elizabeth-A-Schechter.pdf
    • http://kiteeearpdf.myhome.cx/8f210f217f210f216f212/The-artisan-market-by-Emma-MacDonald.pdf
    • http://kiteeearpdf.myhome.cx/2f211f216f214f218f212/Market-for-Love-by-Jamaica-Layne.pdf
    • http://kiteeearpdf.myhome.cx/4f217f210f219f218f210/Goblin-Market-by-Christina-Rossetti.pdf
    • http://kiteeearpdf.myhome.cx/8f217f218f212f213/Liar-s-Market-by-Taylor-Smith.pdf
    • http://kiteeearpdf.myhome.cx/2f212f216f216f212f210/The-Goodbye-Man-Red-Market-1-by-Ashleigh-Giannoccaro.pdf
    • http://kiteeearpdf.myhome.cx/2f214f219f216f217/The-Winter-Market-by-William-Gibson.pdf
    • http://kiteeearpdf.myhome.cx/4f214f214f210f212/Market-Forces-by-Richard-K-Morgan.pdf
    • http://kiteeearpdf.myhome.cx/9f215f216f218f215f219/Around-Downham-Market-by-Michael-Bullen.pdf
    • http://kiteeearpdf.myhome.cx/2f218f213f219f212f214/The-Love-Market-by-Carol-Mason.pdf
    • http://kiteeearpdf.myhome.cx/6f215f217f218f210f215/Day-Trading-the-Currency-Market-Technical-and-Fundamental