Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b89864446ed65e2…

MALICIOUS

PDF

22.6 KB Created: 2019-05-02 19:26:38 +01:00 Authoring application: mPDF 5.7
MD5: 4340cf1a3f30abefdb4859e86ea23f4d SHA-1: c9be999dabcaaeb6d1ca943ceb08a95fbb52b814 SHA-256: 8b89864446ed65e2c43eeed594ab91304e7523dc23cccb5c621932ad770105c6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded URLs, such as http://kiteeearpdf.myhome.cx/3f217f218f212f211f216/Dissociation-in-Traumatized-Children-and-Adolescents-Theory-and-Clinical-Interventions-by-Sandra-Wieland.pdf, are likely used to redirect users to malicious content or for SEO spamming. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/3f217f218f212f211f216/Dissociation-in-Traumatized-Children-and-Adolescents-Theory-and-Clinical-Interventions-by-Sandra-Wieland.pdf
    • http://kiteeearpdf.myhome.cx/1f218f217f211f212f215/Workbook-for-Pledge-s-Counseling-Adolescents-and-Children-Developing-Your-Clinical-Style-by-Deanna-S-Pledge.pdf
    • http://kiteeearpdf.myhome.cx/5f218f218f211f212f212/Counseling-Children-and-Adolescents-by-Ann-Vernon.pdf
    • http://kiteeearpdf.myhome.cx/1f210f215f210f212f216f212/Sociotherapeutic-interventions-for-children-with-Asperger-Syndrome-by-Petra-Stockmann.pdf
    • http://kiteeearpdf.myhome.cx/9f215f215f216f216f219/Creative-Interventions-for-Troubled-Children-and-Youth-by-Liana-Lowenstein.pdf
    • http://kiteeearpdf.myhome.cx/5f218f218f211f213f213/Children-Adolescents-and-the-Media-by-Victor-C-Strasburger.pdf
    • http://kiteeearpdf.myhome.cx/5f218f217f219f217f216/Infants-Children-and-Adolescents-by-Laura-E-Berk.pdf
    • http://kiteeearpdf.myhome.cx/5f218f218f211f213f210/No-Talk-Therapy-for-Children-and-Adolescents-by-Martha-B-Straus.pdf
    • http://kiteeearpdf.myhome.cx/1f210f214f213f212f219f216/Behavior-Therapy-with-Aggressive-Children-and-Adolescents-by-Franz-Petermann.pdf
    • http://kiteeearpdf.myhome.cx/5f218f218f210f215f219/Evidence-Based-Psychotherapies-for-Children-and-Adolescents-by-Alan-E-Kazdin.pdf
    • http://kiteeearpdf.myhome.cx/1f211f212f216f213f212f214/Assessing-Intelligence-in-Children-and-Adolescents-A-Practical-Guide-by-John-H-Kranzler.pdf
    • http://kiteeearpdf.myhome.cx/3f218f216f211f217f215/Attention-Deficit-Disorders-and-Comorbidities-in-Children-Adolescents-and-Adults-by-Thomas-E-Brown.pdf
    • http://kiteeearpdf.myhome.cx/6f214f214f216f211f211/Alexithymia-Advances-in-Research-Theory-and-Clinical-Practice-by-Olivier-Luminet.pdf
    • http://kiteeearpdf.myhome.cx/8f210f218f217f211f218/Critical-Thinking-in-Clinical-Research-Applied-Theory-and-Practice-Using-Case-Studies-by-Felipe-Fregni.pdf
    • http://kiteeearpdf.myhome.cx/9f212f218f219f211/Shades-of-Black-A-Celebration-of-Our-Children-by-Sandra-L-Pinkney.pdf
    • http://kiteeearpdf.myhome.cx/5f218f218f210f215f217/Adolescents-Welcome-to-Reality-All-by-Myself-by-Adolescents.pdf
    • http://kiteeearpdf.myhome.cx/1f219f215f213f215/Nickels-A-Tale-Of-Dissociation-by-Christine-Stark.pdf
    • http://kiteeearpdf.myhome.cx/1f211f212f216f212f218f216/The-Haunted-Self-Structural-Dissociation-and-the-Treatment-of-Chronic-Traumatization-by-Onno-van-der-Hart.pdf
    • http://kiteeearpdf.myhome.cx/7f211f219f211f210f218/Vasopressin-and-Oxytocin-From-Genes-to-Clinical-Applications-From-Genes-to-Clinical-Applications-by-Dominique-Poulain.pdf
    • http://kiteeearpdf.myhome.cx/9f215f216f218f217f213/Red-Blood-Cell-Substitutes-Basic-Principles-and-Clinical-Applications-Basic-Principles-and-Clinical-Applications-by-Alan-Rudolph.pdf