Malicious PDF — malware analysis report

Static analysis result for SHA-256 9585c899ceb07d96…

MALICIOUS

PDF

137.9 KB
MD5: 38bf4d7a61489bfd6ee235642c92be0f SHA-1: 009c390a67ca13d6405a5cc7cd44f0477b3ed58e SHA-256: 9585c899ceb07d9660071f65987cee8912fe4023ea1be8e2e8eff0196b342d2f
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains multiple heuristics indicating it is designed to trick users into downloading a payload. Specifically, it uses invisible and repeated links to deliver 'MineForTheEye.zip' from 'skitty.cloud.seedboxes.cc'. The embedded URLs also point to 'the-eye.eu' and '10gbps.io', suggesting a potential distribution network. The primary attack pattern involves luring the user to download a malicious archive.

Machine Learning

  • Nyx PDF Classifier clean score 0.0075

Heuristics 3

  • Invisible/repeated PDF links deliver payload file critical PDF_REPEATED_PAYLOAD_LINK_LURE
    PDF uses invisible link annotations and points to a direct payload download. Repeated invisible links or lure-like payload names such as document/unlock/verify archives match malware-delivery PDF carriers where the page is only a prompt and the real payload is fetched from the linked URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://the-eye.eu/
    • https://10gbps.io/?utm_source=the-eye.eu&utm_medium=referral&utm_campaign=sponsorship-the-eye&utm_content=link
    • https://skitty.cloud.seedboxes.cc/MineForTheEye.zip
    • https://discord.gg/WjXmqNT

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_009_off00014f57.bin
29bc97f8122d6c595abf1862479435dcdf558aab3d79806c5456ed916078a236
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x14F57 43824 bytes