Malicious PDF — malware analysis report

Static analysis result for SHA-256 97317b1a528fa943…

MALICIOUS

PDF

20.3 KB Created: 2019-05-02 05:27:01 +01:00 Authoring application: mPDF 5.7
MD5: 2797f9ae4d87278588fccb3c8407dc9a SHA-1: d2d97eb9a929a8bbc56f1f23fee1101f0e81b9e7 SHA-256: 97317b1a528fa943652b1e57633fc5956164ca3d36c6985064444085742e91c0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large farm of external links, a technique often used for SEO manipulation or to distribute malicious payloads. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of numerous external links. No scripts were extracted, but the sheer volume of links suggests a redirection or download attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/3f216f210f216f218f214/Another-America-Otra-America-by-Barbara-Kingsolver.pdf
    • http://kiteeearpdf.myhome.cx/4f217f210f211f216f211/Nickel-and-Dimed-On-Not-Getting-By-in-America-by-Barbara-Ehrenreich.pdf
    • http://kiteeearpdf.myhome.cx/6f214f219f214f218f214/Nickel-and-Dimed-On-Not-Getting-By-in-America-by-Barbara-Ehrenreich.pdf
    • http://kiteeearpdf.myhome.cx/2f214f217f214f211f215/America-Speaks-When-will-Our-Hearts-Listen-WHEN-AMERICA-BURN-SO-DOES-OUR-CONSCIENCE-by-Kristin-Hannah.pdf
    • http://kiteeearpdf.myhome.cx/1f210f213f216f212f219f210/South-America-and-Central-America-A-Natural-History-by-Jean-Dorst.pdf
    • http://kiteeearpdf.myhome.cx/4f213f217f219f215f212/1000-Days-Between-Part-1-From-Corporate-America-To-South-America-by-Dan-Perry.pdf
    • http://kiteeearpdf.myhome.cx/7f215f214f218f215f212/Curing-America-A-look-inside-America-s-failing-health-care-system-by-Amol-Soin.pdf
    • http://kiteeearpdf.myhome.cx/6f211f216f210f211f218/St-Francis-of-America-How-a-Thirteenth-Century-Friar-Became-America-s-Most-Popular-Saint-by-Patricia-Appelbaum.pdf
    • http://kiteeearpdf.myhome.cx/7f215f212f215f216f219/America-in-an-Arab-Mirror-Images-of-America-in-Arabic-Travel-Literature-An-Anthology-by-Kamal-Abdel-Malek.pdf
    • http://kiteeearpdf.myhome.cx/5f213f211f211f218f217/America-s-Test-Kitchen-Live-The-All-New-Companion-to-America-s-Favorite-Public-Television-Cooking-Series-by-Carl-Tremblay.pdf
    • http://kiteeearpdf.myhome.cx/1f210f216f218f211f217f219/Madness-in-Cold-War-America-Mad-America-by-Alexander-Dunst.pdf
    • http://kiteeearpdf.myhome.cx/5f212f210f211f212f214/Politician-s-Dilemma-Building-State-Capacity-in-Latin-America-by-Barbara-Geddes.pdf
    • http://kiteeearpdf.myhome.cx/2f218f215f218f219f216/Bright-sided-How-the-Relentless-Promotion-of-Positive-Thinking-Has-Undermined-America-by-Barbara-Ehrenreich.pdf
    • http://kiteeearpdf.myhome.cx/5f213f215f210f211/Small-Wonder-by-Barbara-Kingsolver.pdf
    • http://kiteeearpdf.myhome.cx/1f217f218f214f211f215/Pigs-in-Heaven-by-Barbara-Kingsolver.pdf
    • http://kiteeearpdf.myhome.cx/6f214f216f213f213/Homeland-and-Other-Stories-by-Barbara-Kingsolver.pdf
    • http://kiteeearpdf.myhome.cx/4f214f213f219f211f214/Flight-Behaviour-by-Barbara-Kingsolver.pdf
    • http://kiteeearpdf.myhome.cx/2f216f210f214f210f218/Animal-Dreams-by-Barbara-Kingsolver.pdf
    • http://kiteeearpdf.myhome.cx/6f211f214f211f217f215/L-Arbre-aux-haricots-by-Barbara-Kingsolver.pdf
    • http://kiteeearpdf.myhome.cx/8f211f218f210f218/The-Poisonwood-Bible-by-Barbara-Kingsolver.pdf
    • http://kiteeearpdf.myho