Malicious PDF — malware analysis report

Static analysis result for SHA-256 9a2db9275f103c3f…

MALICIOUS

PDF

26.2 KB Created: 2019-05-01 05:16:39 +01:00 Authoring application: mPDF 5.7
MD5: 1e81a9f29741c6e9520d0fa5292ef4b2 SHA-1: 909830f124e1b03a06901d24b8396e4d971076d2 SHA-256: 9a2db9275f103c3f49d3b35c3b6d4f093396c189305bbb59193c751f03e12832
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, with the primary domain being kiteeearpdf.myhome.cx. The ML classifier also flagged this PDF as malicious with high confidence. The purpose appears to be to lure users to these external sites, likely for SEO spam or phishing purposes.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9908

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/1f210f218f210f212f213f211/Employers-Guide-to-Recruiting-on-the-Internet-by-Ray-Schreyer.pdf
    • http://kiteeearpdf.myhome.cx/4f211f214f216f219f214/DIY-SEO-amp-Internet-Marketing-Guide-How-To-Do-It-Yourself-Search-Engine-Optimization-and-Internet-Marketing-EZ-Website-Promotion-Book-1-by-Darren-Varndell.pdf
    • http://kiteeearpdf.myhome.cx/4f211f216f212f219f211/How-to-Say-it-on-Your-Resume-A-Top-Recruiting-Director-s-Guide-to-Writing-the-Perfect-Resume-for-Every-Job-by-Brad-Karsh.pdf
    • http://kiteeearpdf.myhome.cx/9f216f217f214f219f216/The-Internet-Galaxy-Reflections-on-the-Internet-Business-and-Society-by-Manuel-Castells.pdf
    • http://kiteeearpdf.myhome.cx/1f210f212f217f213f218f219/Internet-Password-Organizer-An-Alphabetical-Journal-to-Organize-Internet-Log-In-Details-by-Anneline-Sophia.pdf
    • http://kiteeearpdf.myhome.cx/1f210f212f217f213f213f211/Internet-Password-Organizer-An-Alphabetical-Journal-to-Organize-Internet-Log-In-Details---Black-Cover-by-Anneline-Sophia.pdf
    • http://kiteeearpdf.myhome.cx/8f210f210f214f213f214/Cretinism-A-Medical-Dictionary-Bibliography-and-Annotated-Research-Guide-to-Internet-References-by-James-N-Parker.pdf
    • http://kiteeearpdf.myhome.cx/9f219f213f217f210f216/Birthmarks-A-Medical-Dictionary-Bibliography-and-Annotated-Research-Guide-to-Internet-References-by-James-N-Parker.pdf
    • http://kiteeearpdf.myhome.cx/8f218f212f216f215f214/Opening-Science-The-Evolving-Guide-on-How-the-Internet-Is-Changing-Research-Collaboration-and-Scholarly-Publishing-by-Sonke-Bartling.pdf
    • http://kiteeearpdf.myhome.cx/7f215f210f218f215f216/Valuation-of-Internet-Start-Ups-An-Applied-Research-on-How-Venture-Capitalists-Value-Internet-Start-Ups-by-Jean-Baptiste-Flanc.pdf
    • http://kiteeearpdf.myhome.cx/1f213f215f214f210f210/On-Sale-Employers-Get-Good-Workers-Dirt-Cheap-by-Tracy-L-Kinne.pdf
    • http://kiteeearpdf.myhome.cx/9f216f211f216f215f216/Against-Labor-How-U-S-Employers-Organized-to-Defeat-Union-Activism-by-Rosemary-Feurer.pdf
    • http://kiteeearpdf.myhome.cx/7f213f211f216f216f211/MLM-SCRIPTS-Recruiting-and-Handling-Objections-by-Lewis-Smile.pdf
    • http://kiteeearpdf.myhome.cx/2f218f212f215f216f214/The-Recruiting-Trip-The-University-of-Gatica-1-by-Lexy-Timms.pdf
    • http://kiteeearpdf.myhome.cx/1f210f218f210f213f217f211/Der-Mann-auf-den-Klippen-by-Wolfgang-Schreyer.pdf
    • http://kiteeearpdf.myhome.cx/1f210f218f210f212f213f212/Gewichtsmanagement-in-Der-Adipositastherapie-by-Katja-Schreyer.pdf
    • http://kiteeearpdf.myhome.cx/1f210f217f219f219f210f216/Tears-and-Tequila-A-Novel-by-Linda-Schreyer.pdf
    • http://kiteeearpdf.myhome.cx/1f210f218f210f211f216f215/A-View-from-the-Ledge-An-Insider-s-Look-at-the-Schreyer-Years-by-Herbert-Schulz.pdf
    • http://kiteeearpdf.myhome.cx/1f210f217f219f219f210f215/Death-by-a-Dark-Horse-Thea-Campbell-Mysteries-1-by-Susan-Schreyer.pdf
    • http://kiteeearpdf.myhome.cx/1f210f218f210f211f217f216/Wednesdays-Are-Cabinet-Days-A-Personal-Account-Of-The-Schreyer-Administration-by-Russell-Doern.pdf
    • http://kiteeearpdf.myhome.cx/9f216f217f21