Malicious PDF — malware analysis report

Static analysis result for SHA-256 9af884d6f5546da5…

MALICIOUS

PDF

30.4 KB Created: 2019-05-01 17:34:41 +01:00 Authoring application: mPDF 5.7
MD5: 129b7168f09285c4884223dc576fa989 SHA-1: 8688ea3f41178e92793d8286d04be721883e4a29 SHA-256: 9af884d6f5546da56ac1b8db1274a3a9752be154525f9997e0a348261f884f70
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files hosted on the suspicious domain 'kiteeearpdf.myhome.cx'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/7f215f212f217f210/Ghosts-True-Encounters-from-the-World-Beyond-by-Hans-Holzer.pdf
    • http://kiteeearpdf.myhome.cx/1f210f216f213f212f211f216/The-Reality-of-Life-Story-of-a-Lived-Life-by-MR-Hans-Juergen-Briest.pdf
    • http://kiteeearpdf.myhome.cx/1f210f216f213f212f211f219/The-Reality-of-Life-Story-of-a-lived-Life-by-Hans-Juergen-Briest.pdf
    • http://kiteeearpdf.myhome.cx/1f210f219f212f212f217f213/Der-wundervolle-Schmetterling-The-Beautiful-Butterfly-by-Andrea-Holzer-Rhomberg.pdf
    • http://kiteeearpdf.myhome.cx/1f210f215f213f212f210f219/Das-pfiffige-Cham-leon-The-Clever-Chameleon-by-Andrea-Holzer-Rhomberg.pdf
    • http://kiteeearpdf.myhome.cx/2f215f214f218f215f211/Lincoln-and-the-Power-of-the-Press-The-War-for-Public-Opinion-by-Harold-Holzer.pdf
    • http://kiteeearpdf.myhome.cx/6f213f219f210f211f211/Virus-Life-in-Diagrams-by-Hans-Wolfgang-Ackermann.pdf
    • http://kiteeearpdf.myhome.cx/4f219f217f215f219f218/The-Bach-Reader-A-Life-of-Johann-Sebastian-Bach-in-Letters-and-Documents-by-Hans-T-David.pdf
    • http://kiteeearpdf.myhome.cx/5f215f212f217f218f215/Hans-Andersen-s-Fairy-Tales---Illustrated-by-Milo-Winter-by-Hans-Christian-Andersen.pdf
    • http://kiteeearpdf.myhome.cx/2f214f211f215f213f213/Panzer-Commander-The-Memoirs-of-Colonel-Hans-von-Luck-by-Hans-von-Luck.pdf
    • http://kiteeearpdf.myhome.cx/1f211f211f214f218f214f214/Simplicissimus-the-Vagabond-That-Is---The-Life-of-a-Strange-Adventurer-Named-Melchior-Sternfels-Von-Fuchshaim-Given-Forth-by-German-Schleifheim-Von-Sulsfort-in-the-Year-MDCLXIX-Translated-by-A-T-S-Goodrick-With-an-Introd-by-William-Rose-by-Hans-Jakob-Christoph-Von-Grimmelshausen.pdf
    • http://kiteeearpdf.myhome.cx/1f210f214f219f219f219f211/Der-Hans-Jakob-Christoph-Von-Grimmelshausen-Abenteurlicher-Simplicius-Simplicissimus-Neu-an-Tag-Geben-Und-in-Unser-Schriftdeutsch-Gesetzt-Von-Engelbert-Hegaur-by-Hans-Jakob-Christoffel-von-Grimmelshausen.pdf
    • http://kiteeearpdf.myhome.cx/1f210f214f218f211f213f215/EISKALTE-JAGD---Eine-Gangsterjagd-im-Schneesturm-Ein-Kinderkrimi-auf-Usedom-von-Hans-Rainer-Riekers-by-Hans-Rainer-Riekers.pdf
    • http://kiteeearpdf.myhome.cx/1f211f210f216f217f212f213/Hans-Ulrich-Obrist-amp-Dominique-Gonzalez-Foerster-by-Hans-Ulrich-Obrist.pdf
    • http://kiteeearpdf.myhome.cx/5f218f210f215f216f213/Hans-Ulrich-Obrist-amp-Cedric-Price-by-Hans-Ulrich-Obrist.pdf
    • http://kiteeearpdf.myhome.cx/2f218f216f219f216f210/The-Classic-Treasury-of-Hans-Christian-Andersen-by-Hans-Christian-Andersen.pdf
    • http://kiteeearpdf.myhome.cx/1f210f211f211f217f210f212/Andersen---The-Illustrated-Fairy-Tales-of-Hans-Christian-Andersen-by-Hans-Christian-Andersen.pdf
    • http://kiteeearpdf.myhome.cx/1f211f217f217f217f213f212/Fachw-rterbuch-Der-Personalarbeit-Die-Wichtigsten-Fachbegriffe-In-Deutsch-Englisch-Englisch-Deutsch-Von-A-Bis-Z-Hans-Otto-Blaeser-by-Hans-Otto-Blaeser.pdf
    • http://kiteeearpdf.myhome.cx/7f210f215f212f219f210/Middlemarch-Life-in-Middlemarch-Is-a-Study-in-Provincial-Life-Indeed-Young-Dorothea-Brooke-Has-High-Hopes-in-Life-But-Soon-Settles-in-Marriage-as-It-Turns-Out-Her-Much-Older-Husband-Is-Not-What-She-Really-Needs-to-Accomplish-Her-Noble-Deeds-in-Life-by-George-Eliot.pdf
    • http://kiteeearpdf.myhome.cx/4f213f219f214f214f218/Ostrich-A-Little-Book-About-Dealing-With-Life-s-Ups-And-Downs-Because-Life-Is-What-Life-Is-by-Kate-Woods.pdf