Malicious PDF — malware analysis report

Static analysis result for SHA-256 a163437086933de3…

MALICIOUS

PDF

18.0 KB Created: 2019-05-02 05:49:03 +01:00 Authoring application: mPDF 5.7
MD5: 32fbeeeaece88c5ecf6ee77cce0e9411 SHA-1: 44a361916db93c96d62c4bf5437a4f2fe77833fe SHA-256: a163437086933de3223e6f5af0762b17c17e4715b9eeecc4daa468f944e051b3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS classifier also flagged this document with high confidence. The embedded URLs, such as http://kiteeearpdf.myhome.cx/2f215f218f216f213f211/1938-Yearbook-of-Jehovah-s-Witnesses-by-Watch-Tower-Bible-and-Tract-Society.pdf, are likely used to distribute malicious content or for SEO manipulation. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/2f215f218f216f213f211/1938-Yearbook-of-Jehovah-s-Witnesses-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f218f213f213f214/1942-Yearbook-of-Jehovah-s-Witnesses-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f216f219f216f218/1972-Yearbook-of-Jehovah-s-Witnesses-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f218f213f218f216/1937-Yearbook-of-Jehovah-s-Witnesses-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f217f215f217f211/2002-Yearbook-of-Jehovah-Witnesses-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f218f216f214f216/1940-Yearbook-of-Jehovah-s-Witnesses-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f216f217f211f215/1941-Report-of-Convention-of-Jehovah-s-Witnesses-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f217f215f211f215/1939-Messenger-Report-Of-Conventions-Of-Jehovah-s-Witnesses-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f218f215f212f217/Songs-to-Jehovah-s-Praise-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f218f212f211f213/Research-Guide-for-Jehova-s-Witnesses-1914-edition-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f217f218f211f212/Reconciliation-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f218f216f217f211/Salvation-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f218f218f218f215/Shepherd-The-Flock-of-God-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f218f217f210f213/Things-in-Which-it-is-Impossible-for-God-to-Lie-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f218f216f218f216/Make-sure-of-all-things-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f211f215f214f219f213/Listening-to-the-Great-Teacher-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f218f218f212f213/You-May-Survive-Armageddon-Into-God-s-New-World-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f217f212f218f216/Biography-of-Pastor-Russell-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/4f217f214f216f213f211/The-Secret-of-Family-Happiness-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f218f210f212f213/Insight-On-The-Scriptures-Volumes-I-And-II-by-Watch-Tower-Bible-and-Tract-Society.pdf
    • http://kiteeearpdf.myhome.cx/2f215f217f215f211f215/1939-Messenger-Report-Of-Conventions-