Malicious PDF — malware analysis report

Static analysis result for SHA-256 a5ce77d38c78d82f…

MALICIOUS

PDF

25.0 KB Created: 2020-03-21 08:34:00 +00:00 Authoring application: mPDF 5.7
MD5: adc545955e90e2c6c8d26d1c42646e77 SHA-1: b573670d2c207e3416ce279b746a1a1458637895 SHA-256: a5ce77d38c78d82f289734df74a247e7147af2e4fae562266ca0bde7592ec5c7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links all point to the same domain, kitasdyu.myhome.cx, and appear to be disguised as book titles. The ML_NYX_PDF_MALICIOUS heuristic also flagged this PDF with high confidence. The primary attack pattern involves tricking the user into clicking these links, which likely lead to a malicious site for further exploitation or content delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kitasdyu.myhome.cx/1871871876876875/Diary-of-a-Fairy-Godmother-by-Esm-Raji-Codell.pdf
    • http://kitasdyu.myhome.cx/1879875878874875/How-to-Get-Your-Child-to-Love-Reading-by-Esm-Raji-Codell.pdf
    • http://kitasdyu.myhome.cx/2879873870871875/Diary-of-a-Teenage-Fairy-Godmother-by-Kathleen-Baldwin.pdf
    • http://kitasdyu.myhome.cx/6874879875878/Diary-of-a-Teenage-Fairy-Godmother-by-Kathleen-Baldwin.pdf
    • http://kitasdyu.myhome.cx/4879871871874875/The-Godmother-Spell-The-Fairy-Godmother-Chronicles-Book-1-by-Lucy-McConnell.pdf
    • http://kitasdyu.myhome.cx/2877879878876878/Zally-s-Book-The-Fairy-Godmother-Academy-3-by-Jan-Bozarth.pdf
    • http://kitasdyu.myhome.cx/3878871877875874/Her-Own-Fairy-Godmother-Where-Dreams-Come-True-2-by-Marie-Higgins.pdf
    • http://kitasdyu.myhome.cx/8877875874873/My-Fairly-Dangerous-Godmother-My-Fair-Godmother-3-by-Janette-Rallison.pdf
    • http://kitasdyu.myhome.cx/3872879877870871/Marriage-by-Design-Dear-Fairy-Godmother-Marriage-on-the-Run-Don-t-Tell-Grandfather-The-Enchanted-Bride-by-Cathy-Gillen-Thacker.pdf
    • http://kitasdyu.myhome.cx/7878874870872872/Love-Journal-Valentine-s-Day-Love-Journal-Diary-Memory-Notebook-Keepsake-Journal-Sketchbook-Blank-Book-Bullet-Journal-Notebook-Planner-by-Night-Fairy-Size-6x9-150-Lined-Pages-by-Night-Fairy.pdf
    • http://kitasdyu.myhome.cx/7878874870879879/Love-Journal-Valentine-s-Day-Love-Journal-Diary-Memory-Notebook-Keepsake-Journal-Sketchbook-Blank-Book-Bullet-Journal-Notebook-Planner-by-Night-Fairy-Size-6x9-150-Lined-Pages-by-Night-Fairy.pdf
    • http://kitasdyu.myhome.cx/5876878875877871/Collections-of-Fairy-Tales-The-Tales-of-Beedle-the-Bard-Grimm-s-Fairy-Tales-Andrew-Lang-s-Fairy-Books-the-Happy-Prince-and-Other-Tales-by-Source-Wikipedia.pdf
    • http://kitasdyu.myhome.cx/3879879879879876/Novels-by-Jeff-Kinney-Diary-of-a-Wimpy-Kid-Dog-Days-Diary-of-a-Wimpy-Kid-the-Last-Straw-Diary-of-a-Wimpy-Kid-Rodrick-Rules-by-Books-LLC.pdf
    • http://kitasdyu.myhome.cx/3877873870879879/Scary-Godmother-by-Jill-Thompson.pdf
    • http://kitasdyu.myhome.cx/9875876875876879/Mastering-Vinyasa-Yoga-The-Yoga-Synthesis-Guide-to-Dynamic-Sequencing-with-Hundreds-of-Photos-and-Instructions-by-Raji-Thron.pdf
    • http://kitasdyu.myhome.cx/3877874872872875/Scary-Godmother-Spooktacular-Stories-by-Jill-Thompson.pdf
    • http://kitasdyu.myhome.cx/3878873877871879/The-Faerie-Godmother-s-Apprentice-Wore-Green-by-Nicky-Kyle.pdf
    • http://kitasdyu.myhome.cx/4870879875878877/The-Last-Fairy-Apple-Tree-Fairy-Realm-4-by-Emily-Rodda.pdf
    • http://kitasdyu.myhome.cx/3873872874874872/Life-as-a-Fairy-Thrall-Fairy-Compacts-2-by-Katey-Hawthorne.pdf
    • http://kitasdyu.myhome.cx/7878874870879875/Love-Journal-Valentine-s-Day-Love-Journal-Diary-Memory-Notebook-Keepsake-Journal-Sketchbook-Blank-Book-Bullet-Journal-Notebook-Planner-Size-6x9-150-Dot-Grid-Pages-by-Night-Fairy.pdf
    • http://kitasdyu.myhome.cx/3872879877870871/Marriage-by-Design-Dear-Fairy-Godmother-Marriage-on-the-Run-Don-t-Tell-Grandfat