Malicious PDF — malware analysis report

Static analysis result for SHA-256 a7274d74110766f6…

MALICIOUS

PDF

21.8 KB Created: 2020-03-18 21:11:57 +00:00 Authoring application: mPDF 5.7
MD5: af9cb2d78b374368df38492047416f28 SHA-1: 855e6a53f97c82ac1d10d4146ba822d58f19b656 SHA-256: a7274d74110766f67f40d3089fa840a4812e838bd04e50fb18c438e92094ae02
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to external PDF files hosted on kitasdyu.myhome.cx. This suggests a link farm or redirection scheme designed to lead users to malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kitasdyu.myhome.cx/4874873871877871/The-List-Irresistible-3-by-Anne-Calhoun.pdf
    • http://kitasdyu.myhome.cx/4875871874877870/Evening-Storm-Irresistible-4-by-Anne-Calhoun.pdf
    • http://kitasdyu.myhome.cx/2870876878877877/On-the-Edge-Uncommon-0-5-by-Anne-Calhoun.pdf
    • http://kitasdyu.myhome.cx/4877879879877870/The-SEAL-s-Rebel-Librarian-Alpha-Ops-2-by-Anne-Calhoun.pdf
    • http://kitasdyu.myhome.cx/4871872876871878/Four-Irresistible-Rogues-by-Tanya-Anne-Crosby.pdf
    • http://kitasdyu.myhome.cx/3879874875872879/Uncommon-Passion-Uncommon-2-by-Anne-Calhoun.pdf
    • http://kitasdyu.myhome.cx/3875871876875871/Uncommon-Pleasure-Uncommon-1-by-Anne-Calhoun.pdf
    • http://kitasdyu.myhome.cx/9879870873870872/Eugenides---Characters-Deities-People-Aris-Costis-Dite-Enkelis-Eugenides-Eugenides-Exis-Galen-Helen-Hephestia-Irene-Laecdomon-List-of-Attendants-List-of-Mede-Ambassadors-List-of-Minor-Characters-Magus-of-Sounis-by-Source-Wikipedia.pdf
    • http://kitasdyu.myhome.cx/5874874878871870/Articles-on-Fablehaven-Series-Including-Fablehaven-Fablehaven-Rise-of-the-Evening-Star-Fablehaven-Grip-of-the-Shadow-Plague-List-of-Magical-Items-in-Fablehaven-List-of-Fablehaven-Characters-List-of-Fablehaven-s-Magical-Creatures-by-Hephaestus-Books.pdf
    • http://kitasdyu.myhome.cx/4873872874874878/The-Bump-List-The-Back-Up-List-3-by-Miriam-Brady.pdf
    • http://kitasdyu.myhome.cx/8870876873878879/Julian-s-List-The-List-3-by-Haleigh-Lovell.pdf
    • http://kitasdyu.myhome.cx/4871876870875872/Kiss-List-The-List-Series-1-by-J-S-Abilene.pdf
    • http://kitasdyu.myhome.cx/1874878876877870/Liam-s-List-The-List-2-by-Haleigh-Lovell.pdf
    • http://kitasdyu.myhome.cx/7871879875872875/Greek-New-Testament-Manuscripts-List-of-New-Testament-Minuscules-Textual-Variants-in-the-New-Testament-List-of-New-Testament-Uncials-by-Source-Wikipedia.pdf
    • http://kitasdyu.myhome.cx/5874874878870879/Fablehaven-Series-List-of-Fablehaven-s-Magical-Creatures-List-of-Fablehaven-Characters-Fablehaven-Keys-to-the-Demon-Prison-by-Books-LLC.pdf
    • http://kitasdyu.myhome.cx/5873878871877/Aria-of-the-Sea-by-Dia-Calhoun.pdf
    • http://kitasdyu.myhome.cx/4876871878873874/Eva-of-the-Farm-by-Dia-Calhoun.pdf
    • http://kitasdyu.myhome.cx/1870876878876870871/Tonio-s-Cat-by-Mary-Calhoun.pdf
    • http://kitasdyu.myhome.cx/4873871875872874/White-Midnight-by-Dia-Calhoun.pdf
    • http://kitasdyu.myhome.cx/1871873872878874870/The-Art-of-Windows-8-1-by-Margaret-Calhoun.pdf
    • http://kitasdyu.myhome.cx/9879870873870872/Eugenides---Characters-Deities-People-Aris-Costis-Dite-Enkelis-Eugenides-Eugenides-Exis-Galen-Helen-Hephestia-Irene-Laecdomon-List