Malicious PDF — malware analysis report

Static analysis result for SHA-256 a76710fa6fb49eb8…

MALICIOUS

PDF

22.8 KB Created: 2019-05-02 05:40:49 +01:00 Authoring application: mPDF 5.7
MD5: e46e3d68b6b1c26cae64e84917211f72 SHA-1: b614d82eb9d7f668eb2d7d6afdba43756ed1b94a SHA-256: a76710fa6fb49eb8bf5af9355284a3cf90872d012e5dcf06c16f09f31b9d1579
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'kiteeearpdf.myhome.cx'. This pattern is indicative of a link farm or a phishing lure designed to redirect users to potentially malicious content. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/1f211f212f213f215f217f210/Foundations-and-Trends-Entrepreneurship-Research-Past-Perspectives-and-Future-Prospects-by-Anders-Lundstr-m.pdf
    • http://kiteeearpdf.myhome.cx/1f210f214f215f211f217f212/Foundations-and-Trends-The-Global-Entrepreneurship-Index-by-Zoltan-J-Acs.pdf
    • http://kiteeearpdf.myhome.cx/9f218f214f213f219f216/Li-S-Batteries-The-Challenges-Chemistry-Materials-and-Future-Perspectives-The-Challenges-Chemistry-Materials-and-Future-Perspectives-by-Rezan-Demir-Cakan.pdf
    • http://kiteeearpdf.myhome.cx/1f211f217f215f217f213f217/Foundations-of-Near-Death-Research-A-Conceptual-and-Phenomenological-Map-by-Alexander-Batthy-ny.pdf
    • http://kiteeearpdf.myhome.cx/1f210f218f210f215f210f218/Nerve-Organ-and-Tissue-Regeneration--Research-Perspectives-by-Frederick-J-Seil.pdf
    • http://kiteeearpdf.myhome.cx/1f210f218f210f213f212f214/Nerve-Organ-and-Tissue-Regeneration-Research-Perspectives-by-Fredrick-Seil.pdf
    • http://kiteeearpdf.myhome.cx/5f218f215f218f219f214/Future-Survey-Annual-1985-A-Guide-to-the-Recent-Literature-of-Trends-Forecasts-and-Policy-Proposals-by-Michael-Marien.pdf
    • http://kiteeearpdf.myhome.cx/5f218f215f218f219f210/Future-Survey-Annual-1990-A-Guide-to-the-Recent-Literature-of-Trends-Forecasts-and-Policy-Proposals-by-Michael-Marien.pdf
    • http://kiteeearpdf.myhome.cx/6f215f214f211f218f210/Making-Australian-History-Perspectives-On-The-Past-Since-1788-by-Deborah-Gare.pdf
    • http://kiteeearpdf.myhome.cx/1f211f211f213f211f212f217/Breast-Cancer-Gene-Research-and-Medical-Practices-Transnational-Perspectives-in-the-Time-of-Brca-by-Sahra-Gibbon.pdf
    • http://kiteeearpdf.myhome.cx/1f211f211f213f211f213f216/Breast-Cancer-Gene-Research-and-Medical-Practices-Transnational-Perspectives-in-the-Time-of-BRCA-by-Sahra-Gibbon.pdf
    • http://kiteeearpdf.myhome.cx/4f218f213f210f218f217/Future-s-Past-The-Beginning-by-Christine-F-Stacey.pdf
    • http://kiteeearpdf.myhome.cx/1f211f218f215f216f219f212/Columbus-Past-Present-and-Future-by-Brad-Pauquette.pdf
    • http://kiteeearpdf.myhome.cx/2f215f213f216f212f210/Godzilla-Past-Present-and-Future-by-Arthur-Adams.pdf
    • http://kiteeearpdf.myhome.cx/9f214f211f215f212f213/International-Tribunals-Past-and-Future-by-Manley-O-Hudson.pdf
    • http://kiteeearpdf.myhome.cx/2f214f211f211f214f217/The-Uncanny-X-Men-Days-of-Future-Past-by-Chris-Claremont.pdf
    • http://kiteeearpdf.myhome.cx/3f213f212f218f219f211/X-Men-Days-of-Future-Past-Prose-Novel-by-Alexander-C-Irvine.pdf
    • http://kiteeearpdf.myhome.cx/6f210f217f216f218f210/The-Long-Bow-of-the-Past-The-Rifle-for-the-Future-by-H--Britannicus-by-Robert-Potts.pdf
    • http://kiteeearpdf.myhome.cx/5f218f214f212f214f215/Neocarzinostatin-The-Past-Present-and-Future-of-Anticancer-Drug-by-H-Maeda.pdf
    • http://kiteeearpdf.myhome.cx/6f214f214f217f211f211/Glorious-Eclipses-Their-Past-Present-and-Future-by-Serge-Brunier.pdf
    • http://kiteeearpdf.myhome.cx/1f211f217f215f217f213f217/Foundations-of-Near-Death-Research-A-Conceptual-and-Phenomenological-Map-by-Alexander-Batthy