Malicious PDF — malware analysis report

Static analysis result for SHA-256 ac24400e255a9556…

MALICIOUS

PDF

28.9 KB Created: 2019-05-01 18:29:47 +01:00 Authoring application: mPDF 5.7
MD5: fe6da83fdbc0f9e2c796abe8065c6430 SHA-1: f44904dd6cef4d01233b523064870174401c47f5 SHA-256: ac24400e255a9556fce622e446c25644e520af0cb4a3a8885bbed1c537790b8e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this document as malicious with high confidence. The embedded URLs point to a domain that appears to be used for distributing numerous PDF files, suggesting a link farm or redirection strategy. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9908

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/6f214f211f217f216f213/Les-Plus-Belles-Pendules-Francaises-The-Finest-French-Pendulum-Clocks-Le-Piu-Belle-Pendole-Francesi-de-Louis-XIV-A-L-Empire-From-Louis-XIV-to-the-Empire-Da-Luigi-XIV-All-Impero-by-Aurelie-Wannenes.pdf
    • http://kiteeearpdf.myhome.cx/2f212f214f215f211f218/The-British-Empire-In-The-Middle-East-1945-1951-Arab-Nationalism-The-United-States-and-Postwar-Imperialism-by-William-Roger-Louis.pdf
    • http://kiteeearpdf.myhome.cx/6f213f210f213f219f213/French-History-Introduction-Berry-Douane-Lacan-Treaty-of-Tours-Louis-the-Stammerer-Coutumes-de-Beauvaisis-French-Ship-Redoutable-by-Books-LLC.pdf
    • http://kiteeearpdf.myhome.cx/4f210f212f210f213f212/Empire-of-Secrets-British-Intelligence-the-Cold-War-and-the-Twilight-of-Empire-by-Calder-Walton.pdf
    • http://kiteeearpdf.myhome.cx/3f216f219f210f213/Daughter-of-the-Empire-The-Empire-Trilogy-1-by-Raymond-E-Feist.pdf
    • http://kiteeearpdf.myhome.cx/4f217f211f211f217f216/Servant-of-the-Empire-The-Empire-Trilogy-2-by-Raymond-E-Feist.pdf
    • http://kiteeearpdf.myhome.cx/5f218f219f219f218f211/Mro-Un-empire-sur-le-Nil-Empire-on-the-Nile-by-Guillemette-Andreu-Lanoe.pdf
    • http://kiteeearpdf.myhome.cx/2f213f211f218f214/The-Triumphant-Empire-Thunder-Clouds-Gather-in-the-West-1763-1766-The-British-Empire-before-the-American-Revolution-10-by-Lawrence-Henry-Gipson.pdf
    • http://kiteeearpdf.myhome.cx/1f214f213f218f212f214/Resolute-Determination-Napoleon-and-the-French-Empire-by-Donald-M-G-Sutherland.pdf
    • http://kiteeearpdf.myhome.cx/1f211f219f210f217f215/How-the-Rama-Empire-disappeared-10-000-years-ago-3-magical-tales-from-the-Ramayana-Rama-Empire-2-by-Lakshmi-Hayagriva.pdf
    • http://kiteeearpdf.myhome.cx/5f214f214f217f213f217/Empire-du-Soleil-Empire-of-the-Sun-1-by-J-G-Ballard.pdf
    • http://kiteeearpdf.myhome.cx/1f211f213f215f211f212/The-Empire-The-Empire-1-by-Elizabeth-Lang.pdf
    • http://kiteeearpdf.myhome.cx/2f212f214f214f216f213/An-Empire-Divided-Religion-Republicanism-and-the-Making-of-French-Colonialism-1880-1914-by-J-P-Daughton.pdf
    • http://kiteeearpdf.myhome.cx/1f213f216f213f217f212/The-Codex-Canadensis-and-the-Writings-of-Louis-Nicolas-The-Natural-History-of-the-New-World-Histoire-Naturelle-des-Indes-Occidentales-by-Louis-Nicolas.pdf
    • http://kiteeearpdf.myhome.cx/3f217f213f216f218f218/A-Path-to-Coldness-of-Heart-Dread-Empire-8-Last-Chronicle-of-the-Dread-Empire-3-by-Glen-Cook.pdf
    • http://kiteeearpdf.myhome.cx/8f213f216f210f213f214/Louis-Pasteur-s-Studies-on-Fermentation-The-Diseases-of-Beer-Their-Causes-and-the-Means-of-Preventing-Them-by-Louis-Pasteur.pdf
    • http://kiteeearpdf.myhome.cx/1f211f219f210f210f212f217/Saint-Louis-Saint-Louis-from-Glass-to-Crystal-from-1586-to-Today-by-G-rard-Ingold.pdf
    • http://kiteeearpdf.myhome.cx/6f219f211f214f211f218/Crimson-Empire-Volume-1-Star-Wars-Crimson-Empire-1-by-Mike-Richardson.pdf
    • http://kiteeearpdf.myhome.cx/6f210f217f213f212f217/Louis-Bachelier-s-Theory-of-Speculation-The-Origins-of-Modern-Finance-by-Louis-Bachelier.pdf
    • http://kiteeearpdf.myhome.cx/8f213f216f211f213f217/Louis-Pasteur-The-Life-and-Legacy-of-the-Legendary-French-Scientist-Recognized-as-the-Father-of-Microbiology-by-Charles-River-Editors.pdf