Malicious PDF — malware analysis report

Static analysis result for SHA-256 b4f7c751b96437ea…

MALICIOUS

PDF

21.2 KB Created: 2019-05-02 17:44:11 +01:00 Authoring application: mPDF 5.7
MD5: e0d050b259625a9ee9e2dc19d24a0b25 SHA-1: c65e078ac488c52cad69d9353ac2385402de2e16 SHA-256: b4f7c751b96437ea6c44fdaf1197c9e3b51583106c68fead5adbdef74c9a9c6e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS classifier also flagged this document with high confidence. The embedded URLs point to a domain that appears to be used for distributing or linking to various documents, suggesting a link farm or a distribution point for further malicious activity. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9939

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/1f211f219f215f213f215f215/Making-the-Grade-Everything-Your-4th-Grader-Needs-to-Know-by-Micki-Pflug.pdf
    • http://kiteeearpdf.myhome.cx/1f211f219f215f214f215f211/Yaddo-Making-American-Culture-by-Micki-McGee.pdf
    • http://kiteeearpdf.myhome.cx/4f210f212f217f218f213/Making-the-Grade-Talented-Boys-3-by-John-Shepherd.pdf
    • http://kiteeearpdf.myhome.cx/5f216f214f211f219f210/First-Grade-Fun-Fitness-Learning-Grade-1-by-Sabena-Maiden.pdf
    • http://kiteeearpdf.myhome.cx/1f210f212f213f211f216f216/30-Websites-for-Sixth-Grade-Independent-Learning-Activities-Sixth-Grade-Enrichment-Series-by-David-Harstad.pdf
    • http://kiteeearpdf.myhome.cx/9f214f214f214f217f210/Wie-man-talentierte-Sportpferde-total-vermurkst-by-Eva-Pflug.pdf
    • http://kiteeearpdf.myhome.cx/9f216f217f211f213f211/Soap-Making-Soap-Making-for-Beginners---How-to-Make-Hand-Soap-In-Your-House-Like-a-Pro-Soap-Making-Soap-Making-Book-Crafts-Soap-Making-Recipes-Hand-Made-Soap-by-Melani-Penn.pdf
    • http://kiteeearpdf.myhome.cx/2f215f216f217f212f219/Miles-to-Go-Before-I-Sleep-My-Grateful-Journey-Back-from-the-Hijacking-of-Eqyptair-Flight-648-by-Jackie-Nink-Pflug.pdf
    • http://kiteeearpdf.myhome.cx/9f216f217f212f213f219/Soap-Making-How-to-Make-Hand-Soap-in-Your-House-Like-a-Pro-Soap-Making-Soap-Making-Book-Soap-Making-Guide-Soap-Making-Recipes-How-to-Make-Soap-by-Melani-Penn.pdf
    • http://kiteeearpdf.myhome.cx/7f213f219f216f215/Junie-B-First-Grader-Toothless-Wonder-Junie-B-Jones-20-by-Barbara-Park.pdf
    • http://kiteeearpdf.myhome.cx/1f211f214f219f218f217f219/Soap-Making-A-Quick-Soap-Making-Book-Including-Homemade-Soap-Recipes-Soap-Making-Supplies-Lye-Process-and-More-by-Kelly-Kohn.pdf
    • http://kiteeearpdf.myhome.cx/4f214f214f212f211f210/The-Cheri-Grade-Compendium-by-Cheri-Grade.pdf
    • http://kiteeearpdf.myhome.cx/1f211f219f215f215f218f210/The-Ugly-Snowflake-by-Micki-Mchay.pdf
    • http://kiteeearpdf.myhome.cx/1f211f219f215f215f212f216/Becoming-The-Chef-Your-Dog-Thinks-You-Are-by-Micki-Voisard.pdf
    • http://kiteeearpdf.myhome.cx/1f211f219f215f212f217f211/Before-the-Daisies-Grow-by-Micki-Street.pdf
    • http://kiteeearpdf.myhome.cx/3f212f218f218f218f218/And-the-Whippoorwill-Sang-by-Micki-Peluso.pdf
    • http://kiteeearpdf.myhome.cx/4f210f211f210f210f216/Grace-the-Maid-by-Micki-Street.pdf
    • http://kiteeearpdf.myhome.cx/1f211f219f215f215f212f218/Escapades-of-Glamour-Grannies-by-Micki-Street.pdf
    • http://kiteeearpdf.myhome.cx/1f211f219f215f215f212f215/Before-the-Blood-Moon-Wanes-by-Micki-Hogan.pdf
    • http://kiteeearpdf.myhome.cx/1f211f219f215f213f214f216/micki-2-prisoners-of-lust-by-J-rg-Meyer-Bothling.pdf
    • http://kiteeearpdf.myhome.cx/9f216f217f211f213f211/Soap-Making-Soap-Making-for-Beginners---How-to-Make-Hand-Soap-In-Your-Ho