Malicious PDF — malware analysis report

Static analysis result for SHA-256 be587871502c15a6…

MALICIOUS

PDF

20.8 KB Created: 2019-05-01 17:59:41 +01:00 Authoring application: mPDF 5.7
MD5: 176af2a51ec30c4b2eec059a2c49daf0 SHA-1: fffd10e5e69671d844729d0d87b9ea2a37898c18 SHA-256: be587871502c15a6a45e67bcaf8b89e0364ece6f42d758ff206012dc8a9b6c2e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDFs hosted on the domain 'kiteeearpdf.myhome.cx'. This is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/1f213f211f213f216f217/Death-Whispers-Death-1-by-Tamara-Rose-Blodgett.pdf
    • http://kiteeearpdf.myhome.cx/4f211f211f216f214f215/Death-Speaks-Death-2-by-Tamara-Rose-Blodgett.pdf
    • http://kiteeearpdf.myhome.cx/2f217f218f218f217f210/Death-Screams-Death-4-by-Tamara-Rose-Blodgett.pdf
    • http://kiteeearpdf.myhome.cx/2f211f218f211f211f217/Blood-Chosen-Blood-3-by-Tamara-Rose-Blodgett.pdf
    • http://kiteeearpdf.myhome.cx/3f218f219f212f210f212/The-Savage-Principle-Savage-3-by-Tamara-Rose-Blodgett.pdf
    • http://kiteeearpdf.myhome.cx/1f215f215f216f217f213/The-Pearl-Savage-Savage-1-by-Tamara-Rose-Blodgett.pdf
    • http://kiteeearpdf.myhome.cx/3f215f218f211f213f210/Angelic-Blood-Blood-5-by-Tamara-Rose-Blodgett.pdf
    • http://kiteeearpdf.myhome.cx/4f210f214f215f215f215/Blood-Song-Blood-2-by-Tamara-Rose-Blodgett.pdf
    • http://kiteeearpdf.myhome.cx/4f216f218f214f211f216/J-D-Robb-4-Book-Series-Collection-Gift-Set-Indulgence-In-Death-Hardcover-Fantasy-In-Death-Kindred-In-Death-Promises-In-Death-In-Death-Series-by-J-D-Robb.pdf
    • http://kiteeearpdf.myhome.cx/4f213f211f219f213/When-Death-Comes-Stealing-Tamara-Hayle-1-by-Valerie-Wilson-Wesley.pdf
    • http://kiteeearpdf.myhome.cx/5f215f216f210f211f210/J-D-Robb-Collection-5-Seduction-in-Death-Reunion-in-Death-and-Purity-in-Death-by-J-D-Robb.pdf
    • http://kiteeearpdf.myhome.cx/5f211f215f213f218f215/Happy-Death-Day---Happy-Death-Day-Jisatsu-ya-Yomiji-to-Satsujinki-Dorian-Happy-Death-Day-1-by-.pdf
    • http://kiteeearpdf.myhome.cx/7f219f217f213f214f211/Death-The-Horsemen-1-by-Lila-Rose.pdf
    • http://kiteeearpdf.myhome.cx/7f216f213f214f213f210/MachoPoni-A-Prance-with-Death-by-Lotus-Rose.pdf
    • http://kiteeearpdf.myhome.cx/4f212f212f216f216f215/Phoenix-Death-Rose-1-by-Melanie-Tushmore.pdf
    • http://kiteeearpdf.myhome.cx/9f210f218f210/An-Easy-Death-Gunnie-Rose-1-by-Charlaine-Harris.pdf
    • http://kiteeearpdf.myhome.cx/8f218f215f218f216f212/Death-is-Not-Enough-Romantic-Suspense-21-Baltimore-6-by-Karen-Rose.pdf
    • http://kiteeearpdf.myhome.cx/4f214f211f217f210f210/Welcome-to-Death-Row-The-Uncensored-Story-of-Death-Row-Records-in-the-Words-of-Those-Who-Were-There-by-S-Leigh-Savidge.pdf
    • http://kiteeearpdf.myhome.cx/2f218f218f212f216f210/Wexford-Omnibus-First-From-Doon-with-Death-New-Lease-of-Death-Best-Man-to-Die-by-Ruth-Rendell.pdf
    • http://kiteeearpdf.myhome.cx/3f215f213f218f215/My-Death-Experiences---A-Preacher-s-18-Apocalyptic-Encounter-with-Death-Heaven-amp-Hell-by-Zion-Odum.pdf