Malicious PDF — malware analysis report

Static analysis result for SHA-256 bf014fa9cdbcf85d…

MALICIOUS

PDF

22.1 KB Created: 2019-05-02 18:23:31 +01:00 Authoring application: mPDF 5.7
MD5: a440a3ee4ad71077b6cece7443966ed7 SHA-1: d4d1cb9b915850e4294c5ec0f39b96ee646d9952 SHA-256: bf014fa9cdbcf85db599d6c300ec16dc61828b626eb87f8f3967994d3359f3fc
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF documents hosted on the domain 'kiteeearpdf.myhome.cx'. This is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/7f219f217f218f210f219/Interpreting-Arnauld-by-Elmar-J-Kremer.pdf
    • http://kiteeearpdf.myhome.cx/7f219f217f217f219f216/A-Troll-Under-the-Bridge-by-D-S-Arnauld.pdf
    • http://kiteeearpdf.myhome.cx/7f219f217f218f210f217/Ang-lique-Arnauld-by-Fabian-Gastellier.pdf
    • http://kiteeearpdf.myhome.cx/7f215f215f219f213f210/The-avenue-in-the-rain---Raconte-moi-une-photo-by-Arnauld-Pontier.pdf
    • http://kiteeearpdf.myhome.cx/1f210f216f214f219f216f211/Die-Briefsammlung-Des-Berard-Von-Neapel-by-Elmar-Fleuchaus.pdf
    • http://kiteeearpdf.myhome.cx/7f219f217f218f210f213/Discourse-on-Metaphysics-Correspondence-with-Arnauld-And-Monadology-by-Gottfried-Wilhelm-Leibniz.pdf
    • http://kiteeearpdf.myhome.cx/1f211f217f214f211f217f211/Schuberts-Liederzyklen-Ein-musikalischer-Werkf-hrer-by-Elmar-Budde.pdf
    • http://kiteeearpdf.myhome.cx/9f219f210f217f219f218/Freddy-Quinn-Ein-unwahrscheinliches-Leben-by-Elmar-Kraushaar.pdf
    • http://kiteeearpdf.myhome.cx/1f210f213f215f212f216f216/Obsessionen-Elf-erotische-Kurzgeschichten-um-Voyeurismus-und-Spa-am-Sex-by-Elmar-Neffe.pdf
    • http://kiteeearpdf.myhome.cx/9f216f215f219f214f216/Ghosts---Or-the-Nearly-Invisible-Spectral-Phenomena-in-Literature-and-the-Media-by-Elmar-Schenkel.pdf
    • http://kiteeearpdf.myhome.cx/1f211f212f214f216f214f211/Die-Freimaurerische-Idee-In-Der-Zauberfl-te-Ein-Spiegelbild-Antiker-Mysterien-by-Elmar-Nordmann.pdf
    • http://kiteeearpdf.myhome.cx/5f215f211f219f215f218/N-gocier-avec-l-Etat-islamique-Plaidoyer-pour-une-Realpolitik-au-Moyen-Orient-by-Arnauld-de-Tocquesaint.pdf
    • http://kiteeearpdf.myhome.cx/1f210f213f215f212f216f214/Mutters-beste-Freundin-Vier-erotische-Geschichten-um-ungew-hnliche-Paarbeziehungen-by-Elmar-Neffe.pdf
    • http://kiteeearpdf.myhome.cx/2f213f216f217f214f214/Interpreting-Sargent-by-Elizabeth-Prettejohn.pdf
    • http://kiteeearpdf.myhome.cx/7f211f218f215f218f217/Conference-Interpreting-Explained-by-Roderick-Jones.pdf
    • http://kiteeearpdf.myhome.cx/2f217f215f211f216f214/Active-Liberty-Interpreting-Our-Democratic-Constitution-by-Stephen-G-Breyer.pdf
    • http://kiteeearpdf.myhome.cx/1f211f214f215f217f219f212/Reading-Autobiography-A-Guide-for-Interpreting-Life-Narratives-by-Sidonie-Smith.pdf
    • http://kiteeearpdf.myhome.cx/3f216f217f213f215f212/A-Basic-Guide-to-Interpreting-the-Bible-Playing-by-the-Rules-by-Robert-H-Stein.pdf
    • http://kiteeearpdf.myhome.cx/9f210f218f217f218f213/Interpreting-Musical-Gestures-Topics-and-Tropes-Mozart-Beethoven-Schubert-by-Robert-S-Hatten.pdf
    • http://kiteeearpdf.myhome.cx/7f217f219f210f218f216/Interpreting-Communicative-Language-Teaching-Contexts-and-Concerns-in-Teacher-Education-by-Sandra-Savignon.pdf