Malicious PDF — malware analysis report

Static analysis result for SHA-256 c0b97470c0aee0f0…

MALICIOUS

PDF

16.7 KB Created: 2019-05-01 17:18:04 +01:00 Authoring application: mPDF 5.7 First seen: 2020-12-28
MD5: 235e9b7122f48bc04d1f62cc9268838f SHA-1: 6fb56bc6b93ce42fdc2449e0a6a20a7d6307667b SHA-256: c0b97470c0aee0f0692c1145dbcc60eeb7a080beca760ad59a2f600aac7eebb1
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF contains a large number of embedded URLs, identified as a link farm, which is a common technique for SEO poisoning or distributing malicious content. The embedded URLs point to external sites that appear to be disguised as book downloads, likely serving as a lure to direct users to potentially malicious content or phishing pages. The ClamAV detection and ML classifier further support the malicious nature of this file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-9742520-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-9742520-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/3f213f211f215f219f215/Dessa-Rose-by-Sherley-Anne-Williams.pdf In PDF document text
    • http://kiteeearpdf.myhome.cx/1f215f218f219f211f217/The-Second-Blush-Poems-by-Molly-Peacock.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/1f213f216f214f218f213/The-Collected-Poems-of-Williams-Carlos-Williams-1939-1962-by-William-Carlos-Williams.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/4f215f218f218f212f218/Selected-Poems-by-C-K-Williams.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/8f214f213f217f217/Selected-Poems-by-William-Carlos-Williams.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/4f217f213f217f218/Immortal-Poems-of-the-English-Language-by-Oscar-Williams.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/4f219f213f217f217f215/Pirate-Spirit-The-Adventures-of-Anne-Bonney-by-Jeffery-S-Williams.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/5f210f218f219f212f218/Floating-City-Poems-by-Anne-Pierson-Wiese.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/8f215f217f218f215f219/Anne-of-Windy-Poplars-Anne-s-House-of-Dreams-Anne-of-Ingleside-Anne-of-Green-Gables-4-6-by-L-M-Montgomery.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/1f213f217f216f215f214/Asphodel-That-Greeny-Flower-and-Other-Love-Poems-That-Greeny-Flower-by-William-Carlos-Williams.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/3f210f218f213f212f214/Williams-Sonoma-New-American-Cooking-The-Best-of-Contemporary-Regional-Cuisines-by-Chuck-Williams.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/4f217f218f211f214f214/The-Peacock-s-Eye-by-Jay-Lewis-Taylor.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/1f211f212f211f216f219f210/The-White-Peacock-by-D-H-Lawrence.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/1f219f214f217f210f213/Willowgrove-Hemlock-3-by-Kathleen-Peacock.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/2f218f216f211f217f210/The-Peacock-Prince-by-John-Tristan.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/3f218f214f218f215f218/Life-Without-Water-by-Nancy-Peacock.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/3f214f213f217f218f218/A-Footman-for-the-Peacock-by-Rachel-Ferguson.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/1f214f215f214f213f212/The-Peacock-Throne-by-Sujit-Saraf.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/1f216f219f210f212/A-Cure-for-Night-by-Justin-Peacock.pdfIn PDF document text
    • http://kiteeearpdf.myhome.cx/4f212f212f212f210f218/The-Golden-Peacock-by-Lauren-B-Grossman.pdfIn PDF document text