Malicious PDF — malware analysis report

Static analysis result for SHA-256 c5259b12f540f889…

MALICIOUS

PDF

31.5 KB Created: 2019-05-02 05:03:36 +01:00 Authoring application: mPDF 5.7
MD5: 236a409d5dd12db0995f6c512794ed97 SHA-1: 39f2af51596a1f6ffaf49d0ca0c24439100c112e SHA-256: c5259b12f540f889ca338033c632fe4cf5e86cb9e0c564ca4d6916f5135796f1
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links. The heuristic PDF_SEO_LINK_FARM indicates a link farm, suggesting the document's primary purpose is to redirect users to potentially harmful websites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/8f214f213f210f211f217/Essais-Sur-L-Eglise-Manicheenne-En-Afrique-Du-Nord-Et-a-Rome-Au-Temps-de-Saint-Augustin-Recueil-D-Etudes-by-Fran-ois-Decret.pdf
    • http://kiteeearpdf.myhome.cx/5f217f214f212f213f216/Protee-Noir-Essais-Sur-La-Litterature-Francophone-de-L-Afrique-Noire-Et-Des-Antilles-by-Peter-Hawkins.pdf
    • http://kiteeearpdf.myhome.cx/7f211f214f219f213f212/Le-Temps-Jaune-Essais-Sur-Corbi-re-by-Marshall-Lindsay.pdf
    • http://kiteeearpdf.myhome.cx/8f214f213f210f211f218/Early-Christianity-in-North-Africa-by-Fran-Decret.pdf
    • http://kiteeearpdf.myhome.cx/6f211f211f217f215f215/Histoire-de-l-Afrique-du-Nord-Des-origines-nos-jours-by-Bernard-Lugan.pdf
    • http://kiteeearpdf.myhome.cx/8f212f211f217f217f215/Histoire-Des-Juifs-En-Afrique-Du-Nord-Tome-1-En-Exil-Au-Maghreb-by-Andr-Chouraqui.pdf
    • http://kiteeearpdf.myhome.cx/8f212f211f217f217f213/Histoire-Des-Juifs-En-Afrique-Du-Nord-Tome-2-Retour-En-Orient-by-Andr-Chouraqui.pdf
    • http://kiteeearpdf.myhome.cx/6f219f210f219f214f217/Moral-Treatises-of-Saint-Augustin-by-Augustine-of-Hippo.pdf
    • http://kiteeearpdf.myhome.cx/8f214f216f210f214f219/When-Etudes-Become-Form-Paris-New-York-and-the-Intersection-of-Fashion-and-Art-by-Etudes.pdf
    • http://kiteeearpdf.myhome.cx/8f214f216f211f218f218/Etudes-philosophiques-et-tudes-analytiques-S-raphita-by-Honor-de-Balzac.pdf
    • http://kiteeearpdf.myhome.cx/5f218f212f213f216f218/Dictionnaire-Royal-Fran-ois-Et-Anglois-Le-Fran-ois-Tir-Des-Dictupdnaires-de-Richelet-Furetiere-Tachard-de-l-Academie-Fran-oise-amp-Des-Remarques-de-Vaugelas-Menage-amp-Bouhours-Divis-En-Deux-Parties-Par-Monsieur-Boyer-of-2-Volume-2-by-Abel-Boyer.pdf
    • http://kiteeearpdf.myhome.cx/5f218f212f213f216f217/Dictionnaire-Royal-Fran-ois-Et-Anglois-Le-Fran-ois-Tir-Des-Dictupdnaires-de-Richelet-Furetiere-Tachard-de-l-Academie-Fran-oise-amp-Des-Remarques-de-Vaugelas-Menage-amp-Bouhours-Divis-En-Deux-Parties-Par-Monsieur-Boyer-of-2-Volume-2-by-Abel-Boyer.pdf
    • http://kiteeearpdf.myhome.cx/5f215f215f217f212f219/-cueils-du-temps-Les-La-Suite-du-temps-3-by-Daniel-Sernine.pdf
    • http://kiteeearpdf.myhome.cx/5f215f215f217f215f211/Archipels-du-temps-Les-La-Suite-du-temps--2-by-Daniel-Sernine.pdf
    • http://kiteeearpdf.myhome.cx/6f219f211f210f212f211/Organizing-the-Revolution-Selections-from-Augustin-Cochin-by-Augustin-Cochin.pdf
    • http://kiteeearpdf.myhome.cx/7f217f216f219f216f219/Strasse-in-Paris-Avenue-Des-Champs-Elysees-Rue-de-La-Pompe-Rue-Saint-Denis-Rue-Du-Bac-Boulevard-Peripherique-Avenue-Foch-Boulevard-Saint-Michel-Rue-de-Rivoli-Axe-Historique-Rue-de-La-Tour-Rue-Saint-Honore-Rue-Saint-Antoine-by-Quelle-Wikipedia.pdf
    • http://kiteeearpdf.myhome.cx/9f214f213f218f213f215/Dictionary-for-Automotive-Engineering-Dictionnaire-Du-G-nie-Automobile-W-rterbuch-F-r-Kraftfahrzeugtechnik-English-French-German-with-Explanations-of-French-and-German-Terms-Anglais-Fran-ais-Allemand-Avec-D-finitions-Des-Termes-Fran-ais-Et-Allem-by-Jean-de-Coster.pdf
    • http://kiteeearpdf.myhome.cx/5f217f211f215f214f215/La-Longue-Tra-ne-Essais-by-Chris-Anderson.pdf
    • http://kiteeearpdf.myhome.cx/2f219f212f218f219f214/Dying-for-Rome-Lucretia-s-Tale-Short-Tales-of-Ancient-Rome-1-by-Elisabeth-Storrs.pdf
    • http://kiteeearpdf.myhome.cx/4f214f218f212f218f215/The-History-of-Rome-Books-31-45-Rome-and-the-Mediterranean-by-Livy.pdf
    • http://kiteeearpdf.myhome.cx/