Malicious PDF — malware analysis report

Static analysis result for SHA-256 c92204dd0aebd81a…

MALICIOUS

PDF

15.9 KB Created: 2020-03-19 03:48:00 +00:00 Authoring application: mPDF 5.7
MD5: 149e53af1f515c24cbe15f73e8f72cc7 SHA-1: 066a9d2d23fa29dd50573da938905190c12c06bd SHA-256: c92204dd0aebd81a936d8ba2ea2ce5481eae8ae77d58794fda85fb25e3478a52
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing:Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs pointing to external PDF files on the domain kitasdyu.myhome.cx. This is indicative of a link farm or SEO poisoning attack, designed to drive traffic to the malicious domain. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kitasdyu.myhome.cx/3872878878878/The-Celestine-Prophecy-Celestine-Prophecy-1-by-James-Redfield.pdf
    • http://kitasdyu.myhome.cx/7872870873873874/The-Song-of-Celestine-Inspired-by-quot-The-Celestine-Prophecy-quot-by-James-Redfield.pdf
    • http://kitasdyu.myhome.cx/7872870873874870/Messages-of-the-Celestine-Prophecy-by-James-Redfield.pdf
    • http://kitasdyu.myhome.cx/7872870873873873/The-Celestine-Prophecy-An-Experiential-Guide-by-James-Redfield.pdf
    • http://kitasdyu.myhome.cx/7872870873873875/The-Celestine-Prophecy-A-Pocket-Guide-to-the-Nine-Insights-by-James-Redfield.pdf
    • http://kitasdyu.myhome.cx/9872870870879870/Die-zehnte-Prophezeiung-von-Celestine-Das-zweite-Buch-von-Celestine-Die-Prophezeiungen-von-Celestine-by-James-Redfield.pdf
    • http://kitasdyu.myhome.cx/1876877876879872/The-Twelfth-Insight-The-Hour-of-Decision-Celestine-Prophecy-4-by-James-Redfield.pdf
    • http://kitasdyu.myhome.cx/5874872879878/Prophecy-s-Child-Prophecy-2-by-Brenda-Dyer.pdf
    • http://kitasdyu.myhome.cx/5870878877874876/Smile-Ernest-and-Celestine-by-Gabrielle-Vincent.pdf
    • http://kitasdyu.myhome.cx/8875871872875878/Ernest-et-celestine-ont-des-poux-by-Vincent-Gabrielle.pdf
    • http://kitasdyu.myhome.cx/6878878879871872/Bravo-Ernest-and-Celestine-by-Gabrielle-Vincent.pdf
    • http://kitasdyu.myhome.cx/1870878873878870870/Chasing-Prophecy-by-James-A-Moser.pdf
    • http://kitasdyu.myhome.cx/1876872874872876/Prophecy-Prophecy-1-by-Lea-Kirk.pdf
    • http://kitasdyu.myhome.cx/3877879876878/Prophecy-of-the-Sisters-Prophecy-of-the-Sisters-1-by-Michelle-Zink.pdf
    • http://kitasdyu.myhome.cx/2879873870879878/Forsaken-Kingdom-City-of-Prophecy-by-Peter-James-Dudek.pdf
    • http://kitasdyu.myhome.cx/5871872871874874/Children-My-Children-by-Celestine-Sibley.pdf
    • http://kitasdyu.myhome.cx/2874873877874870/Prophecy-Moon-by-Laura-Eno.pdf
    • http://kitasdyu.myhome.cx/7879871875879878/The-Prophecy-by-Ananda-Liyanage.pdf
    • http://kitasdyu.myhome.cx/3872870878879879/Prophecy-Arkane-2-by-J-F-Penn.pdf
    • http://kitasdyu.myhome.cx/1873878876878876/The-Prophecy-Animorphs-34-by-K-A-Applegate.pdf
    • http://kitasdyu.myhome.cx/1876877