Malicious PDF — malware analysis report

Static analysis result for SHA-256 de0ba177e6dc8daa…

MALICIOUS

PDF

21.4 KB Created: 2019-05-02 18:07:38 +01:00 Authoring application: mPDF 5.7
MD5: 1afe45859383d88dd027f9758fb14e41 SHA-1: 5149d75a5cd665885d425afaac10333a6be109be SHA-256: de0ba177e6dc8daad2a7972f1f686f4e9016ffaf6874ecd3fc8b0701ce4ba077
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF documents hosted on the 'kiteeearpdf.myhome.cx' domain. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be a link farm designed to lure users to potentially malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9900

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/3f217f211f216f217f211/Burke-Davis-on-the-Civil-War-The-Long-Surrender-Sherman-s-March-To-Appomattox-and-They-Called-Him-Stonewall-by-Burke-Davis.pdf
    • http://kiteeearpdf.myhome.cx/5f212f211f215f218f213/Jeb-Stuart-The-Last-Cavalier-by-Burke-Davis.pdf
    • http://kiteeearpdf.myhome.cx/5f218f214f210f212f215/Preface-to-the-Address-of-M-Brissot-to-his-Constituents-Translated-by-the-Late-William-Burke-Esq-1794-by-Edmund-Burke.pdf
    • http://kiteeearpdf.myhome.cx/6f213f210f219f215f219/Odette-Burke-The-Burke-Sisters-1-by-Josephine-Barly.pdf
    • http://kiteeearpdf.myhome.cx/6f211f214f214f215f213/Burke-s-Gamble-Burke-2-by-William-F-Brown.pdf
    • http://kiteeearpdf.myhome.cx/4f219f212f210f217f214/Long-Gone-by-Alafair-Burke.pdf
    • http://kiteeearpdf.myhome.cx/3f216f218f215f211f215/The-Training-Ground-Grant-Lee-Sherman-and-Davis-in-the-Mexican-War-1846-1848-by-Martin-Dugard.pdf
    • http://kiteeearpdf.myhome.cx/1f218f219f219f218/My-Awesome-Place-Autobiography-of-Cheryl-Burke-by-Cheryl-Burke.pdf
    • http://kiteeearpdf.myhome.cx/1f217f215f216f215/A-Gentleman-Called-Mrs-Norris-Mysteries-2-by-Dorothy-Salisbury-Davis.pdf
    • http://kiteeearpdf.myhome.cx/1f211f219f210f212f214f212/Selected-readings-for-management-208-408-for-the-University-of-CA-Davis-by-Scott-Davis.pdf
    • http://kiteeearpdf.myhome.cx/4f218f214f213f212f217/Mo-ne-Davis-Remember-My-Name-My-Story-from-First-Pitch-to-Game-Changer-by-Mo-Davis.pdf
    • http://kiteeearpdf.myhome.cx/7f215f215f213f218f214/James-Lee-Burke-Books-Checklist-Reading-Order-of-Billy-Bob-Holland-Series-Dave-Robicheaux-Series-Hackberry-Holland-Series-and-List-of-All-James-Lee-Burke-Books-Over-35-Books-by-Kevin-Hanson.pdf
    • http://kiteeearpdf.myhome.cx/8f215f210f215f211/The-Civil-War-Vol-3-Red-River-to-Appomattox-by-Shelby-Foote.pdf
    • http://kiteeearpdf.myhome.cx/6f211f214f215f213f214/The-Portable-Edmund-Burke-by-Edmund-Burke.pdf
    • http://kiteeearpdf.myhome.cx/5f211f216f216f213f217/Marching-to-Appomattox-The-Footrace-That-Ended-the-Civil-War-by-Ken-Stark.pdf
    • http://kiteeearpdf.myhome.cx/3f218f216f210f212f218/As-The-Twig-Is-Bent-A-Matt-Davis-Mystery-Matt-Davis-Mysteries-1-by-Joe-Perrone-Jr-.pdf
    • http://kiteeearpdf.myhome.cx/4f219f215f212f210f214/Taylor-Davis-and-the-Flame-of-Findul-Taylor-Davis-1-by-Michelle-Isenhoff.pdf
    • http://kiteeearpdf.myhome.cx/4f219f215f213f216f219/Taylor-Davis-and-the-Clash-of-Kingdoms-Taylor-Davis-2-by-Michelle-Isenhoff.pdf
    • http://kiteeearpdf.myhome.cx/5f210f219f214f218f216/The-Papers-of-Jefferson-Davis-Vol-I-1808-1840-by-Jefferson-Davis.pdf
    • http://kiteeearpdf.myhome.cx/5f210f214f212f214f212/Stonewall-s-Gold-A-Novel-of-the-Civil-War-by-Robert-J-Mrazek.pdf
    • http://kiteeearpdf.myhome.cx/3f216f218f215f211f215/The-Training-Ground-Grant-Lee-Sherman-and-Dav