Malicious PDF — malware analysis report

Static analysis result for SHA-256 e3d52f982811f5f9…

MALICIOUS

PDF

18.1 KB Created: 2019-05-01 17:14:19 +01:00 Authoring application: mPDF 5.7
MD5: 2008a7ff9dc903be9c14394f11503776 SHA-1: 12117f3bb3b6cf4748c1ca2f98b09c7a3135fe59 SHA-256: e3d52f982811f5f97af6f4a1f52030356b4409bfa2c7fbef5d2ef87505b7431f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'kiteeearpdf.myhome.cx'. This is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/9f218f214f215f219/Fracture-Fracture-1-by-Megan-Miranda.pdf
    • http://kiteeearpdf.myhome.cx/5f218f210f212f211f219/Fracture-Fracture-1-by-Megan-Miranda.pdf
    • http://kiteeearpdf.myhome.cx/3f216f214f211f217/According-to-Queeney-by-Beryl-Bainbridge.pdf
    • http://kiteeearpdf.myhome.cx/1f211f217f215f218f216f218/An-Atlas-of-Functions-With-Equator-the-Atlas-Function-Calculator-by-Jerome-Spanier.pdf
    • http://kiteeearpdf.myhome.cx/6f218f215f210f216f211/Atlas-Du-Monde-Arabo-Islamique-A-L-Epoque-Classique-Ixe-Xe-Siecles-1-Atlas-2-Repertoire-Des-Toponymes-by-G-Cornu.pdf
    • http://kiteeearpdf.myhome.cx/1f211f217f219f212f217f211/Atlas-of-Shrinking-Cities-Atlas-Der-Schrumpfenden-Stadte-by-Tim-Rieniets.pdf
    • http://kiteeearpdf.myhome.cx/6f215f215f217f218f219/Atlas-Atlas-1-by-Becca-C-Smith.pdf
    • http://kiteeearpdf.myhome.cx/6f215f215f217f219f210/ATLAS-3-Atlas-3-by-Isaac-Hooke.pdf
    • http://kiteeearpdf.myhome.cx/7f219f217f215f212f217/La-Fracture-by-Gilles-Kepel.pdf
    • http://kiteeearpdf.myhome.cx/2f214f214f213f215f215/Vengeance-Fracture-2-by-Megan-Miranda.pdf
    • http://kiteeearpdf.myhome.cx/3f211f215f212f213f217/Fracture-The-Soterians-3-by-Jacquelyn-Wheeler.pdf
    • http://kiteeearpdf.myhome.cx/8f213f213f214f211f212/Pilon-Tibial-Fracture-by-U-Heim.pdf
    • http://kiteeearpdf.myhome.cx/9f212f210f216f217/Johnny-Fracture-by-Waheed-Ibne-Musa.pdf
    • http://kiteeearpdf.myhome.cx/5f219f215f215f218/Fracture-The-Secret-Enemy-Saga-1-by-Virginia-McKevitt.pdf
    • http://kiteeearpdf.myhome.cx/9f215f219f212f218f219/Emerald-s-Fracture-Isles-of-Stone-1-by-Kate-Kennelly.pdf
    • http://kiteeearpdf.myhome.cx/1f210f216f213f213f218f216/Atlas-Anthology-Three-Atlas-Anthology-3-by-Alastair-Brotchie.pdf
    • http://kiteeearpdf.myhome.cx/2f217f213f213f217f218/Fracture-Barack-Obama-the-Clintons-and-the-Racial-Divide-by-Joy-Ann-Reid.pdf
    • http://kiteeearpdf.myhome.cx/6f212f214f213f212f219/La-grande-fracture-Les-soci-t-s-in-galitaires-et-ce-que-nous-pouvons-faire-pour-les-changer-by-Joseph-E-Stiglitz.pdf
    • http://kiteeearpdf.myhome.cx/1f211f215f210f217f218f212/The-Crack-Tip-Opening-Displacement-in-Elastic-Plastic-Fracture-Mechanics-Proceedings-of-the-Workshop-on-the-Ctod-Methodology-Gkss-Forschungszentrum-by-Karlheinz-Schwalbe.pdf
    • http://kiteeearpdf.myhome.cx/4f212f212f215f219/Mom-What-s-That-by-Atlas-Jordan.pdf
    • http://kiteeearpdf.myhome.cx/7f219f217f215f212f217/L