Malicious PDF — malware analysis report

Static analysis result for SHA-256 ead84af815ee9936…

MALICIOUS

PDF

18.0 KB Created: 2020-03-18 21:53:47 +00:00 Authoring application: mPDF 5.7 First seen: 2021-06-20
MD5: 6a2c993b82626542cd1575bf27389cd7 SHA-1: d182939cb6a1183f17351cca893a8a4dd9db293a SHA-256: ead84af815ee993641262a99cc5e51c0fc77796e470f02790e62da2a638abf1d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which suggests a link farm or redirection to malicious content. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the file. The embedded links are likely intended to lead users to phishing sites or download further malware, aligning with a spearphishing attachment attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kitasdyu.myhome.cx/3872870870873876/The-Goblins-of-Bellwater-by-Molly-Ringle.pdf In PDF document text
    • http://kitasdyu.myhome.cx/1875873875875871/Molly-Saves-the-Day-A-Summer-Story-American-Girls-Molly-5-by-Valerie-Tripp.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/3878876874877874/Medical-Crisis-Counseling-Short-Term-Therapy-for-Long-Term-Illness-by-Irene-Pollin.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/9878871878879875/Quarterly-Profits-vs-Long-Term-Strategy-Balancing-Short-Term-Profits-With-Strategic-Growth-by-Lanze-Thompson.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/3872875878870871/Molly-s-Surprise-A-Christmas-Story-American-Girls-Molly-3-by-Valerie-Tripp.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/1875873875877872/Changes-for-Molly-A-Winter-Story-American-Girls-Molly-6-by-Valerie-Tripp.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/1875873875876872/Molly-Learns-a-Lesson-A-School-Story-American-Girls-Molly-2-by-Valerie-Tripp.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/8876871871875/Molly-Moon-s-Hypnotic-Time-Travel-Adventure-Molly-Moon-3-by-Georgia-Byng.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/4877874877871875/Love-One-Summer-in-Bath-A-Regency-Romance-Summer-Collection-8-Delightful-Regency-Summer-Stories-Regency-Romance-Collections-Book-4-by-Arietta-Richmond.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/7878871872879877/Term-Life-by-A-J-Lieberman.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/4872871873874870/The-Summer-Wind-Lowcountry-Summer-2-by-Mary-Alice-Monroe.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/2871878872877871/The-Summer-Girls-Lowcountry-Summer-1-by-Mary-Alice-Monroe.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/1870871871878875874/The-Paleo-Summer-Survival-Guide-12-Must-Have-Recipes-Plus-Insider-Tips-for-a-Healthy-Happy-Summer-by-Julie-Mayfield.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/2877877870873878/End-of-Term-The-Marlows-4-by-Antonia-Forest.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/1870871873874872874/Lorrie-s-First-Term-by-Nora-Mylrea.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/2875871871875875/Term-Limits-by-Vince-Flynn.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/2874877873874873/The-Boys-Of-Summer-Songs-of-Summer-1-by-Ciar-n-West.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/3875874871879876/For-the-Term-of-His-Natural-Life-by-Marcus-Clarke.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/1872879875873871/Second-Term---A-Novel-of-America-in-the-Last-Days-by-John-Price.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/1871876874870870/Last-Summer-Summer-Boys-4-by-Hailey-Abbott.pdfIn PDF document text