Malicious PDF — malware analysis report

Static analysis result for SHA-256 ec2fd62c820bac6c…

MALICIOUS

PDF

20.3 KB Created: 2019-05-01 18:45:50 +01:00 Authoring application: mPDF 5.7
MD5: e4b89127e7a7b269db883350727e2cee SHA-1: 5d66bc05eae33782246bed94d0b409060782fbb1 SHA-256: ec2fd62c820bac6cd291c0cbdc2978300803f8a6e96a7ab038b8c49ed84d1fdf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged as malicious by an ML classifier and contains a large number of embedded external links. The heuristic 'PDF_SEO_LINK_FARM' indicates these links are likely part of a link farm designed to direct users to potentially malicious content. No scripts were extracted from this sample, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/8f213f211f210f213/1001-Midnights-The-Aficionado-s-Guide-to-Mystery-and-Detective-Fiction-by-Bill-Pronzini.pdf
    • http://kiteeearpdf.myhome.cx/8f213f211f210f211/Son-of-Gun-in-Cheek-An-Affectionate-Guide-to-More-of-the-quot-Worst-quot-in-Mystery-Fiction-by-Bill-Pronzini.pdf
    • http://kiteeearpdf.myhome.cx/3f219f212f216f213f215/Labyrinth-Nameless-Detective-6-by-Bill-Pronzini.pdf
    • http://kiteeearpdf.myhome.cx/4f213f211f217f218/Sentinels-Nameless-Detective-23-by-Bill-Pronzini.pdf
    • http://kiteeearpdf.myhome.cx/2f216f219f211f216f214/Demons-Nameless-Detective-21-by-Bill-Pronzini.pdf
    • http://kiteeearpdf.myhome.cx/1f216f215f215f219/What-about-Murder-1981-1991-A-Guide-to-Books-about-Mystery-and-Detective-Fiction-by-Jon-L-Breen.pdf
    • http://kiteeearpdf.myhome.cx/3f211f215f219f210/Deadly-Directory-1999-Your-Complete-Guide-to-the-International-Mystery-Crime-and-Detective-Fiction-Community-by-Kate-Derie.pdf
    • http://kiteeearpdf.myhome.cx/5f218f213f216f211f216/Masques-by-Bill-Pronzini.pdf
    • http://kiteeearpdf.myhome.cx/1f217f210f219f210/A-Wasteland-of-Strangers-by-Bill-Pronzini.pdf
    • http://kiteeearpdf.myhome.cx/3f216f218f215f216f213/The-Ghosts-of-Ragged-Ass-Gulch-by-Bill-Pronzini.pdf
    • http://kiteeearpdf.myhome.cx/3f215f216f219/Eve-of-a-Hundred-Midnights-The-Star-Crossed-Love-Story-of-Two-WWII-Correspondents-and-their-Epic-Escape-Across-the-Pacific-by-Bill-Lascher.pdf
    • http://kiteeearpdf.myhome.cx/4f218f211f210f213f214/Ghosts-of-Midnights-Past-The-Skeptics-Guide-to-Love-2-by-Jessica-Arden.pdf
    • http://kiteeearpdf.myhome.cx/2f217f211f212f215/By-a-Woman-s-Hand-A-Guide-to-Mystery-Fiction-by-Women-by-Dean-A-James.pdf
    • http://kiteeearpdf.myhome.cx/4f210f217f211f219f217/Fables-1001-Nights-of-Snowfall-by-Bill-Willingham.pdf
    • http://kiteeearpdf.myhome.cx/3f217f211f219f216f214/The-Return-of-Sherlock-Holmes-by-Arthur-Conan-Doyle-Fiction-Mystery-amp-Detective-by-Arthur-Conan-Doyle.pdf
    • http://kiteeearpdf.myhome.cx/2f215f215f218f219f210/Talking-About-Detective-Fiction-by-P-D-James.pdf
    • http://kiteeearpdf.myhome.cx/4f211f211f216f216f214/Gray-Ghost-Bill-Dix-Detective-1-by-C-L-Swinney.pdf
    • http://kiteeearpdf.myhome.cx/4f212f218f214f213f212/The-Cartel-Enforcers-Bill-Dix-Detective-2-by-C-L-Swinney.pdf
    • http://kiteeearpdf.myhome.cx/2f216f216f219f210f214/Sin-City-Assassin-Bill-Dix-Detective-3-by-C-L-Swinney.pdf
    • http://kiteeearpdf.myhome.cx/1f213f217f217f218f212/Bill-Bergson-Master-Detective-by-Astrid-Lindgren.pdf
    • http://kiteeearpdf.myhome.cx/1f216f215f215f219/What-about-Murder-1981-1991-A-Guide-to-Books-about-Mystery-and-Detective