Malicious PDF — malware analysis report

Static analysis result for SHA-256 f56c3186940328df…

MALICIOUS

PDF

20.1 KB Created: 2019-05-01 17:04:27 +01:00 Authoring application: mPDF 5.7
MD5: 3151a5ceab62d4d0fbb6554aa5193039 SHA-1: eda8ac2a3a0ad7ba9e026b0d4af723b0bacebd1d SHA-256: f56c3186940328df615d38690544f49ab1cd1feaadf145f04802d0c07a448277
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The primary attack pattern appears to be a link farm designed to direct users to external resources, potentially for SEO manipulation or to distribute further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/5f218f218f219f212f210/Terminal-Paradox-The-Novels-of-Milan-Kundera-by-Maria-Nemcova-Baberjee.pdf
    • http://kiteeearpdf.myhome.cx/5f218f219f210f210f217/The-Milan-Kundera-Handbook---Everything-You-Need-to-Know-about-Milan-Kundera-by-Curtis-Stout.pdf
    • http://kiteeearpdf.myhome.cx/3f216f218f212f213/The-Joke-by-Milan-Kundera.pdf
    • http://kiteeearpdf.myhome.cx/9f216f210f214f219f216/Elu-on-mujal-by-Milan-Kundera.pdf
    • http://kiteeearpdf.myhome.cx/2f219f217f216f211f216/The-Unbearable-Lightness-of-Being-by-Milan-Kundera.pdf
    • http://kiteeearpdf.myhome.cx/5f218f210f215f211/The-Festival-of-Insignificance-by-Milan-Kundera.pdf
    • http://kiteeearpdf.myhome.cx/5f218f218f218f212f212/Milan-Kundera-by-Helena-Koskov-.pdf
    • http://kiteeearpdf.myhome.cx/9f215f211f218f212f217/A-Insustent-vel-Leveza-do-Ser-by-Milan-Kundera.pdf
    • http://kiteeearpdf.myhome.cx/1f217f212f210f212f219/The-Unbearable-Lightness-of-Being-by-Milan-Kundera.pdf
    • http://kiteeearpdf.myhome.cx/5f218f219f210f212f212/Lire-Milan-Kundera-by-Martine-Boyer-Weinmann.pdf
    • http://kiteeearpdf.myhome.cx/5f218f218f219f217f212/The-Joke-by-Milan-Kundera-Lesson-Plans-by-BookRags.pdf
    • http://kiteeearpdf.myhome.cx/7f216f219f214f211/Jacques-and-His-Master-An-Homage-to-Diderot-in-Three-Acts-by-Milan-Kundera.pdf
    • http://kiteeearpdf.myhome.cx/5f218f218f219f214f212/The-Joke-by-Milan-Kundera-Summary-amp-Study-Guide-by-BookRags.pdf
    • http://kiteeearpdf.myhome.cx/5f218f219f210f212f211/The-Book-of-Imitation-and-Desire-Reading-Milan-Kundera-with-Rene-Girard-by-Trevor-Cribben-Merrill.pdf
    • http://kiteeearpdf.myhome.cx/5f218f219f210f211f216/Migration-and-Literature-G-nter-Grass-Milan-Kundera-Salman-Rushdie-and-Jan-Kj-rstad-by-S-ren-Frank.pdf
    • http://kiteeearpdf.myhome.cx/2f214f210f211f212f219/House-of-Mist-and-the-Shrouded-Woman-Two-Novels-Two-Novels-by-Maria-Luisa-Bombal-by-Mar-a-Luisa-Bombal.pdf
    • http://kiteeearpdf.myhome.cx/7f218f219f212f217f212/The-Novels-of-Maria-Edgeworth-Leonora-Ennui-by-Maria-Edgeworth.pdf
    • http://kiteeearpdf.myhome.cx/1f211f213f211f214f212f211/Milan-s-M-rchenbuch-Bekannte-M-rchen-neu-und-gewaltfrei-erz-hlt-mit-Milan-als-Hauptperson-Personenbezogenes-Kinderbuch-by-Lana-Stern.pdf
    • http://kiteeearpdf.myhome.cx/9f216f215f217f214f219/-the-Novels-of-Erich-Maria-Remarque-Sparks-of-Life-by-Brian-Murdoch.pdf
    • http://kiteeearpdf.myhome.cx/9f216f215f217f214f218/Heroism-and-Friendship-in-the-Novels-of-Erich-Maria-Remarque-by-Haim-Gordon.pdf
    • http://kiteeearpdf.myhome.cx/5