Malicious PDF — malware analysis report

Static analysis result for SHA-256 f573bb594d370ed3…

MALICIOUS

PDF

21.0 KB Created: 2019-05-01 17:33:07 +01:00 Authoring application: mPDF 5.7
MD5: d203aaf0e7d16fcb6c77998d2536bfae SHA-1: b6f18e36570909f122e86313c1113e33e368c6d5 SHA-256: f573bb594d370ed3a79af542923c9b357818dccc6d14ae7d5a978e38de6a52c1
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDFs on the domain 'kiteeearpdf.myhome.cx'. This heuristic, combined with the ML classifier's high confidence, indicates a malicious intent to redirect users to potentially harmful content. No scripts were extracted, and the document body was unreadable, but the link farm strongly suggests a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/3f213f211f212f213f216/Three-Seasons-Three-Stories-of-England-in-the-Eighties-by-Mike-Robbins.pdf
    • http://kiteeearpdf.myhome.cx/1f215f211f218f217f212/Dog-by-Mike-Robbins.pdf
    • http://kiteeearpdf.myhome.cx/3f215f213f211f210f213/Be-Yourself-Everyone-Else-Is-Already-Taken-Transform-Your-Life-with-the-Power-of-Authenticity-by-Mike-Robbins.pdf
    • http://kiteeearpdf.myhome.cx/5f218f213f211f212f210/Tony-Robbins-His-Best-Insights-tony-robbins-anthony-robbins-unleash-the-power-within-unlimited-power-bandler-nlp-hypnosis-success-by-Jim-Bandler.pdf
    • http://kiteeearpdf.myhome.cx/2f211f214f211f213f213/Psycho-Logical-The-Short-Stories-of-Mike-Miller-Book-1-by-Mike-Miller.pdf
    • http://kiteeearpdf.myhome.cx/4f218f216f216f219f210/Seasons-The-Complete-Seasons-of-Betrayal-Series-by-Bethany-Kris.pdf
    • http://kiteeearpdf.myhome.cx/1f210f216f211f210f215f218/After-Andy-Soho-in-the-Eighties-by-Paul-Taylor.pdf
    • http://kiteeearpdf.myhome.cx/6f212f217f218f210f217/Why-the-Devil-Chose-New-England-for-His-Work-Stories-by-Jason-Brown.pdf
    • http://kiteeearpdf.myhome.cx/5f212f212f214f214f214/Getting-It-in-the-Head-Stories-by-Mike-McCormack.pdf
    • http://kiteeearpdf.myhome.cx/4f212f211f218f214f218/Seasons-in-the-Mist-Seasons-of-Destiny-1-by-Deborah-Kinnard.pdf
    • http://kiteeearpdf.myhome.cx/6f215f214f212f212f216/All-in-the-Best-Possible-Taste-Growing-Up-Watching-Telly-in-the-Eighties-by-Tom-Bromley.pdf
    • http://kiteeearpdf.myhome.cx/2f213f217f215f218f216/Victorian-Ghost-Stories-by-Mike-Stocks.pdf
    • http://kiteeearpdf.myhome.cx/3f210f217f218f219f217/The-Greatest-Joker-Stories-Ever-Told-by-Mike-Gold.pdf
    • http://kiteeearpdf.myhome.cx/4f216f212f212f217f212/Hellboy-The-Complete-Short-Stories-Volume-2-by-Mike-Mignola.pdf
    • http://kiteeearpdf.myhome.cx/5f218f212f216f210f214/Chronicles-of-England-Scotland-and-Ireland-2-of-6-England-5-of-12-Henrie-the-Second-by-Raphael-Holinshed.pdf
    • http://kiteeearpdf.myhome.cx/3f213f218f216f215f218/Weird-England-Your-Travel-Guide-to-England-s-Local-Legends-and-Best-Kept-Secrets-by-Matt-Lake.pdf
    • http://kiteeearpdf.myhome.cx/8f212f211f213f216f219/Passenger-Ships-of-England-Ferries-of-England-Mersey-Ferry-MS-Riverdance-Mv-Royal-Iris-Cowes-Floating-Bridge-PS-Lincoln-Castle-by-Source-Wikipedia.pdf
    • http://kiteeearpdf.myhome.cx/1f210f215f217f218f212f213/New-England-Nightwalkers-Collection-New-England-Nightwalkers-1-To-3-by-Chloe-Cole.pdf
    • http://kiteeearpdf.myhome.cx/4f215f217f219f215f216/Mike-Mike-amp-Me-by-Wendy-Markham.pdf
    • http://kiteeearpdf.myhome.cx/7f212f212f211f219f215/England-My-England-by-D-H-Lawrence.pdf
    • http://kiteeearpdf.myhome.cx/4f218f216f21