Malicious PDF — malware analysis report

Static analysis result for SHA-256 f637088fc4cb5c5b…

MALICIOUS

PDF

20.6 KB Created: 2019-05-02 05:06:11 +01:00 Authoring application: mPDF 5.7
MD5: 989eb59651d70dbc1924ff6a571120d8 SHA-1: e3202b7d48cbfd7bc634712d9d7472a789947cdf SHA-256: f637088fc4cb5c5be97d5073e32ed179d783ebdb73302653a80141c00f5b8793
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged as malicious by an ML classifier and contains a large number of embedded external links. The heuristic 'PDF_SEO_LINK_FARM' indicates a link farm, suggesting these URLs are intended to lead users to potentially harmful content. The presence of numerous links to external PDFs, many with book-like titles, points towards a social engineering tactic to lure victims. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/9f213f215f219f216f214/Perspectives-on-American-Music-1900-1950-by-Michael-Saffle.pdf
    • http://kiteeearpdf.myhome.cx/1f215f217f218f211/American-Popular-Song-The-Great-Innovators-1900-1950-by-Alec-Wilder.pdf
    • http://kiteeearpdf.myhome.cx/9f213f215f219f216f211/Music-and-Culture-in-America-1861-1918-by-Saffle-Michael.pdf
    • http://kiteeearpdf.myhome.cx/9f213f215f218f217f218/Liszt-and-the-Birth-of-Modern-Europe-Music-As-a-Mirror-of-Religious-Political-Cultural-and-Aesthetic-Transformations-Franz-Liszt-Studies-Series-by-Michael-Saffle.pdf
    • http://kiteeearpdf.myhome.cx/1f219f216f218f218f211/Revolution-of-the-Heart-A-Genealogy-of-Love-in-China-1900-1950-by-Haiyan-Lee.pdf
    • http://kiteeearpdf.myhome.cx/9f213f215f219f216f212/Franz-Liszt-Gde-to-Rsh-by-Michael-Saffle.pdf
    • http://kiteeearpdf.myhome.cx/9f213f215f218f216f219/Franz-Liszt-A-Research-and-Information-Guide-by-Michael-Saffle.pdf
    • http://kiteeearpdf.myhome.cx/9f213f215f219f215f219/Franz-Liszt-A-Guide-to-Research-Second-Edition-by-SAFFLE-MICHAEL.pdf
    • http://kiteeearpdf.myhome.cx/9f213f215f218f218f212/Richard-Wagner-A-Research-and-Information-Guide-by-Michael-Saffle.pdf
    • http://kiteeearpdf.myhome.cx/1f218f213f215f214/The-Wonder-of-American-Toys-1920-1950-by-Charles-Dee-Sharp.pdf
    • http://kiteeearpdf.myhome.cx/8f214f214f214f212f216/All-American-Ads-1900-1919-by-Jim-Heimann.pdf
    • http://kiteeearpdf.myhome.cx/5f211f217f213f214f210/George-F-Kennan-And-The-Making-Of-American-Foreign-Policy-1947-1950-by-Wilson-D-Miscamble.pdf
    • http://kiteeearpdf.myhome.cx/1f217f218f217f214/Coming-Home-American-Paintings-1930-1950-from-the-Schoen-Collection-by-Erika-Lee-Doss.pdf
    • http://kiteeearpdf.myhome.cx/8f214f211f212f210f218/The-Triumph-of-Conservatism-A-Reinterpretation-of-American-History-1900-1916-by-Gabriel-Kolko.pdf
    • http://kiteeearpdf.myhome.cx/1f213f216f214f212f211/Peopling-the-North-American-City-Montreal-1840-1900-by-Sherry-Olson.pdf
    • http://kiteeearpdf.myhome.cx/6f218f213f214f214f216/Vienne-1900-Une-Identite-Blessee-by-Michael-Pollak.pdf
    • http://kiteeearpdf.myhome.cx/3f215f213f214f212f214/A-City-So-Grand-The-Rise-of-an-American-Metropolis-Boston-1850-1900-by-Stephen-Puleo.pdf
    • http://kiteeearpdf.myhome.cx/1f213f219f214f212f210/Rhetoric-and-Reality-Writing-Instruction-in-American-Colleges-1900---1985-by-James-A-Berlin.pdf
    • http://kiteeearpdf.myhome.cx/3f213f211f218f218f210/Bernard-Shaw-Volume-3-The-Lure-of-Fantasy-1918-1950-by-Michael-Holroyd.pdf
    • http://kiteeearpdf.myhome.cx/5f210f216f214f210f218/The-Atomic-Bomb-and-American-Society-New-Perspectives-by-Rosemary-B-Mariner.pdf
    • http://kiteeearpdf.myhome.cx/9f213f215f219f2