Malicious PDF — malware analysis report

Static analysis result for SHA-256 0c38dd9136aa6def…

MALICIOUS

PDF

21.6 KB Created: 2020-03-18 16:50:10 +00:00 Authoring application: mPDF 5.7
MD5: 8365c2464678715b4b5edf9de21b8271 SHA-1: d30bae1ed1131330b708d088e922788a59a1e200 SHA-256: 0c38dd9136aa6def738960d0019caf2facdab7ff6b4774d14f9e7b363427d538
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to a single domain, identified by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS classifier also flagged the document with high confidence. The embedded URLs are likely intended to direct users to malicious content or to manipulate search engine results, a common tactic for SEO poisoning.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/1860869865862860864/Higher-Superstition-The-Academic-Left-and-Its-Quarrels-with-Science-by-Paul-R-Gross.pdf
    • http://calistazz.myhome.cx/4866865864868869/Trends-in-Global-Higher-Education-Tracking-an-Academic-Revolution-by-Philip-G-Altbach.pdf
    • http://calistazz.myhome.cx/6864865861862863/A-Magical-World-Superstition-and-Science-from-the-Renaissance-to-the-Enlightenment-by-Derek-K-Wilson.pdf
    • http://calistazz.myhome.cx/4864868863865869/The-Roles-of-Rhetoric-in-the-Public-Understanding-of-Science-by-Alan-G-Gross.pdf
    • http://calistazz.myhome.cx/4864868863865861/Rhetorical-Hermeneutics-Invention-and-Interpretation-in-the-Age-of-Science-by-Alan-G-Gross.pdf
    • http://calistazz.myhome.cx/2867864868864860/How-to-Write-a-Lot-A-Practical-Guide-to-Productive-Academic-Writing-by-Paul-J-Silvia.pdf
    • http://calistazz.myhome.cx/5867861867867860/How-to-Write-a-Lot-A-Practical-Guide-to-Productive-Academic-Writing-by-Paul-J-Silvia.pdf
    • http://calistazz.myhome.cx/1860867867866/The-Left-Hand-of-God-The-Left-Hand-of-God-1-by-Paul-Hoffman.pdf
    • http://calistazz.myhome.cx/1860862868865863867/The-Trifecta-Secret-of-Wealth-amp-Abundance-Align-Your-Higher-Self-amp-You-Shall-Arrive-by-John-Paul-Khoury.pdf
    • http://calistazz.myhome.cx/4864862864862863/The-Left-Hand-of-God-by-Paul-Hoffman.pdf
    • http://calistazz.myhome.cx/2862860863868866/The-Beating-of-His-Wings-The-Left-Hand-of-God-3-by-Paul-Hoffman.pdf
    • http://calistazz.myhome.cx/5863864866866862/Reviews-On-Corrosion-Inhibitors-Science-And-Technology-Papers-Presented-At-The-Corrosion-89-Symposium-quot-Review-Of-Corrosion-Inhibition-Science-quot-Sponsored-Group-T-3-A-15-N-Inhibitors-State-Of-The-A-by-Paul-Labine.pdf
    • http://calistazz.myhome.cx/4863862867867/Left-Behind-Series-Gift-Set-Left-Behind-1-6-by-Jerry-B-Jenkins.pdf
    • http://calistazz.myhome.cx/2866862866869866/Pandora-s-Lab-Seven-Stories-of-Science-Gone-Wrong-by-Paul-A-Offit.pdf
    • http://calistazz.myhome.cx/8865861869861/Superstition-by-Karen-Robards.pdf
    • http://calistazz.myhome.cx/4868867866866/Superstition-by-David-Ambrose.pdf
    • http://calistazz.myhome.cx/5865867861860/What-s-Left-of-Me-What-s-Left-of-Me-1-by-Amanda-Maxlyn.pdf
    • http://calistazz.myhome.cx/5863863869860868/Satanism-and-Witchcraft-The-Classic-Study-of-Medieval-Superstition-by-Jules-Michelet.pdf
    • http://calistazz.myhome.cx/3868860862861866/Legend-of-the-Superstition-Gold-Black-Pony-Adventures-3-by-Connie-Peck.pdf
    • http://calistazz.myhome.cx/2866862869864/Narrow-Houses-Tales-of-Superstition-Suspense-and-Fear-by-Peter-Crowther.pdf