Malicious PDF — malware analysis report

Static analysis result for SHA-256 13e1fa18e118284e…

MALICIOUS

PDF

14.7 KB Created: 2020-03-14 00:29:57 +00:00 Authoring application: mPDF 5.7
MD5: 228732a75c8edb6abf56687d35f135db SHA-1: cda4c46068e0567da71823341a63324e19290a1c SHA-256: 13e1fa18e118284e0d8e1133c7276143560fb6b6c78a8cb8eb4878c4fc534475
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF contains a large number of embedded links, identified as a link farm. The links point to various PDF files hosted on the domain 'calistazz.myhome.cx'. The presence of these links suggests an attempt to direct users to external resources, likely for malicious purposes such as distributing further malware or conducting phishing. No scripts were extracted, but the structure indicates a potential for T1059.007 (JavaScript) if interactive elements were present, or T1566.001 (Spearphishing Attachment) as the likely initial access vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/1861861868868861/Blood-Knot-Blood-Stone-1-by-Tracy-Cooper-Posey.pdf
    • http://calistazz.myhome.cx/1863862861863860/Dead-Again-by-Tracy-Cooper-Posey.pdf
    • http://calistazz.myhome.cx/1861869865862865869/Greyson-s-Doom-The-Endurance-1-by-Tracy-Cooper-Posey.pdf
    • http://calistazz.myhome.cx/5860869869867861/Faring-Soul-Interspace-Origins-1-by-Tracy-Cooper-Posey.pdf
    • http://calistazz.myhome.cx/6861867867868867/Carson-s-Night-Stonebrood-Saga-1-by-Tracy-Cooper-Posey.pdf
    • http://calistazz.myhome.cx/2860866864865862/Romani-Armada-Beloved-Bloody-Time-3-by-Tracy-Cooper-Posey.pdf
    • http://calistazz.myhome.cx/3865867868867864/Knot-of-the-Slain-Part-One-TWISTED-Blood-Angels-Book-1-by-T-C-Archer.pdf
    • http://calistazz.myhome.cx/3868860863869863/Blood-and-Stone-Alastair-Stone-Chronicles-6-by-R-L-King.pdf
    • http://calistazz.myhome.cx/3865862861865869/Blood-of-My-Blood-Blood-of-My-Blood-1-by-Joann-L-Polite.pdf
    • http://calistazz.myhome.cx/1868867869868868/Blood-Bonded-by-Force-The-Community-3-by-Tracy-Tappan.pdf
    • http://calistazz.myhome.cx/2867863862869862/The-Symbiotic-Law-Blood-and-Bone-Trilogy-3-by-Lia-Cooper.pdf
    • http://calistazz.myhome.cx/4868862861864/Bad-Blood-Alexandra-Cooper-9-by-Linda-Fairstein.pdf
    • http://calistazz.myhome.cx/3867868863860866/The-Duality-Paradigm-Blood-and-Bone-Trilogy-1-by-Lia-Cooper.pdf
    • http://calistazz.myhome.cx/3867860869861862/Blood-on-the-Tongue-Ben-Cooper-amp-Diane-Fry-3-by-Stephen-Booth.pdf
    • http://calistazz.myhome.cx/4866860863869866/Blood-Lines-D-I-Kim-Stone-5-by-Angela-Marsons.pdf
    • http://calistazz.myhome.cx/4865866861860869/Blood-Ties-MC-Outlaw-3-by-Ella-Stone.pdf
    • http://calistazz.myhome.cx/4865869864866868/How-to-Draw-Blood-from-a-Stone-by-Priscila-Uppal.pdf
    • http://calistazz.myhome.cx/1865860862865869/Blood-Bone-and-Stone-by-Tara-Barnacle.pdf
    • http://calistazz.myhome.cx/4861866862868866/Calasade-Blood-Isle-by-Mark-Stone.pdf
    • http://calistazz.myhome.cx/2861863868866863/Calasade-Blood-Isle-by-Mark-Stone.pdf