Malicious PDF — malware analysis report

Static analysis result for SHA-256 3b881584d4d653ca…

MALICIOUS

PDF

15.0 KB Created: 2020-03-20 19:38:54 +00:00 Authoring application: mPDF 5.7
MD5: d28bedd07fec79aa0ff94d4e92082a42 SHA-1: fb86e798dce643c4150e1430ba270693a4fe01a0 SHA-256: 3b881584d4d653ca63b7318ecb9461d91e230ba433d6c62d72efbe3531c7bae2
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, all pointing to the same domain 'calistazz.myhome.cx'. This indicates a link farm designed to redirect users to potentially malicious content. The ML classifier and ClamAV detection further support its malicious nature, classifying it as a Pdf.Dropper.Agent. The presence of numerous book-themed URLs suggests a lure to entice users to click, likely leading to credential theft or further malware downloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7745800-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7745800-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/7867863867864861/The-Cambridge-Companion-to-Spinoza-by-Don-Garrett.pdf
    • http://calistazz.myhome.cx/9867867863869861/The-Cambridge-Companion-to-Don-Delillo-by-John-Duvall.pdf
    • http://calistazz.myhome.cx/1860866860867864865/The-Cambridge-Companion-To-Leonardo-by-Claire-Farago.pdf
    • http://calistazz.myhome.cx/6861865866862862/The-Cambridge-Companion-to-the-Fin-de-Si-cle-by-Gail-Marshall.pdf
    • http://calistazz.myhome.cx/1861860869863862862/The-Cambridge-Companion-to-Augustine-by-Eleonore-Stump.pdf
    • http://calistazz.myhome.cx/6864864868869869/The-Cambridge-Companion-to-Nabokov-by-Julian-W-Connolly.pdf
    • http://calistazz.myhome.cx/1861860860866861864/The-Cambridge-Companion-to-Seneca-by-Shadi-Bartsch.pdf
    • http://calistazz.myhome.cx/6860865861862861/The-Cambridge-Companion-to-Rabelais-by-John-O-39-Brien.pdf
    • http://calistazz.myhome.cx/5868860863863860/The-Cambridge-Companion-to-Flaubert-by-Timothy-A-Unwin.pdf
    • http://calistazz.myhome.cx/6861862865865865/The-Cambridge-Companion-to-Ovid-by-Philip-Hardie.pdf
    • http://calistazz.myhome.cx/6865866867869864/The-Cambridge-Companion-to-Tocqueville-by-Cheryl-B-Welch.pdf
    • http://calistazz.myhome.cx/6868860866860865/The-Cambridge-Companion-to-Baudelaire-by-Rosemary-Lloyd.pdf
    • http://calistazz.myhome.cx/9864863864860861/The-Cambridge-Companion-to-Rilke-by-Karen-Leeder.pdf
    • http://calistazz.myhome.cx/8863863860862869/The-Cambridge-Companion-to-Horace-by-Stephen-H-Harrison.pdf
    • http://calistazz.myhome.cx/1861860868868864860/The-Cambridge-Companion-to-Schopenhauer-by-Christopher-Janaway.pdf
    • http://calistazz.myhome.cx/7863867861861863/The-Cambridge-Companion-to-the-Beats-by-Steven-Belletto.pdf
    • http://calistazz.myhome.cx/9861860869863864/The-Cambridge-Companion-to-Feminism-in-Philosophy-by-Miranda-Fricker.pdf
    • http://calistazz.myhome.cx/1861864861861866862/The-Cambridge-Companion-to-Karl-Barth-by-John-B-Webster.pdf
    • http://calistazz.myhome.cx/7864868865861863/The-Cambridge-Companion-to-Edith-Wharton-by-Millicent-Bell.pdf
    • http://calistazz.myhome.cx/2864867867868/The-Cambridge-Companion-to-Fantasy-Literature-by-Edward-James.pdf