Malicious PDF — malware analysis report

Static analysis result for SHA-256 427277b6974788aa…

MALICIOUS

PDF

18.0 KB Created: 2020-03-18 21:02:14 +00:00 Authoring application: mPDF 5.7
MD5: abca48c7fbf32dc6da8fe1d86f5d4b13 SHA-1: 8ad7db5ec973429b341d53e6b535bbbf6abc8368 SHA-256: 427277b6974788aaf118e4b6c0d328190ae0485724e35a5df4479b6b68aff310
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'calistazz.myhome.cx'. This is indicative of a link farm or SEO poisoning attack, designed to drive traffic to potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9807

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/3869866868869863/The-Amelia-Six-by-Kristin-L-Gray.pdf
    • http://calistazz.myhome.cx/2860869864862867/Museum-of-the-Weird-by-Amelia-Gray.pdf
    • http://calistazz.myhome.cx/3867863861867864/Amelia-s-Most-Unforgettable-Embarrassing-Moments-Amelia-s-Notebooks-16-by-Marissa-Moss.pdf
    • http://calistazz.myhome.cx/9866869862866/Amelia-the-Venutons-and-the-Golden-Cage-Amelia-s-Amazing-Space-Adventures-2-by-Evonne-Blanchard.pdf
    • http://calistazz.myhome.cx/3867863861865867/Luv-Amelia-Luv-Nadia-Amelia-s-Notebooks-6-by-Marissa-Moss.pdf
    • http://calistazz.myhome.cx/2864861868867866/Amelia-Writes-Again-Amelia-s-Notebooks-2-by-Marissa-Moss.pdf
    • http://calistazz.myhome.cx/7862869865868862/The-Ugly-Duckling-by-Rachel-Isadora.pdf
    • http://calistazz.myhome.cx/5865865866865861/Lili-on-Stage-by-Rachel-Isadora.pdf
    • http://calistazz.myhome.cx/5865865866860860/Lili-at-Ballet-by-Rachel-Isadora.pdf
    • http://calistazz.myhome.cx/4861868866867867/Isadora-The-Chronicles-of-Kaya-3-by-Charlotte-McConaghy.pdf
    • http://calistazz.myhome.cx/2863861865864869/Isadora-The-Chronicles-of-Kaya-3-by-Charlotte-McConaghy.pdf
    • http://calistazz.myhome.cx/4863861865863867/Persephone-Queen-of-the-Dead-by-Isadora-Marie.pdf
    • http://calistazz.myhome.cx/4867861861860869/The-Isadora-Interviews-The-Network-Series-1-5-by-Katie-Cross.pdf
    • http://calistazz.myhome.cx/5862865866867865/The-Picture-of-Dorian-Gray-English-French-Edition-illustrated-Le-Portrait-de-Dorian-Gray-by-Oscar-Wilde.pdf
    • http://calistazz.myhome.cx/6867869864867869/Gray-Part-II-Gray-2-by-Lou-Cadle.pdf
    • http://calistazz.myhome.cx/7868868865868/D-Gray-man-Vol-10-D-Gray-man-10-by-Katsura-Hoshino.pdf
    • http://calistazz.myhome.cx/2868868869869865/D-Gray-man-Vol-3-D-Gray-man-3-by-Katsura-Hoshino.pdf
    • http://calistazz.myhome.cx/7868864868866861/A-Friendship-Of-The-Nineties-Letters-Between-John-Gray-amp-Pierre-Lou-s-by-John-N-Gray.pdf
    • http://calistazz.myhome.cx/2869861869869864/The-Wolf-of-Dorian-Gray-A-Werewolf-Spawned-by-the-Evil-of-Man-The-Wolf-of-Dorian-Gray-Series-Book-1-by-Brian-S-Ference.pdf
    • http://calistazz.myhome.cx/2860866860860867/Gray-Back-Bad-Bear-Gray-Back-Bears-1-by-T-S-Joyce.pdf
    • http://calistazz.myhome.cx/2863861865864869/Isadora-The-Chronicles-of-Kaya-3-by-Charlotte-McConagh