Malicious PDF — malware analysis report

Static analysis result for SHA-256 5ab839a67d603f3c…

MALICIOUS

PDF

17.0 KB Created: 2020-03-15 20:30:37 +00:00 Authoring application: mPDF 5.7
MD5: cbb58db24c846dad36b26490a6f3b3d1 SHA-1: a92acd58ed18d1b6555c937e03ad3b0ea5626c9a SHA-256: 5ab839a67d603f3c7a466200b2eb000d3045d2ef58f1d971057f9b7cf40de1d4
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, suggesting a link farm or redirection scheme. The ML classifier also flagged this document as malicious. The primary attack pattern involves directing users to a domain hosting numerous documents, likely for SEO manipulation or to distribute further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/2866865863860864/Voodoo-Love-and-the-Curse-of-Jean-Lafitte-s-Treasure-Episode-1-by-Victoria-Richards.pdf
    • http://calistazz.myhome.cx/1860864860861860869/A-Thankful-Love-Richards-Family-1-by-K-Victoria-Chase.pdf
    • http://calistazz.myhome.cx/8864860860860862/Curse-of-the-Voodoo-Gods-by-Joyce-Rochat.pdf
    • http://calistazz.myhome.cx/4866869869868864/For-A-Dragon-s-Treasure-Highland-Dragons-3-by-Charlie-Richards.pdf
    • http://calistazz.myhome.cx/3862867866863867/Treasure-for-Treasure-Beings-in-Love-7-by-R-Cooper.pdf
    • http://calistazz.myhome.cx/9869866869861868/Jim-Hawkins-and-The-Curse-of-Treasure-Island-by-Frank-Delaney.pdf
    • http://calistazz.myhome.cx/5861860864865866/Once-Were-Mountains-by-Victoria-Richards.pdf
    • http://calistazz.myhome.cx/3867867863865863/Breaking-the-Playboy-s-Curse-Kontra-s-Menagerie-10-by-Charlie-Richards.pdf
    • http://calistazz.myhome.cx/2869867865868861/The-Christie-Curse-by-Victoria-Abbott.pdf
    • http://calistazz.myhome.cx/4866868864869862/Young-Merlin-A-Dragon-s-tale-Book-1-by-Victoria-Richards.pdf
    • http://calistazz.myhome.cx/6868860867862/The-Christie-Curse-Book-Collector-Mystery-1-by-Victoria-Abbott.pdf
    • http://calistazz.myhome.cx/2865863861867862/The-Surrender-Your-Love-Trilogy-Surrender-Your-Love-Conquer-Your-Love-Treasure-Your-Love-by-J-C-Reed.pdf
    • http://calistazz.myhome.cx/1861865864861862864/A-Dope-Boy-in-Love-2-In-Love-with-a-Dopeboy-Spinoff-by-Treasure-Bee.pdf
    • http://calistazz.myhome.cx/7864862863864869/Summer-in-a-Small-Town-Welcome-to-Icicle-Falls-Treasure-Beach-Life-in-Icicle-Falls-0-5-by-Emilie-Richards.pdf
    • http://calistazz.myhome.cx/2862867865862864/Victoria-by-Ruby-Jean-Jensen.pdf
    • http://calistazz.myhome.cx/1865863868861866/Victoria-in-the-Wings-Georgian-Saga-11-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/4869863868862865/Not-Looking-For-Love-Episode-1-by-Lena-Bourne.pdf
    • http://calistazz.myhome.cx/1867860866867866/Love-Games-Episode-1-There-Are-No-Rules-1-by-Lara-Dash.pdf
    • http://calistazz.myhome.cx/5864863861864861/Fight-For-Love-T01-Real---Episode-2-by-Katy-Evans.pdf
    • http://calistazz.myhome.cx/4866869869869860/Trill-To-Me-Sweetly-A-Paranormal-s-Love-1-by-Charlie-Richards.pdf