Malicious PDF — malware analysis report

Static analysis result for SHA-256 6b218c3c9263c514…

MALICIOUS

PDF

29.7 KB Created: 2020-03-18 16:43:41 +00:00 Authoring application: mPDF 5.7
MD5: c48695d344be95260b1bdbb40b8a5b9e SHA-1: 5c35f1feaf755ec353b478ff96caf02fd3ec5666 SHA-256: 6b218c3c9263c514785b083534d5e9f9f5323c9f515532a9e8dac5fc97e6995d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on the suspicious domain 'calistazz.myhome.cx'. This heuristic firing suggests a link farm intended to distribute or redirect users to other malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9684

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/1860866867860868863/Der-Konflikt-Von-Aberglaube-Technischem-Fortschritt-Und-Tradition-Zwischen-Hauke-Haien-Und-Seinen-Mitmenschen-in-Theodor-Storms-Der-Schimmelreiter-by-Dario-Corradini.pdf
    • http://calistazz.myhome.cx/8867869867866862/Lateinunterricht-Zwischen-Tradition-Und-Fortschritt-by-Friedrich-Maier.pdf
    • http://calistazz.myhome.cx/1861861867861868866/Zwischen-Unbedingter-Tradition-Und-Bedingungslosem-Fortschritt-Zur-Auseinandersetzung-Um-Die-Moderne-Kunst-in-Der-Bundesrepublik-Deutschland-Der-50er-Jahre-by-Falko-Herlemann.pdf
    • http://calistazz.myhome.cx/9862865864867865/Der-Innerpalaestinensische-Konflikt-Eine-Analyse-Der-Gewaltdynamiken-Im-Konflikt-Zwischen-Fatah-Und-Hamas-1980-2007-by-Manuel-Winkelkotte.pdf
    • http://calistazz.myhome.cx/1860863866865869861/Theodor-Storm-Novellen-M-rchen-Gedichte-amp-Briefe-ber-400-Titel-in-einem-Band-Der-Schimmelreiter-Der-kleine-H-welmann-Immensee-Pole-Poppensp-ler-Marthe-und-ihre-Uhr-by-Theodor-Storm.pdf
    • http://calistazz.myhome.cx/1860866867860863860/German-Literature-on-the-Go-Volume-2-Der-Schimmelreiter-by-Theodor-Storm.pdf
    • http://calistazz.myhome.cx/9866867860868869/Theodor-Fahrner-Jewelry-Between-Avante-Garde-and-Tradition-Between-Avant-Garde-and-Tradition-Art-Nouveau-Art-Deco-The-1950s-by-Hase-Schmundt.pdf
    • http://calistazz.myhome.cx/9866867860865860/Theodor-Fahrner-Jewellery-Between-Avant-Garde-and-Tradition-by-B-Leonhard.pdf
    • http://calistazz.myhome.cx/1860863866865868864/Die-Bedeutung-Des-Elements-Wasser-in-Theodor-Storms-Novellen-Die-Wassermetaphorik-in-Seinem-Werk--Immensee--by-Sebastian-Madge.pdf
    • http://calistazz.myhome.cx/8865861861862868/Europaische-Sozietatsbewegung-Und-Demokratische-Tradition-Die-Europaischen-Akademien-Der-Fruhen-Neuzeit-Zwischen-Fruhrenaissance-Und-Spataufklarung-by-Klaus-Garber.pdf
    • http://calistazz.myhome.cx/1861860860868868863/Theodor-K-rners-S-mtliche-Werke-in-zwei-B-nden-Erster-Band-by-Theodor-K-rner.pdf
    • http://calistazz.myhome.cx/1861867863865866862/The-Death-Of-Ivan-Ilych-quot-He-in-his-madness-prays-for-storms-and-dreams-that-storms-will-bring-him-peace-quot-by-Leo-Tolstoy.pdf
    • http://calistazz.myhome.cx/5864860860860868/Tropical-Warning-An-Original-Serge-Storms-Story-and-Other-Debris-Serge-Storms-series-by-Tim-Dorsey.pdf
    • http://calistazz.myhome.cx/1861862865866868/Family-Storms-Storms-1-by-V-C-Andrews.pdf
    • http://calistazz.myhome.cx/9868869863862860/Der-Aberglaube-in-Der-Krankenstube-Nach-Seinem-Ursprunge-Betrachtet-by-Felix-Von-Oefele.pdf
    • http://calistazz.myhome.cx/1860866867860861869/Storm-Der-Schimmelreiter-by-Alfred-D-White.pdf
    • http://calistazz.myhome.cx/1861861861866869865/Fuzzy-Modelle-in-Der-Unternehmensplanung-by-Wolfgang-Hauke.pdf
    • http://calistazz.myhome.cx/9868868862864860/SPIEGEL-E-Book-M-nchhausen-by-Hauke-Janssen.pdf
    • http://calistazz.myhome.cx/1860863866865867868/Aquis-Submersis-und-Immensee---Zwei-Novellen-von-Theodor-Storm-by-Theodor-Storm.pdf
    • http://calistazz.myhome.cx/1860869860869861864/Konflikt-und-Konsens-Transformationsprozesse-in-Ostdeutschland-by-Martin-Brussig.pdf