Malicious PDF — malware analysis report

Static analysis result for SHA-256 6de138c5719f8e81…

MALICIOUS

PDF

14.8 KB Created: 2020-03-20 19:39:00 +00:00 Authoring application: mPDF 5.7
MD5: be7e696fdc473f200f79a0a12493d7cc SHA-1: 06095980ac95e644e07cd024bc77b20f7ee48fcf SHA-256: 6de138c5719f8e8135bba984abd30143e9861ff1c82cc6d3bda035714f366f16
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document was flagged by a machine learning classifier and contains a large number of embedded links, indicating a link farm or SEO poisoning attempt. The links point to external PDF files hosted on the domain 'calistazz.myhome.cx', suggesting a distribution mechanism for potentially malicious content. No scripts were extracted, but the structure and heuristics point towards a malicious PDF designed to lure users to external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/8861866867866866/Devil-Duke-of-Darby-Wolfson-Chronicles-2-by-Jillian-Eaton.pdf
    • http://calistazz.myhome.cx/6867868867863864/A-Night-Without-Stars-The-Lola-Chronicles-1-by-Jillian-Eaton.pdf
    • http://calistazz.myhome.cx/3864869864866865/A-Duke-by-December-A-Year-Without-A-Duke-5-by-Sabrina-Darby.pdf
    • http://calistazz.myhome.cx/6865868866869860/The-Forgotten-Fiancee-The-London-Ladies-2-by-Jillian-Eaton.pdf
    • http://calistazz.myhome.cx/2865860864867868/For-the-Love-of-Lynette-Swan-Sisters-1-by-Jillian-Eaton.pdf
    • http://calistazz.myhome.cx/2860864862866865/The-Duke-Devil-s-Duke-3-by-Katharine-Ashe.pdf
    • http://calistazz.myhome.cx/8860867866861/The-Devilish-Pleasures-of-a-Duke-Boscastle-6-by-Jillian-Hunter.pdf
    • http://calistazz.myhome.cx/1861866866867860861/Life-in-Christ---J-N-Darby-by-John-Nelson-Darby.pdf
    • http://calistazz.myhome.cx/3864869860863865/In-the-Devil-s-Bed-Sins-of-the-Duke-1-by-Eva-Devon.pdf
    • http://calistazz.myhome.cx/3861866869863869/The-Duke-Can-Go-to-the-Devil-Prelude-to-a-Kiss-3-by-Erin-Knightley.pdf
    • http://calistazz.myhome.cx/3864869864869861/Devil-of-a-Duke-The-Wickeds-Book-2-by-Kathleen-Ayers.pdf
    • http://calistazz.myhome.cx/4863864865869863/Date-Me-The-Keatyn-Chronicles-3-by-Jillian-Dodd.pdf
    • http://calistazz.myhome.cx/4863864869860/Adore-Me-The-Keatyn-Chronicles-4-5-by-Jillian-Dodd.pdf
    • http://calistazz.myhome.cx/3869865867865/Date-Me-The-Keatyn-Chronicles-3-by-Jillian-Dodd.pdf
    • http://calistazz.myhome.cx/3869868863864/Stalk-Me-The-Keatyn-Chronicles-1-by-Jillian-Dodd.pdf
    • http://calistazz.myhome.cx/6869863862861/Hate-Me-The-Keatyn-Chronicles-5-by-Jillian-Dodd.pdf
    • http://calistazz.myhome.cx/2867862864860860/Stalk-Me-The-Keatyn-Chronicles-1-by-Jillian-Dodd.pdf
    • http://calistazz.myhome.cx/4864860869865868/Kiss-Me-The-Keatyn-Chronicles-2-by-Jillian-Dodd.pdf
    • http://calistazz.myhome.cx/4863864865869865/Love-Me-The-Keatyn-Chronicles-4-by-Jillian-Dodd.pdf
    • http://calistazz.myhome.cx/3860867862864869/The-Rogue-Devil-s-Duke-1-Falcon-Club-4-by-Katharine-Ashe.pdf