Malicious PDF — malware analysis report

Static analysis result for SHA-256 6fca2334c9e185d6…

MALICIOUS

PDF

19.2 KB Created: 2020-03-16 23:43:27 +00:00 Authoring application: mPDF 5.7
MD5: 01fd1001cdda0c691c001622a3cddfe2 SHA-1: 8a2c75cad4bb55937f9d9d30c91e5e9eadb4e2db SHA-256: 6fca2334c9e185d68e369be0f311ad3669fcb0c5136730afb2a6ccfc025360e5
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, many of which are structured as numeric slugs and book titles, indicating a link farm designed to redirect users to external content. The ML classifier also flagged this PDF as malicious. The primary attack pattern observed is the use of a link farm to potentially distribute further malicious content or lead users to phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/7866862863865864/The-Trial-by-Franz-Kafka-Classic-Annotated-and-Translated-Edition-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/7865861862863863/The-Essential-Kafka-The-Castle-The-Trial-Metamorphosis-and-Other-Stories-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/7863862861863867/The-Metamorphosis-by-Franz-Kafka-Annotated-and-Translated-Edition-Die-Verwandlung-Franz-Kafka-Collection-Book-1-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/2862865863862861/The-Metamorphosis-and-The-Trial-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/5867864862865869/The-Trial---The-Original-Classic-Edition-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/9865861868869868/Franz-Kafka-Briefe-an-die-Eltern-Aus-den-Jahren-1922---1924-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/4867865868868861/The-Diaries-of-Franz-Kafka-1910-1913-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/9865860860862/The-Trial-America-The-Castle-Metamorphosis-In-The-Penal-Settlement-The-Great-Wall-Of-China-Investigations-Of-A-Dog-Letter-To-His-Father-The-Diaries-1910-23-Complete-amp-Unabridged-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/5862868869867867/Franz-Kafka---Collected-Works-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/8869868862864868/Franz-Kafka---Gesammelte-Werke-Von-quot-Die-Verwandlung-quot-ber-quot-Der-Prozess-quot-bis-hin-zu-quot-Das-Schloss-quot-Illustrierte-Ausgabe-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/5866861868866864/Metamorphosis-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/1860861860866865861/The-Castle-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/1861862861866860860/The-Castle-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/3864866869868/Amerika-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/5868860863869864/La-metamorfosis-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/1863869864866867/The-Castle-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/7866862862867861/The-Metamorphosis-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/7864863867868867/The-Metamorphosis-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/8863869867863862/Metamorphosis-by-Franz-Kafka.pdf
    • http://calistazz.myhome.cx/8867860861863863/Brief-an-den-Vater-by-Franz-Kafka.pdf