Malicious PDF — malware analysis report

Static analysis result for SHA-256 8a9f0fcdbd2a7344…

MALICIOUS

PDF

19.6 KB Created: 2020-03-16 23:43:25 +00:00 Authoring application: mPDF 5.7
MD5: 8c1c5a6e870e4b4e47924ce055bd4812 SHA-1: 235683a10f333e8dbaca0fbef6c62a32d74df650 SHA-256: 8a9f0fcdbd2a7344b3dc5b33d2156c5fba5bcd6da701b7b3b30598f05e0b3c4e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links all point to the same domain, calistazz.myhome.cx, and appear to be disguised as book titles. This suggests a link farm or redirection scheme, likely intended to manipulate search engine results or lead users to malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/3861862861863867/Victims-of-a-Map-A-Bilingual-Anthology-of-Arabic-Poetry-by-Mahmoud-Darwish.pdf
    • http://calistazz.myhome.cx/5866864867862868/Absent-Presence-by-Mahmoud-Darwish.pdf
    • http://calistazz.myhome.cx/4865869867863860/Why-Did-You-Leave-the-Horse-Alone-by-Mahmoud-Darwish.pdf
    • http://calistazz.myhome.cx/1860864868867863/The-Butterfly-s-Burden-by-Mahmoud-Darwish.pdf
    • http://calistazz.myhome.cx/9869863865869864/Birthmark-A-Bilingual-Anthology-of-Armenian-American-Poetry-by-Gourgen-Arzoumanian.pdf
    • http://calistazz.myhome.cx/1868867865866862/Unfortunately-It-Was-Paradise-Selected-Poems-by-Mahmoud-Darwish.pdf
    • http://calistazz.myhome.cx/1868863862867/No-Sign-of-Ceasefire-An-Anthology-of-Contemporary-Israeli-Poetry-An-Anthology-of-Contemporary-Israeli-Poetry-by-Warren-Bargad.pdf
    • http://calistazz.myhome.cx/9862865864868862/My-poetry-depicts-you-An-anthology-of-contemporary-Kurdish-poetry-by-Dr-Rebwar-Fatah.pdf
    • http://calistazz.myhome.cx/9862865863863863/My-poetry-depicts-you-An-anthology-of-contemporary-Kurdish-poetry-by-Rebwar-Fatah.pdf
    • http://calistazz.myhome.cx/4860868864867868/Triumph-Over-Tragedy-an-Anthology-for-the-Victims-of-Hurricane-Sandy-by-R-T-Kaelin.pdf
    • http://calistazz.myhome.cx/7864864865867867/Yvan-Goll-And-Bilingual-Poetry-by-James-Philips.pdf
    • http://calistazz.myhome.cx/4869865865865860/A-Boom-in-the-Room-an-Anthology-of-Student-Poetry-Student-Poetry-Anthologies-Book-1-by-Annie-Douglass-Lima.pdf
    • http://calistazz.myhome.cx/7868864864863862/The-Arab-Renaissance-A-Bilingual-Anthology-of-the-Nahda-by-Tarek-El-Ariss.pdf
    • http://calistazz.myhome.cx/7868864864863861/The-Arab-Renaissance-A-Bilingual-Anthology-of-the-Nahda-by-Tarek-El-Ariss.pdf
    • http://calistazz.myhome.cx/4861863862867868/The-Norton-Anthology-of-Modern-amp-Contemporary-Poetry-Vol-2-Contemporary-Poetry-by-Jahan-Ramazani.pdf
    • http://calistazz.myhome.cx/8862864861866868/28-Arabic-Short-Stories-In-Arabic-Language-by-Hasan-Yahya.pdf
    • http://calistazz.myhome.cx/1861865867869864867/The-Poetry-Of-Surrealism-An-Anthology-by-Michael-Benedikt.pdf
    • http://calistazz.myhome.cx/3863863866861868/Encounter-An-Anthology-Of-Modern-Poetry-by-H-M-Rosenberg.pdf
    • http://calistazz.myhome.cx/3869864867860861/Four-Paws-A-Poetry-Anthology-by-The-Quillective-Project-by-Ben-Ditmars.pdf
    • http://calistazz.myhome.cx/8860860862865864/Confucius-to-Cummings-An-Anthology-of-Poetry-by-Ezra-Pound.pdf
    • http://calistazz.myhome.cx/1868863862867/No-Sign-of-Ceasefire-An-Anthology-of-Contemporary-Israeli-Poetr