Malicious PDF — malware analysis report

Static analysis result for SHA-256 9c366f45e3874b50…

MALICIOUS

PDF

28.8 KB Created: 2020-03-18 21:37:22 +00:00 Authoring application: mPDF 5.7
MD5: 288497e5bfe8495aba0b81391da83299 SHA-1: 3befda7a11d89ae5c7a771e7305f268464ed2e67 SHA-256: 9c366f45e3874b50ccd4b0a278aee20c82beba22ad23f293a49e10028d00c9fb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, hosted on the domain 'calistazz.myhome.cx'. This pattern is indicative of a link farm or a method to distribute malicious content indirectly. The ML classifier also flagged this PDF as malicious with a high probability. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/2863869864865860/The-Writing-Revolution-Cuneiform-to-the-Internet-by-Amalia-E-Gnanadesikan.pdf
    • http://calistazz.myhome.cx/5863864868868/Walking-on-Water-Reading-Writing-and-Revolution-by-Derrick-Jensen.pdf
    • http://calistazz.myhome.cx/9866867864869866/The-Internet-Galaxy-Reflections-on-the-Internet-Business-and-Society-by-Manuel-Castells.pdf
    • http://calistazz.myhome.cx/1860862867863868869/Internet-Password-Organizer-An-Alphabetical-Journal-to-Organize-Internet-Log-In-Details-by-Anneline-Sophia.pdf
    • http://calistazz.myhome.cx/7869865868863861/Writing-Mastery-How-to-Master-the-Art-of-Writing-amp-Write-3-000-Words-Per-Day---Overcoming-Writer-s-Block-Make-Money-Online-Copywriting-Erotica-Writing-Writing-Mastery-How-to-Write-a-Book-by-Lance-Devoir.pdf
    • http://calistazz.myhome.cx/7865860868865868/Valuation-of-Internet-Start-ups-An-Applied-Research-on-How-Venture-Capitalists-Value-Internet-Start-ups-Nowadays-by-Jean-Baptiste-Flanc.pdf
    • http://calistazz.myhome.cx/4861864866869864/DIY-SEO-amp-Internet-Marketing-Guide-How-To-Do-It-Yourself-Search-Engine-Optimization-and-Internet-Marketing-EZ-Website-Promotion-Book-1-by-Darren-Varndell.pdf
    • http://calistazz.myhome.cx/6861866860866862/J-ai-cherch-de-l-or-sur-Internet---Ce-Que-Vous-Pouvez-Faire-Pour-Gagner-De-L-Argent-Sur-Internet-Et-Qui-Vous-Donnent-Les-Meilleures-Chances-De-R-ussir-by-Nary-Andrian.pdf
    • http://calistazz.myhome.cx/9862864865860861/Creative-Writing---From-Think-To-Ink-Learn-How-To-Unleash-Your-Creative-Self-and-Discover-Why-You-Don-t-Need-1000-Writing-Prompts-To-Blast-Away-Your-Writer-s-Block-and-Improve-Your-Writing-Skills-by-Simeon-Lindstrom.pdf
    • http://calistazz.myhome.cx/6862863868861862/INTERNET-ADDICTION-DEAL-WITH-YOUR-INTERNET-ADDICTION-REASONS-AND-SYMPTOMS-by-S-FATOU.pdf
    • http://calistazz.myhome.cx/3864863860863865/Welcome-to-the-Writer-s-Life-How-to-Design-Your-Writing-Craft-Writing-Business-Writing-Practice-and-Reading-Practice-by-Paulette-Perhach.pdf
    • http://calistazz.myhome.cx/1860862862867868863/Old-Assyrian-Bibliography-of-Cuneiform-Texts-Bullae-Seals-and-the-Results-of-the-Excavations-at-Assur-Kultepe-Kanis-Acemhoyuk-Alisar-and-Bogazkoy-by-C-Michel.pdf
    • http://calistazz.myhome.cx/6864865860864862/Amalia-Pica-by-Various.pdf
    • http://calistazz.myhome.cx/3861869868867865/Tamer-of-Horses-by-Amalia-Carosella.pdf
    • http://calistazz.myhome.cx/6864864869864868/Postcards-from-Asgard-by-Amalia-Dillin.pdf
    • http://calistazz.myhome.cx/1861865863865861861/Writing-for-Children-Writing-Handbooks-Writing-Handbooks-by-Linda-Strachan.pdf
    • http://calistazz.myhome.cx/3867861863863862/Amalia-Diary-2-California-Diaries-9-by-Ann-M-Martin.pdf
    • http://calistazz.myhome.cx/9867860861867863/Unsterblich-Bonnie-Amalia-Celina-by-Daniela-Igelhorst.pdf
    • http://calistazz.myhome.cx/5864866864864867/Raising-Amalia-Veredian-Chronicles-3-by-Regine-Abel.pdf
    • http://calistazz.myhome.cx/8860866861868/Mem-rias-do-Padre-Germano-by-Amalia-Domingo-Soler.pdf
    • http://calistazz.myhome.cx/7865860868865868/Valuation-of-Internet-Start-ups-An-Applied-Research-on-How-Venture-Capitalists-Value-Internet-Start-ups-Nowadays-by-Jean-Ba