Malicious PDF — malware analysis report

Static analysis result for SHA-256 b32c16c5784cda18…

MALICIOUS

PDF

23.7 KB Created: 2020-03-14 00:24:13 +00:00 Authoring application: mPDF 5.7
MD5: 9e1cfd2177e7f26597639a5df9ae4ee0 SHA-1: e1d8e557c4cdc229fda6b903d354c6bfb4cfe619 SHA-256: b32c16c5784cda18fda2374351b816194e89055f3f6dfef676670ae77b988af7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged the document as malicious. The primary intent appears to be directing users to a domain hosting numerous documents, likely as a form of SEO spam or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9449

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/4867860862869867/The-Dog-Who-Couldn-t-Stop-Loving-How-Dogs-Have-Captured-Our-Hearts-for-Thousands-of-Years-by-Jeffrey-Moussaieff-Masson.pdf
    • http://calistazz.myhome.cx/4869864869869866/Dogs-Never-Lie-About-Love-Reflections-on-the-Emotional-World-of-Dogs-by-Jeffrey-Moussaieff-Masson.pdf
    • http://calistazz.myhome.cx/5860861863860869/Dogs-Have-the-Strangest-Friends-amp-Other-True-Stories-of-Animal-Feelings-by-Jeffrey-Moussaieff-Masson.pdf
    • http://calistazz.myhome.cx/3866864860863865/My-Father-s-Guru-A-Journey-Through-Spirituality-and-Disillusion-by-Jeffrey-Moussaieff-Masson.pdf
    • http://calistazz.myhome.cx/5866869867867/The-Pig-Who-Sang-to-the-Moon-The-Emotional-World-of-Farm-Animals-by-Jeffrey-Moussaieff-Masson.pdf
    • http://calistazz.myhome.cx/1864860865860866/The-Man-Who-Couldn-t-Stop-by-David-Adam.pdf
    • http://calistazz.myhome.cx/1865869860868862/The-Latke-Who-Couldn-t-Stop-Screaming-A-Christmas-Story-by-Lemony-Snicket.pdf
    • http://calistazz.myhome.cx/1861867864862869864/Kombucha-Tea-of-Immortality-A-Little-Secret-that-has-improved-health-for-thousands-of-years-by-Martin-Zahl.pdf
    • http://calistazz.myhome.cx/1868861869866863/Captured-Hearts-by-Sandra-Deighan.pdf
    • http://calistazz.myhome.cx/2868869866865861/I-Just-Can-t-Stop-Loving-You-by-Imari-Jade.pdf
    • http://calistazz.myhome.cx/1864868860860866/Captive-Cowboy-Captured-Hearts-2-by-Lindsey-Brookes.pdf
    • http://calistazz.myhome.cx/1865866860861860/Amen-Amen-Amen-Memoir-of-a-Girl-Who-Couldn-t-Stop-Praying-by-Abby-Sher.pdf
    • http://calistazz.myhome.cx/2866868867869869/Cold-Black-Hearts-by-Jeffrey-J-Mariotte.pdf
    • http://calistazz.myhome.cx/6865867869862/Let-s-Face-It-90-Years-of-Living-Loving-and-Learning-by-Kirk-Douglas.pdf
    • http://calistazz.myhome.cx/3861866861861863/The-Dogs-Buried-Over-the-Bridge-A-Memoir-in-Dog-Years-by-Rheta-G-Johnson.pdf
    • http://calistazz.myhome.cx/7867861867864869/Captured-by-our-Addiction-Captured-5-by-Karen-Frances.pdf
    • http://calistazz.myhome.cx/4867867862867869/Letter-to-Louise-A-Loving-Memoir-to-the-Daughter-I-Gave-Up-for-Adoption-More-Than-Twenty-Five-Years-Ago-by-Pauline-Collins.pdf
    • http://calistazz.myhome.cx/3869860865863866/Stop-Dieting-Now-25-Reasons-to-Stop-25-Ways-to-Heal-by-Golda-Poretsky.pdf
    • http://calistazz.myhome.cx/5866862866867/Teenage-Murderer-Alyssa-Bustamante-True-Crime-Bus-Stop-Reads-29-by-Bus-Stop-Guides.pdf
    • http://calistazz.myhome.cx/2862860861869866/Loving-Conor-A-Clairvoyant-s-Memoir-on-Loving-Bonding-and-Healing-by-Tami-Arlene-Urbanek.pdf
    • http://calistazz.myhome.cx/5860861863860869/Dogs-Have-the-Strangest-Friends-amp-Other-True-Stories-of-Animal-Feelings-by-Jeffre