Malicious PDF — malware analysis report

Static analysis result for SHA-256 b8fe226591d5dc1d…

MALICIOUS

PDF

17.8 KB Created: 2020-03-18 21:47:04 +00:00 Authoring application: mPDF 5.7
MD5: 21dd2f2f8586b18bc8c51e47f833f917 SHA-1: 1f356b7e7881b9a8bd1139f41e36fd876fc2597e SHA-256: b8fe226591d5dc1d635deb53df0debfa7e6d351b0c26fb0448cdc53fe030eece
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified as a link farm. The ML classifier strongly indicates maliciousness. The primary attack pattern appears to be SEO poisoning or distributing malicious content via these numerous links hosted on calistazz.myhome.cx.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/3866865863867863/Thee-I-Love-by-Annette-Blair.pdf
    • http://calistazz.myhome.cx/3861866866860863/Sea-Scoundrel-Knave-of-Hearts-1-by-Annette-Blair.pdf
    • http://calistazz.myhome.cx/3862861863862864/Red-Winter-Red-Winter-Trilogy-1-by-Annette-Marie.pdf
    • http://calistazz.myhome.cx/4867868865862863/Untamable-Rogue-Rogues-Club-4-by-Annette-Blair.pdf
    • http://calistazz.myhome.cx/4861867865868860/Captive-Scoundrel-Knave-of-Hearts-2-by-Annette-Blair.pdf
    • http://calistazz.myhome.cx/1867868862866868/A-Veiled-Deception-A-Vintage-Magic-Mystery-1-by-Annette-Blair.pdf
    • http://calistazz.myhome.cx/1867868862868869/Cloaked-in-Malice-A-Vintage-Magic-Mystery-5-by-Annette-Blair.pdf
    • http://calistazz.myhome.cx/1866869862865865/Sex-and-the-Psychic-Witch-Triplet-Witch-Trilogy-1-by-Annette-Blair.pdf
    • http://calistazz.myhome.cx/1860860868867861862/Victorian-Poetry-and-the-Culture-of-the-Heart-by-Kirstie-Blair.pdf
    • http://calistazz.myhome.cx/3865863864863868/Winter-s-Heart-by-A-C-Warneke.pdf
    • http://calistazz.myhome.cx/7868865862861863/Blair-s-Chronological-and-Historical-Tables-from-the-Creation-to-the-Present-Time-With-Additions-and-Corrections-from-the-Most-Authentic-Writers-Including-the-Computation-of-St-Paul-as-Connecting-the-Period-from-the-Exode-to-the-Temple-by-John-Blair.pdf
    • http://calistazz.myhome.cx/1868867862866867/Winter-s-Heart-by-Michael-Kanuckel.pdf
    • http://calistazz.myhome.cx/2860862869861867/The-Winter-Heart-by-Lillian-Cheatham.pdf
    • http://calistazz.myhome.cx/4868861861860864/Winter-Heart-Seasons-of-Love-4-by-B-G-Thomas.pdf
    • http://calistazz.myhome.cx/3867862867865868/Winter-s-Heart-Seasons-of-Change-Book-2-by-Jaye-Patrick.pdf
    • http://calistazz.myhome.cx/2862860862867866/Winter-s-Scars-The-Forsaken-Winter-s-Saga-5-by-Karen-Luellen.pdf
    • http://calistazz.myhome.cx/1865865867860869/Winter-s-Wrath-Sacrifice-Winter-s-Saga-3-by-Karen-Luellen.pdf
    • http://calistazz.myhome.cx/1865865867862867/Winter-s-Storm-Retribution-Winter-s-Saga-2-by-Karen-Luellen.pdf
    • http://calistazz.myhome.cx/2864866861860869/The-War-Against-Miss-Winter-Rosie-Winter-1-by-Kathryn-Miller-Haines.pdf
    • http://calistazz.myhome.cx/3866865864869860/Call-of-Winter-Winter-Princess-Serial-1-by-Skye-MacKinnon.pdf