Malicious PDF — malware analysis report

Static analysis result for SHA-256 c1135ff8df1875f5…

MALICIOUS

PDF

16.1 KB Created: 2020-03-16 23:45:21 +00:00 Authoring application: mPDF 5.7
MD5: 131c5889b5868b8acdde742976aa6617 SHA-1: a0ee583c9e1d5cb39ba84ec7f596cb0e0c5fa17d SHA-256: c1135ff8df1875f54e3a747f22a4543ff6595819813f6f843836ced4964f6072
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary attack pattern involves directing users to a link farm hosted on calistazz.myhome.cx, likely to serve further malicious payloads or to engage in phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/2865862864866861/Bone-amp-Cane-by-David-Belbin.pdf
    • http://calistazz.myhome.cx/7864862868865866/The-Losers-High-Hunt-by-David-Eddings.pdf
    • http://calistazz.myhome.cx/7864862868864865/S-O-R-Losers-by-Avi.pdf
    • http://calistazz.myhome.cx/4868863862867865/Losers-by-Jeff-Erno.pdf
    • http://calistazz.myhome.cx/4865869868865866/Beautiful-Losers-by-Remittance-Girl.pdf
    • http://calistazz.myhome.cx/2865862868869867/The-Losers-Vol-1-Ante-Up-by-Andy-Diggle.pdf
    • http://calistazz.myhome.cx/2860866862861862/Beautiful-Losers-by-Remittance-Girl.pdf
    • http://calistazz.myhome.cx/1867865862868869/Liars-and-Losers-Like-Us-by-Ami-Allen-Vath.pdf
    • http://calistazz.myhome.cx/4860863863865/Beautiful-Losers-by-Leonard-Cohen.pdf
    • http://calistazz.myhome.cx/7864862868864863/The-Losers-Vol-3-Trifecta-by-Andy-Diggle.pdf
    • http://calistazz.myhome.cx/5861861861865860/The-Losers-Club-by-Lise-S-Baker.pdf
    • http://calistazz.myhome.cx/7864862868866866/The-Big-Book-of-Losers-by-Paul-Kirchner.pdf
    • http://calistazz.myhome.cx/7864862868865865/The-Losers-Vol-4-Close-Quarters-by-Andy-Diggle.pdf
    • http://calistazz.myhome.cx/7864862869863867/Lovers-Losers-and-You-Sunshine-and-Happiness-2-by-Skylar-M-Cates.pdf
    • http://calistazz.myhome.cx/5861864862868861/Born-Losers-A-History-of-Failure-in-America-by-Scott-A-Sandage.pdf
    • http://calistazz.myhome.cx/7864862867867862/Beautiful-Losers-Contemporary-Art-and-Street-Culture-by-Aaron-Rose.pdf
    • http://calistazz.myhome.cx/7864862869864864/Losers-Like-Us-Redefining-Discipleship-after-Epic-Failure-by-Daniel-Hochhalter.pdf
    • http://calistazz.myhome.cx/3860868867867/Winners-amp-Losers-Battles-Retreats-Gains-Losses-and-Ruins-from-the-Vietnam-War-by-Gloria-Emerson.pdf
    • http://calistazz.myhome.cx/4866863867866869/Thieves-Rascals-and-Sore-Losers-The-Unsettling-History-of-the-Dirty-Deals-that-Helped-Settle-Nebraska-by-Marilyn-Coffey.pdf
    • http://calistazz.myhome.cx/8868866864867/Strange-Fascination-David-Bowie-The-Definitive-Story-by-David-Buckley.pdf