Malicious PDF — malware analysis report

Static analysis result for SHA-256 ea272f0fa6a9aeba…

MALICIOUS

PDF

17.7 KB Created: 2020-02-06 00:24:54 +00:00 Authoring application: mPDF 5.7
MD5: 9884a75031ffeb20576897f9711009a1 SHA-1: 2c2f5b755cdd4a79949942fe258c91ad585ec2a2 SHA-256: ea272f0fa6a9aeba67964310a27f9f7e96e6826cdd5e42ebb46aae85ea6df9e0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier and contains a large number of embedded external links, indicating it functions as a link farm. The primary URL identified is http://calistazz.myhome.cx/, which hosts numerous PDF files with book-like titles. This suggests the document's purpose is to manipulate search engine results or distribute potentially malicious content through these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/1869862868864/My-Life-as-a-Mole-and-Five-Other-Stories-by-Larry-Mitchell.pdf
    • http://calistazz.myhome.cx/2864864861869864/Night-Noises-And-Other-Mole-And-Troll-Stories-Mole-and-Troll-3-by-Tony-Johnston.pdf
    • http://calistazz.myhome.cx/7867868867868867/Surviving-My-Haunted-Life-True-Life-Stories-of-Ghostly-Hauntings-in-Shreveport-La-by-Linda-Mitchell-Logan.pdf
    • http://calistazz.myhome.cx/9862862860869867/The-Adrian-Mole-Collection-The-Growing-Pains-of-Adrian-Mole-True-Confessions-of-Adrian-Albert-Mole-Adrian-Mole-The-Wilderness-by-Sue-Townsend.pdf
    • http://calistazz.myhome.cx/5861863864867/Inahpozishun-Tulogeck-by-Larry-Mitchell.pdf
    • http://calistazz.myhome.cx/9868863863863863/Dangerous-Ground-Jerry-Mitchell-1-by-Larry-Bond.pdf
    • http://calistazz.myhome.cx/9868863864866864/Fatal-Thunder-Jerry-Mitchell-5-by-Larry-Bond.pdf
    • http://calistazz.myhome.cx/9868863864860862/Shattered-Trident-Jerry-Mitchell-4-by-Larry-Bond.pdf
    • http://calistazz.myhome.cx/9862862861869869/The-Naughty-Mole-by-Time-Life-Books.pdf
    • http://calistazz.myhome.cx/2869863862865868/The-Secret-Diary-of-Adrian-Mole-Aged-13-3-4-Adrian-Mole-1-by-Sue-Townsend.pdf
    • http://calistazz.myhome.cx/3867861862869866/Adrian-Mole-The-Wilderness-Years-Adrian-Mole-4-by-Sue-Townsend.pdf
    • http://calistazz.myhome.cx/4860868868866/The-Growing-Pains-of-Adrian-Mole-Adrian-Mole-2-by-Sue-Townsend.pdf
    • http://calistazz.myhome.cx/4867864861866/Adrian-Mole-The-Wilderness-Years-Adrian-Mole-4-by-Sue-Townsend.pdf
    • http://calistazz.myhome.cx/2864868867866867/Love-Stories-of-World-War-II-by-Larry-King.pdf
    • http://calistazz.myhome.cx/7864860869/All-Out-The-No-Longer-Secret-Stories-of-Queer-Teens-Throughout-the-Ages-by-Saundra-Mitchell.pdf
    • http://calistazz.myhome.cx/1866860866863868/Life-Over-Easy-Fragments-1-by-K-A-Mitchell.pdf
    • http://calistazz.myhome.cx/2863862866868862/Literary-Life-A-Second-Memoir-by-Larry-McMurtry.pdf
    • http://calistazz.myhome.cx/7868860865867860/Searching-for-Life-s-Water-by-Sita-Jehanne-Mitchell.pdf
    • http://calistazz.myhome.cx/8867861869860865/Life-of-Wallenstein---Duke-of-Friedland-by-John-Mitchell.pdf
    • http://calistazz.myhome.cx/6862865864868865/Screwball-The-life-of-Carole-Lombard-by-Larry-Swindell.pdf