Malicious PDF — malware analysis report

Static analysis result for SHA-256 eb4de5119adeb0c7…

MALICIOUS

PDF

15.7 KB Created: 2020-03-18 21:41:05 +00:00 Authoring application: mPDF 5.7
MD5: aa254a1701a29a5678c31fb2c069b680 SHA-1: ecc25071eff916aa5cfe5f3e1d403320d78ec2a4 SHA-256: eb4de5119adeb0c7e29adb741916904182f8c316c912498bcf727cacd2547cf8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various book titles hosted on the domain 'calistazz.myhome.cx'. This suggests a link farm or SEO poisoning attack. The ML classifier also flagged the PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/1866860865861867/Inertia-Impulse-1-by-Amelia-C-Gormley.pdf
    • http://calistazz.myhome.cx/3869863863865864/Inertia-Impulse-1-by-Amelia-C-Gormley.pdf
    • http://calistazz.myhome.cx/3860863861863860/Bane-Strain-2-by-Amelia-C-Gormley.pdf
    • http://calistazz.myhome.cx/3866864862869864/Bane-Strain-2-by-Amelia-C-Gormley.pdf
    • http://calistazz.myhome.cx/2865867861867862/The-Laird-s-Forbidden-Lover-by-Amelia-C-Gormley.pdf
    • http://calistazz.myhome.cx/2862860863860862/Inertia-Inertia-1-by-Dani-Hermit.pdf
    • http://calistazz.myhome.cx/2862864863862867/Saugatuck-Summer-Saugatuck-1-by-Amelia-C-Gormley.pdf
    • http://calistazz.myhome.cx/5864869863866/Strain-Strain-1-by-Amelia-C-Gormley.pdf
    • http://calistazz.myhome.cx/3867863861867864/Amelia-s-Most-Unforgettable-Embarrassing-Moments-Amelia-s-Notebooks-16-by-Marissa-Moss.pdf
    • http://calistazz.myhome.cx/9866869862866/Amelia-the-Venutons-and-the-Golden-Cage-Amelia-s-Amazing-Space-Adventures-2-by-Evonne-Blanchard.pdf
    • http://calistazz.myhome.cx/3867863861865867/Luv-Amelia-Luv-Nadia-Amelia-s-Notebooks-6-by-Marissa-Moss.pdf
    • http://calistazz.myhome.cx/2864861868867866/Amelia-Writes-Again-Amelia-s-Notebooks-2-by-Marissa-Moss.pdf
    • http://calistazz.myhome.cx/1865862865865864/Salome-by-Beatrice-Gormley.pdf
    • http://calistazz.myhome.cx/8861869865866866/Archibald-Cox-Conscience-Of-A-Nation-by-Ken-Gormley.pdf
    • http://calistazz.myhome.cx/2862866863862861/The-Death-of-American-Virtue-Clinton-vs-Starr-by-Ken-Gormley.pdf
    • http://calistazz.myhome.cx/2866866863867866/Don-t-Feed-the-Fairies-The-Cytolene-Chronicles-1-by-Eileen-Gormley.pdf
    • http://calistazz.myhome.cx/1865862866863863/Poisoned-Honey-A-Story-of-Mary-Magdalene-by-Beatrice-Gormley.pdf
    • http://calistazz.myhome.cx/2867862864865/Murder-by-Impulse-by-D-R-Meredith.pdf
    • http://calistazz.myhome.cx/3861869862866863/Impulse-by-Candace-Camp.pdf
    • http://calistazz.myhome.cx/9869869868862869/Impulse-Mageri-3-by-Dannika-Dark.pdf