Malicious PDF — malware analysis report

Static analysis result for SHA-256 f290c30cf3aed04c…

MALICIOUS

PDF

21.0 KB Created: 2020-03-15 20:30:53 +00:00 Authoring application: mPDF 5.7
MD5: a0f168fe11a5e9b7b36f013f21acb199 SHA-1: 1b18728586220a7eb2d6044baac2342514bb6161 SHA-256: f290c30cf3aed04c355a58ce0db90853d0f7487f8f2ae29084e5366692372115
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning to drive traffic to malicious sites. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic identified the link farm pattern. The embedded URLs are the primary IOCs, pointing to the domain calistazz.myhome.cx.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/4863865862868863/The-Au-Pair-A-True-Story-by-Michele-Macfarlane.pdf
    • http://calistazz.myhome.cx/2861865867864860/I-Wish-You-Didn-t-Know-My-Name-The-Story-Of-Michele-Launders-And-Her-Daughter-Lisa-by-Michele-Launders.pdf
    • http://calistazz.myhome.cx/8869867860864868/Levi-Strauss-Gets-a-Bright-Idea-A-Fairly-Fabricated-Story-of-a-Pair-of-Pants-by-Tony-Johnston.pdf
    • http://calistazz.myhome.cx/3860865861860/French-Illusions-My-Story-as-an-American-Au-Pair-in-the-Loire-Valley-Book-1-by-Linda-Kovic-Skow.pdf
    • http://calistazz.myhome.cx/2866862867861867/If-You-Love-Me-True-love-True-terror-True-story-by-Alice-Keale.pdf
    • http://calistazz.myhome.cx/1860869864861862861/Robert-Black-The-True-Story-of-a-Child-Rapist-and-Serial-Killer-Homicide-True-Crime-Cases-1-by-C-L-Swinney.pdf
    • http://calistazz.myhome.cx/5862861860860/The-Story-of-San-Michele-by-Axel-Munthe.pdf
    • http://calistazz.myhome.cx/3862861865863861/Core-of-Conviction-My-Story-by-Michele-Bachmann.pdf
    • http://calistazz.myhome.cx/2862863866868/Xelie-s-Gift-A-story-of-transformation-and-inspiration-from-this-life-to-the-next-by-Michele-McGuire.pdf
    • http://calistazz.myhome.cx/7860865863867860/The-Anunnaki-Unification-Book-3-A-Stargate-Sg-1-Fan-Fiction-Story-by-Michele-Briere.pdf
    • http://calistazz.myhome.cx/2869861865860863/An-Alcoholic-Husband---a-Story-of-Love-and-Hope-The-extraordinary-true-story-of-one-woman-s-journey-married-to-a-loveable-rogue-by-Carol-Mills.pdf
    • http://calistazz.myhome.cx/6861865863864/A-Death-In-Tuscany-Michele-Ferrara-2-by-Michele-Giuttari.pdf
    • http://calistazz.myhome.cx/9868864866865864/La-mia-storia-con-Zaira-cenerentola-a-4-zampe-The-story-of-Zaira-my-Cinderella-on-4-paws-by-Michele-Pisculli.pdf
    • http://calistazz.myhome.cx/4861865860866862/Holloway-by-Robert-Macfarlane.pdf
    • http://calistazz.myhome.cx/9864865863865860/Pierced-by-a-Sword-by-Bud-Macfarlane-Jr-.pdf
    • http://calistazz.myhome.cx/4869860864867863/Summer-Gone-by-David-MacFarlane.pdf
    • http://calistazz.myhome.cx/3868864866860866/Changing-Her-Mind-by-Stevie-MacFarlane.pdf
    • http://calistazz.myhome.cx/1865861869868869/Daughter-Of-The-Raven-by-Cherime-MacFarlane.pdf
    • http://calistazz.myhome.cx/3865863862869865/North-By-Northeast-by-Cherime-MacFarlane.pdf
    • http://calistazz.myhome.cx/4869864867864868/The-Old-Ways-A-Journey-on-Foot-by-Robert-Macfarlane.pdf
    • http://calistazz.myhome.cx/1860869864861862861/Robert-Black-The-T