Malicious PDF — malware analysis report

Static analysis result for SHA-256 f550e2e501a9cdd7…

MALICIOUS

PDF

24.6 KB Created: 2020-03-18 16:43:37 +00:00 Authoring application: mPDF 5.7
MD5: f49f12f570052db0ebe46b880cf785d3 SHA-1: 435fd21b52328abbee6afcb2533b48335133c08f SHA-256: f550e2e501a9cdd78080ac6debcdcbc161f575eb812145a0d86a8aa8932f22cb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'calistazz.myhome.cx'. This behavior is indicative of a link farm, likely used for SEO manipulation or to distribute further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9773

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/1861861863860863867/The-Alfred-Hitchcock-Presents-Companion-by-Martin-Grams-Jr-.pdf
    • http://calistazz.myhome.cx/5860865862863864/Alfred-Hitchcock-Presents-Twelve-Stories-for-Late-at-Night-by-Alfred-Hitchcock.pdf
    • http://calistazz.myhome.cx/1860868867860860864/Alfred-Hitchcock-Presents-A-Month-Of-Mystery-by-Alfred-Hitchcock.pdf
    • http://calistazz.myhome.cx/2867862861862/Alfred-Hitchcock-s-Home-Sweet-Homicide-Stories-from-Alfred-Hitchcock-s-Mystery-Magazine-by-Alfred-Hitchcock.pdf
    • http://calistazz.myhome.cx/1860868866868868862/Alfred-Hitchcock-s-A-Hangman-s-Dozen-by-Alfred-Hitchcock.pdf
    • http://calistazz.myhome.cx/1860868866869869868/Writing-With-Hitchcock-The-Collaboration-of-Alfred-Hitchcock-and-John-Michael-Hayes-by-Steven-DeRosa.pdf
    • http://calistazz.myhome.cx/1860868866869863860/Alfred-Hitchcock-s-Rear-Window-by-John-Belton.pdf
    • http://calistazz.myhome.cx/2864865862860868/The-Mystery-of-the-Singing-Serpent-Alfred-Hitchcock-and-The-Three-Investigators-17-by-M-V-Carey.pdf
    • http://calistazz.myhome.cx/6862865868861868/Alfred-Hitchcock-A-Life-in-Darkness-and-Light-by-Patrick-McGilligan.pdf
    • http://calistazz.myhome.cx/5867868863868869/The-Secret-of-the-Crooked-Cat-Alfred-Hitchcock-and-The-Three-Investigators-13-by-William-Arden.pdf
    • http://calistazz.myhome.cx/3861867866866860/The-Secret-of-the-Crooked-Cat-Alfred-Hitchcock-and-The-Three-Investigators-13-by-William-Arden.pdf
    • http://calistazz.myhome.cx/1860868866869869865/The-Art-of-Alfred-Hitchcock-Fifty-Years-of-His-Motion-Pictures-by-Donald-Spoto.pdf
    • http://calistazz.myhome.cx/1860868866868868863/The-Mystery-of-the-Nervous-Lion-Alfred-Hitchcock-and-The-Three-Investigators-16-by-Nick-West.pdf
    • http://calistazz.myhome.cx/2863867863866864/The-Mystery-of-the-Green-Ghost-Alfred-Hitchcock-and-The-Three-Investigators-4-by-Robert-Arthur.pdf
    • http://calistazz.myhome.cx/1860868866869862862/Spellbound-by-Beauty-Alfred-Hitchcock-and-His-Leading-Ladies-by-Donald-Spoto.pdf
    • http://calistazz.myhome.cx/7865863866864/The-Secret-of-Terror-Castle-Alfred-Hitchcock-and-The-Three-Investigators-1-by-Robert-Arthur.pdf
    • http://calistazz.myhome.cx/2863866869867866/The-Mystery-of-the-Whispering-Mummy-Alfred-Hitchcock-and-The-Three-Investigators-3-by-Robert-Arthur.pdf
    • http://calistazz.myhome.cx/2864863862865865/The-Secret-of-Skeleton-Island-Alfred-Hitchcock-and-The-Three-Investigators-6-by-Robert-Arthur.pdf
    • http://calistazz.myhome.cx/1860868866869862863/The-Best-of-Mystery-63-Short-Stories-Chosen-by-the-Master-of-Suspense-by-Alfred-Hitchcock.pdf
    • http://calistazz.myhome.cx/3861863865866/Alfred-Hitchcock-s-Mystery-Magazine-May-June-2017-by-Dell-Magazines.pdf