Malicious PDF — malware analysis report

Static analysis result for SHA-256 f81145e6ba8a0c5e…

MALICIOUS

PDF

25.2 KB Created: 2020-03-18 21:40:35 +00:00 Authoring application: mPDF 5.7
MD5: df6297bacd83ced8929bed19b62768de SHA-1: b64ddc73e104d83f0484c2f7ba26e40ca52d4361 SHA-256: f81145e6ba8a0c5ed3ae37bba50bd33351215dc6323df30d9ada24b580f6042d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDFs hosted on the domain 'calistazz.myhome.cx'. This is indicative of a link farm or a distribution point for malicious content. The ML classifier also flagged this PDF as malicious with a high probability. No scripts were extracted, and the document body was heavily obfuscated, but the presence of numerous external links strongly suggests a malicious intent to redirect the user to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/3861863865866/Alfred-Hitchcock-s-Mystery-Magazine-May-June-2017-by-Dell-Magazines.pdf
    • http://calistazz.myhome.cx/2867862861862/Alfred-Hitchcock-s-Home-Sweet-Homicide-Stories-from-Alfred-Hitchcock-s-Mystery-Magazine-by-Alfred-Hitchcock.pdf
    • http://calistazz.myhome.cx/1860868867860860864/Alfred-Hitchcock-Presents-A-Month-Of-Mystery-by-Alfred-Hitchcock.pdf
    • http://calistazz.myhome.cx/5860865862863864/Alfred-Hitchcock-Presents-Twelve-Stories-for-Late-at-Night-by-Alfred-Hitchcock.pdf
    • http://calistazz.myhome.cx/2864865862860868/The-Mystery-of-the-Singing-Serpent-Alfred-Hitchcock-and-The-Three-Investigators-17-by-M-V-Carey.pdf
    • http://calistazz.myhome.cx/1862864863866861/The-Mystery-of-the-Laughing-Shadow-Alfred-Hitchcock-and-the-Three-Investigators-12-by-William-Arden.pdf
    • http://calistazz.myhome.cx/2863867863866864/The-Mystery-of-the-Green-Ghost-Alfred-Hitchcock-and-The-Three-Investigators-4-by-Robert-Arthur.pdf
    • http://calistazz.myhome.cx/2863866869867866/The-Mystery-of-the-Whispering-Mummy-Alfred-Hitchcock-and-The-Three-Investigators-3-by-Robert-Arthur.pdf
    • http://calistazz.myhome.cx/2864865860866861/The-Mystery-of-the-Shrinking-House-Alfred-Hitchcock-and-The-Three-Investigators-18-by-William-Arden.pdf
    • http://calistazz.myhome.cx/1860868866869862863/The-Best-of-Mystery-63-Short-Stories-Chosen-by-the-Master-of-Suspense-by-Alfred-Hitchcock.pdf
    • http://calistazz.myhome.cx/1860868866868868863/The-Mystery-of-the-Nervous-Lion-Alfred-Hitchcock-and-The-Three-Investigators-16-by-Nick-West.pdf
    • http://calistazz.myhome.cx/1860868866868868862/Alfred-Hitchcock-s-A-Hangman-s-Dozen-by-Alfred-Hitchcock.pdf
    • http://calistazz.myhome.cx/1860868866869869868/Writing-With-Hitchcock-The-Collaboration-of-Alfred-Hitchcock-and-John-Michael-Hayes-by-Steven-DeRosa.pdf
    • http://calistazz.myhome.cx/7861866866862864/Artificial-Intelligence-and-Soft-Computing-16th-International-Conference-Icaisc-2017-Zakopane-Poland-June-11-15-2017-Part-II-by-Leszek-Rutkowski.pdf
    • http://calistazz.myhome.cx/1861866864864861864/Magazines-Established-in-1994-Dengeki-Daioh-Slam-Magazine-Fourfourtwo-Loaded-Brave-Words-by-Books-LLC.pdf
    • http://calistazz.myhome.cx/7865863860864860/Whatever-Our-Souls-Issue-2-June-2017-by-Mandi-Jourdan.pdf
    • http://calistazz.myhome.cx/2865869867861/Uncanny-Magazine-Issue-18-September-October-2017-by-Lynne-M-Thomas.pdf
    • http://calistazz.myhome.cx/8867869862866868/June-Cleaver-Was-a-Feminist-by-Cary-O-39-Dell.pdf
    • http://calistazz.myhome.cx/1861863862866869868/RENT-MY-WEDDING-Magazine---Fall-2017-Volume-1-Book-3-by-Marie-Kubin.pdf
    • http://calistazz.myhome.cx/1860868866869863860/Alfred-Hitchcock-s-Rear-Window-by-John-Belton.pdf
    • http://calistazz.myhome.cx/1862864863