Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe1e4ebeb3625b0d…

MALICIOUS

PDF

14.9 KB Created: 2020-03-18 16:43:46 +00:00 Authoring application: mPDF 5.7
MD5: 6d18955c96f7a3ef3bbaef472f94f2a9 SHA-1: 02bb136ce93de2ea8861c1dc598fd0d73ae9d24c SHA-256: fe1e4ebeb3625b0d7ee82461b5abdb4e235abce30aaef867e9864210fdbb8805
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document was identified as malicious due to a critical heuristic firing for a link farm containing 20 external PDF links. The document body confirms the presence of these links, all pointing to the domain 'calistazz.myhome.cx'. This suggests a phishing or content-distribution attack where users are lured to click on these links, potentially leading to further malware downloads or credential harvesting. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/1865863868861866/Victoria-in-the-Wings-Georgian-Saga-11-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/1865863868865868/Perdita-s-Prince-Georgian-Saga-6-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/1865863869866869/The-Prince-and-the-Quakeress-Georgian-Saga-4-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/1865863869864868/Queen-in-Waiting-Georgian-Saga-2-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/1867862860866861/The-Vow-on-the-Heron-Plantagenet-Saga-9-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/1865863865866866/The-Murder-in-the-Tower-Stuart-Saga-3-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/3869869867860869/Edward-Longshanks-Plantagenet-Saga-7-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/1865863864863860/The-Battle-of-the-Queens-Plantagenet-Saga-5-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/1867862860866862/The-Star-of-Lancaster-Plantagenet-Saga-11-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/1865863865863868/The-Prince-of-Darkness-Plantagenet-Saga-4-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/1865863866866868/The-Follies-of-the-King-Plantagenet-Saga-8-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/1865863867864868/The-Star-of-Lancaster-Plantagenet-Saga-11-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/1865863860867862/Katharine-the-Virgin-Widow-Tudor-Saga-2-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/1865862864865861/Mary-Queen-of-France-Tudor-Saga-9-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/1863864865869861/Katharine-of-Aragon-The-Wives-of-Henry-VIII-Tudor-Saga-2-4-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/1865863866864863/The-Queen-and-Lord-M-Queen-Victoria-2-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/2865861861867868/The-Queen-and-Lord-M-Queen-Victoria-2-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/1865860860861862/The-Royal-Road-to-Fotheringhay-Stuart-Saga-1-Mary-Stuart-1-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/4866868869864862/Royal-Road-to-Fotheringhay-Stuart-Saga-1-Mary-Stuart-1-by-Jean-Plaidy.pdf
    • http://calistazz.myhome.cx/1865861866861864/The-Plantagenet-Prelude-Plantagenet-Saga-1-by-Jean-Plaidy.pdf
    • http://calistazz.m