Malicious PDF — malware analysis report

Static analysis result for SHA-256 10ed18c16bdc222e…

MALICIOUS

PDF

17.8 KB Created: 2019-04-30 17:53:32 +01:00 Authoring application: mPDF 5.7
MD5: e2ae6d826d4a0056b03b5fe122fc929c SHA-1: e89d7a2bd3c3fab0d4c5d3a7a24e6b6b7596363e SHA-256: 10ed18c16bdc222e2a08fa4d03b085b16054789febd41e122ba3423fb00103e7
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the 'PDF_SEO_LINK_FARM' heuristic. While the document body is heavily obfuscated, the presence of numerous links suggests an attempt to direct users to a large collection of content, potentially for SEO manipulation or to host malicious payloads. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/3200207207208201/Gaslight-Arcanum-Uncanny-Tales-of-Sherlock-Holmes-by-J-R-Campbell.pdf
    • http://xiixmcuin.linkpc.net/2202203207209209/Gaslight-Grimoire-Fantastic-Tales-of-Sherlock-Holmes-by-Charles-Prepolec.pdf
    • http://xiixmcuin.linkpc.net/1200203208205202/The-Original-Illustrated-Sherlock-Holmes-Sherlock-Holmes-3-6-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/8204208207200207/Sherlock-Holmes-e-lo-Studio-in-Rosso-Sherlock-Holmes-1-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/1201206208201207200/Sherlock-Holmes-1-Sherlock-Holmes-und-das-Druidengrab-Meisterdetektive-by-Alisha-Bionda.pdf
    • http://xiixmcuin.linkpc.net/3201206205200202/The-Adventures-of-Sherlock-Holmes-Sherlock-Holmes-3-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/2200209204204205/The-Devil-amp-Sherlock-Holmes-Tales-of-Murder-Madness-amp-Obsession-by-David-Grann.pdf
    • http://xiixmcuin.linkpc.net/7200204207207205/The-Complete-Sherlock-Holmes-and-Tales-of-Terror-and-Mystery-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/9204200207204201/The-Memoirs-of-Sherlock-Holmes-Las-Meorias-de-Sherlock-Holles-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/2205207202204203/Sherlock-The-Memoirs-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/5209203201209201/The-Return-of-SHERLOCK-HOLMES-A-Collection-of-Holmes-Adventures-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/8206203206207203/Sherlock-Holmes-and-the-Redheaded-League-On-the-Case-with-Holmes-amp-Watson-7-by-Murray-Shaw.pdf
    • http://xiixmcuin.linkpc.net/4201201205202202/Sherlock-Holmes-time-detective-by-Adrian-Sherlock.pdf
    • http://xiixmcuin.linkpc.net/9203209205209205/Eine-Studie-in-Sherlock-Eine-Studie-in-Scharlachrot-amp-Das-Zeichen-der-Vier-Zwei-Sherlock-Holmes-Romane-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/1201206209208200/Shadows-of-the-Night-Queer-Tales-of-the-Uncanny-and-Unusual-by-Greg-Herren.pdf
    • http://xiixmcuin.linkpc.net/7204204200206203/Sherlock-Holmes-en-Sib-rie-by-P-Orlovets.pdf
    • http://xiixmcuin.linkpc.net/4208205203/Mrs-Sherlock-Holmes-by-Brad-Ricca.pdf
    • http://xiixmcuin.linkpc.net/4209202204204200/The-Last-Sherlock-Holmes-Story-by-Michael-Dibdin.pdf
    • http://xiixmcuin.linkpc.net/9202204209209201/Sherlock-Holmes-in-Berlin-by-Wolfgang-Sch-ler.pdf
    • http://xiixmcuin.linkpc.net/1200204206201201204/The-Trial-of-Sherlock-Holmes-by-Leah-Moore.pdf