Malicious PDF — malware analysis report

Static analysis result for SHA-256 64aecfa804e0f390…

MALICIOUS

PDF

22.2 KB Created: 2019-05-02 19:52:46 +01:00 Authoring application: mPDF 5.7
MD5: ad4d7dc5f23ba5579a6f78b13dfeebf1 SHA-1: f5913a17e0c09327c52612b97c75bf959fffb44c SHA-256: 64aecfa804e0f3900ab978c213ad6b035fe1c0558f4a5f22f82f63b197bce1fa
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded external links, identified as a link farm. The primary heuristic indicates this is a SEO-based tactic to distribute content, likely as a lure. While no scripts were extracted, the sheer volume of links suggests an attempt to drive traffic to potentially malicious or deceptive content, masquerading as legitimate literature.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8094098092093096/The-Sherlock-Holmes-Illustrated-Omnibus-The-Adventures-of-Sherlock-Holmes-the-Memoirs-of-Sherlock-Holmes-the-Hound-of-the-Baskervilles-the-Return-of-Sherlock-Holmes-A-Facsimile-of-the-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/3092090090091091/The-Adventures-of-Sherlock-Holmes-Sherlock-Holmes-3-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/6091099091097092/The-Adventures-of-Sherlock-Holmes-Sherlock-Holmes-3-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/4094092094094091/Adventures-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/8090090096095/The-Adventures-and-the-Memoirs-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/1090094096091091095/The-Great-Adventures-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/5097091097098/The-Adventures-of-Sherlock-Holmes-and-Other-Stories-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/5090095097099092/The-Adventures-of-Sherlock-Holmes-original-illustrated-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/1090097095092095093/The-Adventures-of-Sherlock-Holmes-Radio-Dramatization-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/2093097090097093/The-Five-Orange-Pips-The-Adventures-of-Sherlock-Holmes-5-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/9096097099094092/Arthur-Conan-Doyle-Sherlock-Holmes---Die-Romane-Eine-Studie-in-Scharlachrot---Das-Zeichen-der-Vier---Der-Hund-der-Baskervilles---Das-Tal-des-Grauens-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/8090092099098095/The-Adventures-Of-Sherlock-Holmes-JBS-Classics---Illustrated-100-Formatted-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/2093097090097096/The-Boscombe-Valley-Mystery-The-Adventures-of-Sherlock-Holmes-4-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/6090091094097092/The-Adventures-of-Sherlock-Holmes-100-Greatest-Books-Ever-Written-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/3090093092093094/The-Adventure-of-the-Blue-Carbuncle-The-Adventures-of-Sherlock-Holmes-7-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/2093096099098097/The-Adventure-of-the-Engineer-s-Thumb-The-Adventures-of-Sherlock-Holmes-9-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/8098099093093095/Die-Abenteuer-des-Sherlock-Holmes-Sherlock-Holmes-Ausgabe-Band-1-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/1090093098095092/The-Original-Illustrated-Sherlock-Holmes-Sherlock-Holmes-3-6-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/2091095090099093/The-Case-Book-of-Sherlock-Holmes-Sherlock-Holmes-9-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/8090093098092091/The-Sherlock-Holmes-Collection-by-Arthur-Conan-Doyle-by-Arthur-Conan-Doyle.pdf