Malicious PDF — malware analysis report

Static analysis result for SHA-256 70325bae67ddc9d2…

MALICIOUS

PDF

28.7 KB Created: 2019-05-02 06:12:13 +01:00 Authoring application: mPDF 5.7
MD5: f1b6ad9f8252e31d9571568dce9f8df7 SHA-1: 2c73d98131b121a9443d13e49e9cbb4830373079 SHA-256: 70325bae67ddc9d239d3e37d2de020505d45489e1b7589593924059c4daf1f3e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, identified as a link farm. While the document body is heavily obfuscated, the heuristic firings strongly indicate a malicious intent to redirect users to a large collection of documents. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2735733731731732/Sherlock-Holmes-Volume-1-A-Study-in-Scarlet-amp-Other-Sherlock-Holmes-Stories-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/8736734731739739/Die-R-ckkehr-des-Sherlock-Holmes-Im-leeren-Hause-und-andere-Detektivgeschichten-The-Return-of-Sherlock-Holmes-The-Empty-House-and-Other-Stories---Zweisprachige-einsame-Radfahrerin-etc-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/1731733730731731733/Sherlock-Holmes---Die-sch-nsten-Geschichten-Band-5-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/3738735739737736/The-Adventure-of-the-Reigate-Squire-The-Memoirs-of-Sherlock-Holmes-6-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/7739733734737/The-Adventure-of-Black-Peter-The-Return-of-Sherlock-Holmes-6-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/9735734735738738/Sherlock-Holmes---Die-sch-nsten-Detektivgeschichten-Band-2-Kommentierte-amp-Illustrierte-Ausgabe-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/3732732738731734/Sherlock-Holmes-Selected-Stories-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/5737731737738/The-Adventures-of-Sherlock-Holmes-and-Other-Stories-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/8731731732739736/The-Complete-Stories-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/1735735737739732/The-Best-of-Sherlock-Holmes-Volume-1-Stories-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/8736734731733730/Die-Memoiren-des-Sherlock-Holmes-Holmes-erstes-Abenteuer-und-andere-Detektivgeschichten-The-Memoirs-of-Sherlock-Holmes-The-Gloria-Scott-and-Other-Gesicht-und-vieles-mehr-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/8734738730737734/The-Complete-Sherlock-Holmes-Treasury-Including-The-Complete-Adventures-and-Memoirs-of-Sherlock-Holmes-The-Return-of-Sherlock-Holmes-The-Hound-of-the-Baskervilles-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/1739730736730732/Sherlock-Holmes-The-Complete-Novels-and-Stories-Volume-II-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/3734731732739/Sherlock-Holmes-The-Complete-Novels-and-Stories-Volume-I-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/6730731734732/Sherlock-Holmes-The-Complete-Novels-and-Stories-Volumes-I-and-II-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/4730738730738/The-Original-Illustrated-Sherlock-Holmes-37-Short-Stories-Plus-a-Complete-Novel-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/1730735736739735730/A-Study-in-Scarlet-Introducing-Sherlock-Holmes-The-Sherlock-Holmes-Collection-Volume-1-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/1730730737731737737/The-Adventures-of-Sherlock-Holmes-Die-Abenteuer-von-Sherlock-Holmes---zweisprachig-Englisch-Deutsch-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/7737733733730734/The-Adventures-of-Sherlock-Holmes-Sherlock-Holmes-The-Definitive-Collection-3-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/2731735730739733/The-Case-Book-of-Sherlock-Holmes-Sherlock-Holmes-9-by-Arthur-Conan-Doyle.pdf