Malicious PDF — malware analysis report

Static analysis result for SHA-256 7043a79bbd3f25c1…

MALICIOUS

PDF

17.3 KB Created: 2019-04-30 02:15:19 +01:00 Authoring application: mPDF 5.7
MD5: 3d5dfeb4ea1670e67aa96cd17d70b186 SHA-1: b5e7e669ab6e9a12fb86f4381f27d4a7f79795b5 SHA-256: 7043a79bbd3f25c13c2d49167a0bd0804c653212976120337ef19225d61e22dc
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or distribution mechanism. While the document body is unreadable, the ML classifier strongly indicates maliciousness. The embedded URLs, though marked as benign, are part of a pattern consistent with distributing malicious content or SEO spam.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1201206208201207200/Sherlock-Holmes-1-Sherlock-Holmes-und-das-Druidengrab-Meisterdetektive-by-Alisha-Bionda.pdf
    • http://xiixmcuin.linkpc.net/8204208207200207/Sherlock-Holmes-e-lo-Studio-in-Rosso-Sherlock-Holmes-1-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/1200203208205202/The-Original-Illustrated-Sherlock-Holmes-Sherlock-Holmes-3-6-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/3201206205200202/The-Adventures-of-Sherlock-Holmes-Sherlock-Holmes-3-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/9204200207204201/The-Memoirs-of-Sherlock-Holmes-Las-Meorias-de-Sherlock-Holles-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/2205207202204203/Sherlock-The-Memoirs-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/5209203201209201/The-Return-of-SHERLOCK-HOLMES-A-Collection-of-Holmes-Adventures-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/8206203206207203/Sherlock-Holmes-and-the-Redheaded-League-On-the-Case-with-Holmes-amp-Watson-7-by-Murray-Shaw.pdf
    • http://xiixmcuin.linkpc.net/4201201205202202/Sherlock-Holmes-time-detective-by-Adrian-Sherlock.pdf
    • http://xiixmcuin.linkpc.net/9203209205209205/Eine-Studie-in-Sherlock-Eine-Studie-in-Scharlachrot-amp-Das-Zeichen-der-Vier-Zwei-Sherlock-Holmes-Romane-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/7204204200206203/Sherlock-Holmes-en-Sib-rie-by-P-Orlovets.pdf
    • http://xiixmcuin.linkpc.net/4208205203/Mrs-Sherlock-Holmes-by-Brad-Ricca.pdf
    • http://xiixmcuin.linkpc.net/2204203207200204/Sherlock-Holmes-The-Army-of-Dr-Moreau-by-Guy-Adams.pdf
    • http://xiixmcuin.linkpc.net/1201202209207205205/Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/1200205201204203201/Sherlock-Holmes-and-the-Red-Demon-by-Larry-Millett.pdf
    • http://xiixmcuin.linkpc.net/3208201200205208/The-Best-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://xiixmcuin.linkpc.net/1200204206201201204/The-Trial-of-Sherlock-Holmes-by-Leah-Moore.pdf
    • http://xiixmcuin.linkpc.net/4200204205203202/The-Sherlock-Holmes-Handbook-by-Ransom-Riggs.pdf
    • http://xiixmcuin.linkpc.net/4206205203203208/The-Lost-Adventures-of-Sherlock-Holmes-by-Ken-Greenwald.pdf
    • http://xiixmcuin.linkpc.net/9202204209209201/Sherlock-Holmes-in-Berlin-by-Wolfgang-Sch-ler.pdf