Malicious PDF — malware analysis report

Static analysis result for SHA-256 840093ab81b18c8f…

MALICIOUS

PDF

18.7 KB Created: 2019-05-05 16:53:07 +01:00 Authoring application: mPDF 5.7
MD5: 4334b8f45b0826dc28fce5a0710fd426 SHA-1: 7e5aee4244089161201d1aee337579b810fecd5b SHA-256: 840093ab81b18c8f05a5bee1063f167eab17a0b78f5b2676af36aea0b9be0416
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, many of which are structured like book summaries and point to external PDFs. The heuristic PDF_SEO_LINK_FARM indicates this is a link farm, suggesting a deceptive purpose. While the ML classifier strongly flagged it as malicious, the exact payload or intent beyond link distribution is unclear from the provided evidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/5203209206200208/Quicklet-on-Stieg-Larsson-s-The-Girl-with-the-Dragon-Tattoo-Book-Summary-by-Estelle-Wagner.pdf
    • http://xiixmcuin.linkpc.net/5203209205209208/The-Girl-with-the-Dragon-Tattoo-by-Stieg-Larsson-l-Summary-amp-Study-Guide-by-BookRags.pdf
    • http://xiixmcuin.linkpc.net/1200202206200208201/The-Girl-with-the-Dragon-Tattoo-Millennium-1-by-Stieg-Larsson.pdf
    • http://xiixmcuin.linkpc.net/1201207207207201209/The-Girl-with-the-Dragon-Tattoo-in-Vietnamese-by-Stieg-Larsson.pdf
    • http://xiixmcuin.linkpc.net/2206208204201/The-Girl-with-the-Dragon-Tattoo-Millennium-1-by-Stieg-Larsson.pdf
    • http://xiixmcuin.linkpc.net/5203209204208204/Stieg-Larsson-The-Man-Behind-The-Girl-with-the-Dragon-Tattoo-by-Kurdo-Baksi.pdf
    • http://xiixmcuin.linkpc.net/5203209205203206/The-Girl-in-the-Spider-s-Web-A-Lisbeth-Salander-novel-continuing-Stieg-Larsson-s-Millennium-Series-by-David-Lagercrantz-Unofficial-amp-Independent-Summary-amp-Analysis-by-Leopard-Books.pdf
    • http://xiixmcuin.linkpc.net/1200202206200208202/The-Girl-Who-Played-with-Fire-by-Stieg-Larsson.pdf
    • http://xiixmcuin.linkpc.net/4207203201206206/The-Girl-Who-Played-with-Fire-Millennium-2-by-Stieg-Larsson.pdf
    • http://xiixmcuin.linkpc.net/9206206201/The-Girl-Who-Played-with-Fire-Millennium-2-by-Stieg-Larsson.pdf
    • http://xiixmcuin.linkpc.net/4205209207200204/The-Girl-Who-Played-with-Fire-Millennium-2-by-Stieg-Larsson.pdf
    • http://xiixmcuin.linkpc.net/3204202202206204/The-Girl-Who-Played-with-Fire-Millennium-2-by-Stieg-Larsson.pdf
    • http://xiixmcuin.linkpc.net/3200201209204204/The-Girl-Who-Kicked-the-Hornet-s-Nest-Millennium-3-by-Stieg-Larsson.pdf
    • http://xiixmcuin.linkpc.net/6205203205204208/The-Girl-Who-Kicked-the-Hornet-s-Nest-Millennium-3-by-Stieg-Larsson.pdf
    • http://xiixmcuin.linkpc.net/1207209203201201/The-Girl-With-the-Dragon-Tattoo-Book-1-Millennium-The-Graphic-Novels-1-1-by-Denise-Mina.pdf
    • http://xiixmcuin.linkpc.net/1209203204204200/The-Girl-With-the-Dragon-Tattoo-Book-2-Millennium-The-Graphic-Novels-1-2-by-Denise-Mina.pdf
    • http://xiixmcuin.linkpc.net/4205204203205203/The-Dragon-with-the-Girl-Tattoo-Paranormal-Dating-Agency-Dragon-Guard-16-by-Julia-Mills.pdf
    • http://xiixmcuin.linkpc.net/6201205200206208/Quicklet-on-Carlos-Ruiz-Zaf-n-s-The-Shadow-of-the-Wind-Book-Summary-by-Luke-Trayser.pdf
    • http://xiixmcuin.linkpc.net/3202207205209208/The-Girl-With-the-Dragon-Tattoo-Millennium-The-Graphic-Novels-1-2-by-Denise-Mina.pdf
    • http://xiixmcuin.linkpc.net/5203209205209205/Afterword-by-Stieg-Larsson.pdf