Malicious PDF — malware analysis report

Static analysis result for SHA-256 b41fa82573d162ef…

MALICIOUS

PDF

17.0 KB Created: 2019-04-30 04:32:45 +01:00 Authoring application: mPDF 5.7
MD5: 8fc0ced307bd89e4e23ff650af88ad29 SHA-1: afbbf10596dc77a404a05d969e24b18f38ff50d6 SHA-256: b41fa82573d162ef41d25a2610324b3ba737d563826fd7dde19516a184395395
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. While the specific URLs appear to point to book downloads and are marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to distribute further payloads. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/7a05a03a05a06/The-Sorcerer-of-the-North-Ranger-s-Apprentice-5-by-John-Flanagan.pdf
    • http://muicuiu.dumb1.com/1a03a04a09a06a06/Ranger-s-Apprentice-7-volume-Set-Ranger-s-Apprentice-1-7-by-John-Flanagan.pdf
    • http://muicuiu.dumb1.com/5a00a05a05a02a03/The-Red-Fox-Clan-Ranger-s-Apprentice-The-Royal-Ranger-2-by-John-Flanagan.pdf
    • http://muicuiu.dumb1.com/7a02a09a07a07/The-Royal-Ranger-Ranger-s-Apprentice-12-by-John-Flanagan.pdf
    • http://muicuiu.dumb1.com/1a03a05a00a05a06/Rangers-Apprentice-Bundle-Books-1-8-Ranger-s-Apprentice-1-8-by-John-Flanagan.pdf
    • http://muicuiu.dumb1.com/3a04a00a02a04/The-Kings-of-Clonmel-Ranger-s-Apprentice-8-by-John-Flanagan.pdf
    • http://muicuiu.dumb1.com/7a06a09a05a05/The-Kings-of-Clonmel-Ranger-s-Apprentice-8-by-John-Flanagan.pdf
    • http://muicuiu.dumb1.com/7a06a01a01a08/Erak-s-Ransom-Ranger-s-Apprentice-7-by-John-Flanagan.pdf
    • http://muicuiu.dumb1.com/2a07a02a00a03a00/The-Siege-of-Macindaw-Ranger-s-Apprentice-6-by-John-Flanagan.pdf
    • http://muicuiu.dumb1.com/3a03a09a09a01/The-Siege-of-Macindaw-Ranger-s-Apprentice-6-by-John-Flanagan.pdf
    • http://muicuiu.dumb1.com/4a01a01a00a01a05/The-Siege-of-Macindaw-Ranger-s-Apprentice-6-by-John-Flanagan.pdf
    • http://muicuiu.dumb1.com/2a01a03a06a08a09/The-Ruins-of-Gorlan-Ranger-s-Apprentice-1-by-John-Flanagan.pdf
    • http://muicuiu.dumb1.com/3a00a08a02a00a02/The-Ruins-of-Gorlan-The-Burning-Bridge-Ranger-s-Apprentice-1-2-by-John-Flanagan.pdf
    • http://muicuiu.dumb1.com/4a06a00a04a07a09/The-Battle-of-Hackham-Heath-Ranger-s-Apprentice-The-Early-Years-2-by-John-Flanagan.pdf
    • http://muicuiu.dumb1.com/7a02a01a01a09/The-Ruins-of-Gorlan-The-Burning-Bridge-The-Icebound-Land-Ranger-s-Apprentice-1-3-by-John-Flanagan.pdf
    • http://muicuiu.dumb1.com/1a01a08a09a05a09/The-Icebound-Land-Oakleaf-Bearers-Rangers-Apprentice-3-4-by-John-Flanagan.pdf
    • http://muicuiu.dumb1.com/8a07a04a02a02/The-Sorcerer-s-Apprentice-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/5a00a06a08a01a08/Sorcerer-s-Apprentice-by-David-Ionovich-Bronstein.pdf
    • http://muicuiu.dumb1.com/1a00a05a07a07a02/The-Sorcerer-s-Apprentice-Tales-and-Conjurations-by-Charles-R-Johnson.pdf
    • http://muicuiu.dumb1.com/5a01a00a08a05a02/The-Sorcerer-s-Apprentice-Raven-Hill-Mysteries-2-by-Emily-Rodda.pdf
    • http://muicuiu.dumb1.com/7a06a01a01a08/Erak-s-Ransom-Ranger-s-Apprentic