Malicious PDF — malware analysis report

Static analysis result for SHA-256 b50df7fd41a1b36d…

MALICIOUS

PDF

16.3 KB Created: 2019-04-30 04:58:14 +01:00 Authoring application: mPDF 5.7
MD5: d0b6328dfa5fdc8f84efdd5048f28a9e SHA-1: c40f22fd7ce05fd055d7822b0dd7d23bc0d81710 SHA-256: b50df7fd41a1b36d9cc6d07a48ba30ac623c69dcc03a8677d878ebe409c5ce39
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded URLs, forming a link farm. The heuristic PDF_SEO_LINK_FARM indicates this is a technique to distribute content or potentially lead users to malicious sites. While the specific URLs extracted were labeled benign, the sheer volume and the ML classifier's high confidence suggest a malicious intent, likely for SEO manipulation or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a08a04a08a01a05/In-the-Name-of-the-Father-The-Story-of-Gerry-Conlon-of-the-Guildford-Four-by-Gerry-Conlon.pdf
    • http://muicuiu.dumb1.com/1a00a08a08a09a06a03/Gerry-Tales-How-I-Lived-Happily-Ever-After-Despite-Stabbing-Myself-in-the-Back-Scalding-My-Cojones-and-Really-Pissing-Off-My-Wife-During-Childbirth-by-Gerry-Boylan.pdf
    • http://muicuiu.dumb1.com/6a06a03a01a06a02/The-Innocent-Auction-Innocent-1-by-Victoria-Sue.pdf
    • http://muicuiu.dumb1.com/4a07a08a06a00a03/The-Innocent-Betrayal-Innocent-2-by-Victoria-Sue.pdf
    • http://muicuiu.dumb1.com/1a06a08a02a07/Red-on-Red-by-Edward-Conlon.pdf
    • http://muicuiu.dumb1.com/3a08a07a00a00/A-Matrix-of-Angels-by-Christopher-Conlon.pdf
    • http://muicuiu.dumb1.com/2a07a06a05a07a06/Pink-Innocent-Vol-1-Pink-Innocent-1-by-Kotori-Momoyuki.pdf
    • http://muicuiu.dumb1.com/6a05a09a07a06a03/Love-Lucie-x-by-Marita-Conlon-McKenna.pdf
    • http://muicuiu.dumb1.com/3a00a02a05a05a01/Fields-of-Home-by-Marita-Conlon-McKenna.pdf
    • http://muicuiu.dumb1.com/8a02a07a04a02a09/The-Hat-Shop-On-The-Corner-by-Marita-Conlon-McKenna.pdf
    • http://muicuiu.dumb1.com/3a08a08a00a09/Midnight-on-Mourn-Street-by-Christopher-Conlon.pdf
    • http://muicuiu.dumb1.com/4a04a05a09a03a05/The-Oblivion-Room-Stories-of-Violation-by-Christopher-Conlon.pdf
    • http://muicuiu.dumb1.com/2a05a09a07a02a01/Children-of-the-Famine-Trilogy-by-Marita-Conlon-McKenna.pdf
    • http://muicuiu.dumb1.com/1a00a01a07a04a08/Under-the-Hawthorn-Tree-Children-of-the-Famine-1-by-Marita-Conlon-McKenna.pdf
    • http://muicuiu.dumb1.com/1a00a05a02a09a06a01/Rossum-s-Universal-Replicas-Karel-Capek-s-quot-R-U-R-quot-Reimagined-by-Christopher-Conlon.pdf
    • http://muicuiu.dumb1.com/2a04a04a01a09/Elmer-by-Gerry-Alanguilan.pdf
    • http://muicuiu.dumb1.com/4a05a03a04a02a07/Wasted-by-Gerry-Alanguilan.pdf
    • http://muicuiu.dumb1.com/5a03a01/Hawkeye-vs-Deadpool-by-Gerry-Duggan.pdf
    • http://muicuiu.dumb1.com/1a09a03a04a04a02/Essential-Ms-Marvel-Vol-1-by-Gerry-Conway.pdf
    • http://muicuiu.dumb1.com/2a04a00a08a09/Carnage-Volume-1-The-One-That-Got-Away-by-Gerry-Conway.pdf