Malicious PDF — malware analysis report

Static analysis result for SHA-256 1a04bd466c2466a8…

MALICIOUS

PDF

16.4 KB Created: 2019-05-01 13:05:53 +01:00 Authoring application: mPDF 5.7
MD5: 7a4eaf31a4c58f5c317bfee444888af5 SHA-1: c11c698ebdfd203d149fc69ad400d5a5ff79fc11 SHA-256: 1a04bd466c2466a8ab4c12ab79e0387f66f10631aa1ab64a3d638a0e22612287
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document was identified as malicious due to a critical heuristic firing for a large number of external links. These links, such as http://cefasfese.4pu.com/3739732734737739/Blue-Moon-Anita-Blake-Vampire-Hunter-8-by-Laurell-K-Hamilton.pdf, are likely part of a link farm designed to redirect users to malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese
    • http://cefasfese.4pu.com/3739732734737739/Blue-Moon-Anita-Blake-Vampire-Hunter-8-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/3732733739732732/Blue-Moon-Anita-Blake-Vampire-Hunter-8-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/7738739733737738/Laurell-K-Hamilton-s-Anita-Blake-Vampire-Hunter---The-First-Death-2-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/7738739734736737/Laurell-K-Hamilton-s-Anita-Blake-Vampire-Hunter---The-First-Death-1-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/8736735739/Serpentine-Anita-Blake-Vampire-Hunter-26-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/2730737735735738/Affliction-Anita-Blake-Vampire-Hunter-22-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/1732738739733734/Jason-Anita-Blake-Vampire-Hunter-23-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/7738739733737739/Anita-Blake-Vampire-Hunter-Collection-16-19-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/1739739736739731/The-Harlequin-Anita-Blake-Vampire-Hunter-15-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/3739739730732738/Guilty-Pleasures-Anita-Blake-Vampire-Hunter-1-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/3734738737734732/Circus-of-the-Damned-Anita-Blake-Vampire-Hunter-3-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/3732734731731732/Skin-Trade-Anita-Blake-Vampire-Hunter-17-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/3730732738736735/The-Lunatic-Cafe-Anita-Blake-Vampire-Hunter-4-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/3732733739731738/The-Laughing-Corpse-Anita-Blake-Vampire-Hunter-2-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/3733737733736/The-Killing-Dance-Anita-Blake-Vampire-Hunter-6-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/8736731731731/The-Midnight-Cafe-Anita-Blake-Vampire-Hunter-4-6-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/3733738738734/Bloody-Bones-Anita-Blake-Vampire-Hunter-5-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/3735734733736730/Incubus-Dreams-Anita-Blake-Vampire-Hunter-12-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/1739730734734739/Obsidian-Butterfly-Anita-Blake-Vampire-Hunter-9-by-Laurell-K-Hamilton.pdf
    • http://cefasfese.4pu.com/4734731738732730/Anita-Blake-Vampire-Hunter-Guilty-Pleasures-by-Laurell-K-Hamilton.pdf