Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e05bb375b0364b7…

MALICIOUS

PDF

16.6 KB Created: 2019-06-04 12:05:06 +01:00 Authoring application: mPDF 5.7
MD5: 4dcbeffc90aee283529dc5ab93e0ef32 SHA-1: 4565ef43ea986171e0d44259db74de6bde82a791 SHA-256: 1e05bb375b0364b77136ee0563b5421a8dc0b01a93e8c4ef571e823f40a72e94
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs pointing to a single domain, 'cefasfese.4pu.com'. This domain appears to be hosting a link farm, likely intended to direct users to various PDF documents. The heuristic 'PDF_SEO_LINK_FARM' indicates a malicious intent to generate traffic or potentially distribute further malicious content through these links. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfes
    • http://cefasfese.4pu.com/5738738739737734/Milan-Kundera-amp-the-Art-of-Fiction-Critical-Essays-by-Aron-Aji.pdf
    • http://cefasfese.4pu.com/3733735734732/Immortality-by-Milan-Kundera.pdf
    • http://cefasfese.4pu.com/9730733737734737/The-Joke-by-Milan-Kundera.pdf
    • http://cefasfese.4pu.com/7737732735730/Edward-And-God-by-Milan-Kundera.pdf
    • http://cefasfese.4pu.com/1735735735739/Life-is-Elsewhere-by-Milan-Kundera.pdf
    • http://cefasfese.4pu.com/3736738732733/The-Joke-by-Milan-Kundera.pdf
    • http://cefasfese.4pu.com/6737738739730730/A-Insustent-vel-Leveza-do-Ser-by-Milan-Kundera.pdf
    • http://cefasfese.4pu.com/5738738739731738/Milan-Kundera-by-Glen-Brand.pdf
    • http://cefasfese.4pu.com/4730738731732/Laughable-Loves-by-Milan-Kundera.pdf
    • http://cefasfese.4pu.com/2739737736731736/The-Unbearable-Lightness-of-Being-by-Milan-Kundera.pdf
    • http://cefasfese.4pu.com/6733736736731/Farewell-Waltz-by-Milan-Kundera.pdf
    • http://cefasfese.4pu.com/3732732734739731/The-Unbearable-Lightness-of-Being-by-Milan-Kundera.pdf
    • http://cefasfese.4pu.com/3734731738731/The-Book-of-Laughter-and-Forgetting-by-Milan-Kundera.pdf
    • http://cefasfese.4pu.com/9730733736739738/The-Book-of-Laughter-and-Forgetting-by-Milan-Kundera.pdf
    • http://cefasfese.4pu.com/5738738739731732/Translating-Milan-Kundera-by-Michelle-Woods.pdf
    • http://cefasfese.4pu.com/5736731737738734/Nevynosimaya-legkost-bytiya-Roman-by-Milan-Kundera.pdf
    • http://cefasfese.4pu.com/1739730733733730/Testaments-Betrayed-An-Essay-in-Nine-Parts-by-Milan-Kundera.pdf
    • http://cefasfese.4pu.com/5738739730731739/Terminal-Paradox-Novels-of-Milan-Kundera-by-N-Banerjee.pdf
    • http://cefasfese.4pu.com/5738738739734730/Understanding-Milan-Kundera-Public-Events-Private-Affairs-by-Fred-Misurella.pdf
    • http://cefasfese.4pu.com/5732739739732734/The-Scarlet-Letter-Complete-Authoritative-Text-With-Biographical-Background-And-Critical-History-Plus-Essays-From-Five-Contemporary-Critical-Perspectives-With-Introductions-And-Bibliographies-by-Nathaniel-Hawthorne.pdf