Malicious PDF — malware analysis report

Static analysis result for SHA-256 20ebbc56e89d67a7…

MALICIOUS

PDF

18.0 KB Created: 2019-11-21 12:47:25 +00:00 Authoring application: mPDF 5.7
MD5: 5a551a7533c865480ed0d21f6cc85759 SHA-1: b223430a52155490c8feccee41861783efac3d83 SHA-256: 20ebbc56e89d67a7b4fc0093fd4ade5a839ef07a908a95b5ee3478dacdc15151
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDFs, primarily hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a lure to download further content. While the specific intent beyond linking is unclear due to the lack of executable scripts, the sheer volume of links suggests a malicious attempt to direct users to potentially harmful content.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2737731730732738/Sadie-s-War-A-Supernatural-Uprising-Novel-Book-1-by-Jayelle-Cochran.pdf
    • http://cefasfese.4pu.com/6732739730739733/Jovian-Uprising---2315-Jovian-Uprising-1-by-Michel-Poulin.pdf
    • http://cefasfese.4pu.com/8738738739733/The-Ultimate-Treasure-Hunt-A-Guide-to-Supernatural-Evangelism-Through-Supernatural-Encounters-by-Kevin-Dedmon.pdf
    • http://cefasfese.4pu.com/1731733733730730738/Hell-Bent-for-Leather-Six-Gun-Supernatural-Book-1-by-Joshua-Unruh.pdf
    • http://cefasfese.4pu.com/1734736738733738/His-Mistaken-Muse-The-Muse-Book-1-by-Sadie-Starr.pdf
    • http://cefasfese.4pu.com/2731731739736733/Fool-s-Joruney-The-War-of-the-Tarot-Book-One-Episode-One-A-Supernatural-Urban-Fantasy-War-of-the-Tarot-1-of-6-by-Brandon-Tackett.pdf
    • http://cefasfese.4pu.com/4734735732737732/Mireille-by-Molly-Cochran.pdf
    • http://cefasfese.4pu.com/2734733734735739/Betrayed-by-Rosie-Cochran.pdf
    • http://cefasfese.4pu.com/7739733734738738/Spellbinders-Collection-by-Molly-Cochran.pdf
    • http://cefasfese.4pu.com/1731733736739733739/The-Lius-of-Shanghai-by-Sherman-Cochran.pdf
    • http://cefasfese.4pu.com/1730733736736739732/In-Love-with-Eleanor-Rigby-by-Stacey-Cochran.pdf
    • http://cefasfese.4pu.com/8731736732733/I-Have-Tampered-with-the-Divine-Plan-by-Tony-Cochran.pdf
    • http://cefasfese.4pu.com/3731732739737738/The-Third-Magic-Forever-King-3-by-Molly-Cochran.pdf
    • http://cefasfese.4pu.com/1733731736737731/The-Most-Important-Memoir-Ever-Written-Ever-by-Joshua-Daniel-Cochran.pdf
    • http://cefasfese.4pu.com/5736737732734736/Presidential-Affair-Love-Lies-and-Liaisons-3-by-Les-Cochran.pdf
    • http://cefasfese.4pu.com/5736737732734732/Costly-Affair-Love-Lies-and-Liaisons-1-by-Les-Cochran.pdf
    • http://cefasfese.4pu.com/1736738730730733/Divine-Healing-Made-Simple-Simplifying-the-supernatural-to-make-healing-amp-miracles-a-part-of-your-everyday-life-The-Kingdom-of-God-Made-Simple-Book-1-by-Praying-Medic.pdf
    • http://cefasfese.4pu.com/4739737732734736/Singing-in-Zion-Music-and-Song-in-the-Life-of-One-Arkansas-Family-by-Robert-Cochran.pdf
    • http://cefasfese.4pu.com/1732735738737732/The-Collapse-The-Uprising-2-by-R-A-Desilets.pdf
    • http://cefasfese.4pu.com/1731739737737739736/Uprising-Starcraft-0-5-by-Micky-Neilson.pdf
    • http://cefasfese.4pu.com/2734733734735739/Betrayed-