Malicious PDF — malware analysis report

Static analysis result for SHA-256 2e0d5bd1b3c21d35…

MALICIOUS

PDF

15.7 KB Created: 2019-05-04 10:52:29 +01:00 Authoring application: mPDF 5.7
MD5: 8a80569529ded0b876aa3332edbb81f6 SHA-1: 081324858f7fdf27ced7375941e3c37b7ddf8e6c SHA-256: 2e0d5bd1b3c21d35498fab10987f5ff82c71f9901804ead42ccde2aedb024eb6
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs pointing to a single domain, 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a mechanism to distribute malicious content indirectly. While the URLs themselves were labeled as benign, the sheer volume and the nature of the heuristic firing suggest a malicious intent to redirect users to potentially harmful content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730736738737734/Mr-Right-There-All-Along-by-Jackie-Braun.pdf
    • http://cefasfese.4pu.com/4738739733739739/Boardroom-Baby-Surprise-by-Jackie-Braun.pdf
    • http://cefasfese.4pu.com/1731735732739731738/Julia-Extra-Band-322---Titel-4-Verzaubert-vom-Fest-der-Liebe-by-Jackie-Braun.pdf
    • http://cefasfese.4pu.com/5736739737738739/Idylle-inattendue---Un-secret-bouleversant---La-fianc-e-surprise-Harlequin-by-Jackie-Braun.pdf
    • http://cefasfese.4pu.com/2732737734738732/The-Jackie-Collins-Gift-Set-Lucky-The-Bitch-The-World-is-Full-of-Married-Men-Hollywood-Wives-by-Jackie-Collins.pdf
    • http://cefasfese.4pu.com/6735730733735/I-Am-Jackie-Chan-My-Life-in-Action-by-Jackie-Chan.pdf
    • http://cefasfese.4pu.com/5734733733736736/L-i-h-a-v-m-t-c-y-b-t-ch-by-Adam-Braun.pdf
    • http://cefasfese.4pu.com/5738739732736731/Can-You-Say-It-Too-Moo-Moo-by-Sebastien-Braun.pdf
    • http://cefasfese.4pu.com/3734731733733734/Somewhere-Else-A-Novel-by-Jan-Guenther-Braun.pdf
    • http://cefasfese.4pu.com/1731736736739733/Stranded-by-Melinda-Braun.pdf
    • http://cefasfese.4pu.com/9731733737739733/Doris-Day-by-Eric-Braun.pdf
    • http://cefasfese.4pu.com/5738739732730733/On-Our-Way-Home-by-Sebastien-Braun.pdf
    • http://cefasfese.4pu.com/2739735738730/The-Kincaids-by-Matt-Braun.pdf
    • http://cefasfese.4pu.com/5738739732735732/Digger-and-Tom-by-Sebastien-Braun.pdf
    • http://cefasfese.4pu.com/6733732732734733/Me-My-Kid-amp-HollyWeird-by-Chartreuse-Braun.pdf
    • http://cefasfese.4pu.com/3731738731731734/The-Cat-Who-Went-into-the-Closet-Cat-Who-15-by-Lilian-Jackson-Braun.pdf
    • http://cefasfese.4pu.com/8733735735730735/Adolphe-Braun-by-Denise-Ankele.pdf
    • http://cefasfese.4pu.com/5732734735731738/Meeow-and-the-Little-Chairs-by-Sebastien-Braun.pdf
    • http://cefasfese.4pu.com/3738737730731733/Solving-the-Voynich-Manuscript-by-L-A-Braun.pdf
    • http://cefasfese.4pu.com/9738734738733731/The-Cat-Who-Had-14-Tales-by-Lilian-Jackson-Braun.pdf
    • http://cefasfese.4pu.com/1731736736739733/Stran