Malicious PDF — malware analysis report

Static analysis result for SHA-256 3355aa63f280c3bf…

MALICIOUS

PDF

15.9 KB Created: 2019-06-04 09:53:26 +01:00 Authoring application: mPDF 5.7
MD5: 4c916a0ecf7cdcb3aa64e1559dd0a565 SHA-1: e10c9d539303537abab7afce01ca29875218a383 SHA-256: 3355aa63f280c3bf799647964d00d26b7bf94dd519e0426bc84a06005bb2de59
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs pointing to external PDF documents. This technique is often used for SEO spam or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' confirms the presence of a link farm. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent to redirect users to potentially harmful content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2734739739731736/The-Stolen-Mackenzie-Bride-MacKenzies-amp-McBrides-8-by-Jennifer-Ashley.pdf
    • http://cefasfese.4pu.com/2738731736731739/Scandal-And-The-Duchess-MacKenzies-amp-McBrides-6-5-by-Jennifer-Ashley.pdf
    • http://cefasfese.4pu.com/1733730731734734/Rules-for-a-Proper-Governess-MacKenzies-amp-McBrides-7-by-Jennifer-Ashley.pdf
    • http://cefasfese.4pu.com/4733733730732/The-Duke-s-Perfect-Wife-MacKenzies-amp-McBrides-4-by-Jennifer-Ashley.pdf
    • http://cefasfese.4pu.com/3735736738738733/Lady-Isabella-s-Scandalous-Marriage-Mackenzies-amp-McBrides-2-by-Jennifer-Ashley.pdf
    • http://cefasfese.4pu.com/5738737737739733/Stolen-Fruits-A-Bride-For-The-Viking-Part-One-by-Ashley-Spector.pdf
    • http://cefasfese.4pu.com/1734732732738733/The-Madness-of-Lord-Ian-Mackenzie-Highland-Pleasures-1-by-Jennifer-Ashley.pdf
    • http://cefasfese.4pu.com/2732732734734734/The-Madness-of-Lord-Ian-Mackenzie-Highland-Pleasures-1-by-Jennifer-Ashley.pdf
    • http://cefasfese.4pu.com/7738733732732738/Sleuthing-for-a-Living-Mackenzie-amp-Mackenzie-P-I-1-by-Jennifer-L-Hart.pdf
    • http://cefasfese.4pu.com/2730732736738732/Dylan-s-Redemption-The-McBrides-3-by-Jennifer-Ryan.pdf
    • http://cefasfese.4pu.com/1734738734736732/Falling-for-Owen-The-McBrides-2-by-Jennifer-Ryan.pdf
    • http://cefasfese.4pu.com/1737732733730731/The-Return-of-Brody-McBride-The-McBrides-1-by-Jennifer-Ryan.pdf
    • http://cefasfese.4pu.com/4730738739736/Mackenzie-s-Legacy-Mackenzie-s-Mountain-amp-Mackenzie-s-Mission-Mackenzie-Family-1-2-by-Linda-Howard.pdf
    • http://cefasfese.4pu.com/9733739734737739/From-Jennifer-Ashley-With-Love-by-Jennifer-Ashley.pdf
    • http://cefasfese.4pu.com/1732735731739/His-Stolen-Bride-by-Judith-Stanton.pdf
    • http://cefasfese.4pu.com/2737739737732734/Bride-of-the-Beast-MacKenzie-2-by-Sue-Ellen-Welfonder.pdf
    • http://cefasfese.4pu.com/9735736735732739/Niko-s-Stolen-Bride-by-Lindy-Corbin.pdf
    • http://cefasfese.4pu.com/1731733735734/His-Stolen-Bride-Chicago-Sons-4-by-Barbara-Dunlop.pdf
    • http://cefasfese.4pu.com/2737739735738733/The-Highlander-s-Conquest-Stolen-Bride-2-by-Eliza-Knight.pdf
    • http://cefasfese.4pu.com/2737739737732736/The-Highlander-s-Lady-Stolen-Bride-3-by-Eliza-Knight.pdf
    • http://cefasfese.4pu.com/2730732736738732/Dylan-s-Redemption-The-McBride