Malicious PDF — malware analysis report

Static analysis result for SHA-256 36a2bd2bb7674fc8…

MALICIOUS

PDF

19.2 KB Created: 2019-11-07 21:32:32 +00:00 Authoring application: mPDF 5.7
MD5: 654e9e33b703986e754dd30e1e15ec50 SHA-1: 46ac7e14aefb62233dc05765c7b1cc9a75893baa SHA-256: 36a2bd2bb7674fc8e866dd456fa310a08579e373358c585e6753bcd347b1d966
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO poisoning or to act as a landing page for further attacks. The document body is heavily corrupted, preventing a detailed analysis of its content, but the presence of numerous links points to a delivery mechanism rather than a legitimate document.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8736730739733/Native-Tongue-Native-Tongue-1-by-Suzette-Haden-Elgin.pdf
    • http://cefasfese.4pu.com/2739734736734737/Flush-by-Carl-Hiaasen.pdf
    • http://cefasfese.4pu.com/7734737739737/Skinny-Dip-by-Carl-Hiaasen.pdf
    • http://cefasfese.4pu.com/1733730738734/Flush-by-Carl-Hiaasen.pdf
    • http://cefasfese.4pu.com/3730735732734733/Chomp-by-Carl-Hiaasen.pdf
    • http://cefasfese.4pu.com/1733739733732739/Lucky-You-by-Carl-Hiaasen.pdf
    • http://cefasfese.4pu.com/1731738733738731736/Bad-Monkey-by-Carl-Hiaasen.pdf
    • http://cefasfese.4pu.com/2738732733735/Scat-by-Carl-Hiaasen.pdf
    • http://cefasfese.4pu.com/1733732731735/Chomp-by-Carl-Hiaasen.pdf
    • http://cefasfese.4pu.com/1734730736733732/Basket-Case-by-Carl-Hiaasen.pdf
    • http://cefasfese.4pu.com/1730735736737736/Strip-Tease-by-Carl-Hiaasen.pdf
    • http://cefasfese.4pu.com/2730738732730736/Native-Tongue-The-Specialists-4-by-Shannon-Greenland.pdf
    • http://cefasfese.4pu.com/8731738739731737/Our-Marvelous-Native-Tongue-by-Robert-Claiborne.pdf
    • http://cefasfese.4pu.com/2735738731733737/Skinny-Dip-Mick-Stranahan-2-by-Carl-Hiaasen.pdf
    • http://cefasfese.4pu.com/1730735739734739/Earthsong-Native-Tongue-3-by-Suzette-Haden-Elgin.pdf
    • http://cefasfese.4pu.com/3736738735737738/The-Downhill-Lie-A-Hacker-s-Return-to-a-Ruinous-Sport-by-Carl-Hiaasen.pdf
    • http://cefasfese.4pu.com/8737737731737732/New-Light-on-Dark-Africa-Being-the-Narrative-of-the-German-Emin-Pasha-Expedition-Its-Journeyings-and-Adventures-Among-the-Native-Tribes-of-Eastern-Equatorial-Africa-the-Gallas-Massais-Wasukuma-Etc-on-the-Lake-Baringo-and-the-Victoria-Nyanza-by-Carl-Peters.pdf
    • http://cefasfese.4pu.com/1730732733730730731/Go-Native-Gardening-with-Native-Plants-and-Wildflowers-in-the-Lower-Midwest-by-Carolyn-Harstad.pdf
    • http://cefasfese.4pu.com/3738736739737730/Native-Authenticity-Transnational-Perspectives-On-Native-American-Literary-Studies-by-Deborah-L-Madsen.pdf
    • http://cefasfese.4pu.com/3734731738734730/Pollinators-of-Native-Plants-Attract-Observe-and-Identify-Pollinators-and-Beneficial-Insects-with-Native-Plants-by-Heather-N-Holm.pdf
    • http://cefasfese.4pu.com/1730735739734739/Earthsong-Native-Tongue-3-by-S