Malicious PDF — malware analysis report

Static analysis result for SHA-256 3b8cb7cb67427837…

MALICIOUS

PDF

17.2 KB Created: 2019-05-02 06:20:45 +01:00 Authoring application: mPDF 5.7
MD5: 75ad61ac09f4c8f057dba22565fdd864 SHA-1: d7a78f917d5d92870dc1cd008eefd2de4b15b7be SHA-256: 3b8cb7cb674278373fd8eab7e3d1fb6dbaf37518606bcada90ed229f9308bdec
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. While most of these URLs were flagged as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted, limiting the analysis of direct execution capabilities.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731731739737733730/the-way-none-of-this-happened-by-Mike-Breiner.pdf
    • http://cefasfese.4pu.com/1731731739737732732/Leben-und-Arbeiten-in-der-Schweiz-Trauminsel-in-Europa-by-Rolf-Breiner.pdf
    • http://cefasfese.4pu.com/1731731739737731738/Black-Yeats-Eric-Roach-and-the-Politics-of-Caribbean-Poetry-by-Laurence-A-Breiner.pdf
    • http://cefasfese.4pu.com/5732735737732733/Harry-Potter-and-the-Chamber-of-Secrets---Harry-Potter-dan-Kamar-Rahasia-Harry-Potter-2-by-J-K-Rowling.pdf
    • http://cefasfese.4pu.com/2733733731736735/Bike-Boy-by-Zack.pdf
    • http://cefasfese.4pu.com/5737737734739/Uncle-Harry-s-Stories-Looking-Back-Blackly-and-Proudly-Growing-Up-in-America-by-Harry-R-Irving.pdf
    • http://cefasfese.4pu.com/4736730735731731/Harry-s-Last-Stand-How-the-World-My-Generation-Built-is-Falling-Down-and-What-We-Can-Do-to-Save-It-by-Harry-Leslie-Smith.pdf
    • http://cefasfese.4pu.com/3731731732737733/One-Man-and-His-Bike-by-Mike-Carter.pdf
    • http://cefasfese.4pu.com/9732733738738/I-d-Rather-Be-Riding-My-Bike-by-Eric-Pinder.pdf
    • http://cefasfese.4pu.com/3731732737732730/The-Broomstick-Bike-by-Veronica-Bennett.pdf
    • http://cefasfese.4pu.com/2738734731734730/Stationary-Bike-by-Stephen-King.pdf
    • http://cefasfese.4pu.com/1737736730739/The-Kurdish-Bike-by-Alesa-Lightbourne.pdf
    • http://cefasfese.4pu.com/2735735735739733/The-Bike-Lesson-by-Stan-Berenstain.pdf
    • http://cefasfese.4pu.com/1736732735730739/Bump-Bike-amp-Baby-by-Moire-O-39-Sullivan.pdf
    • http://cefasfese.4pu.com/1732739731730734/Francesca-and-the-Magic-Bike-by-Cynthia-Nugent.pdf
    • http://cefasfese.4pu.com/5732731737733738/Getting-Out-of-Town-by-Book-amp-Bike-by-Kent-Thompson.pdf
    • http://cefasfese.4pu.com/2730736730733735/Like-Riding-a-Bike-Ken-amp-Michael-1-by-Eug-ne-Thicke.pdf
    • http://cefasfese.4pu.com/6737730736738730/By-Bike-around-Bando-and-Chichibu-by-Tony-Gibb.pdf
    • http://cefasfese.4pu.com/1730732738739737734/7-Secrets-to-Success-I-Learned-From-My-bike-by-Katie-Schmatz.pdf
    • http://cefasfese.4pu.com/9737734733735730/Basic-Illustrated-Bike-Touring-and-Bikepacking-by-Justin-Lichter.pdf
    • http://cefasfese.4pu.com/4736730735731731/Harry-s-Last-Stand-How-the-World-My-Generation-Built-is-Falling-Down-and-What-We-Can-Do-to-Save-It-by-Harry-Leslie-