Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c0451db880c9ba7…

MALICIOUS

PDF

18.7 KB Created: 2019-06-07 20:36:11 +01:00 Authoring application: mPDF 5.7
MD5: 463145f1214d73ff7853f9f89adb0b87 SHA-1: 432a3d0977f743e74857e9dc9b04aa958320edf1 SHA-256: 3c0451db880c9ba7f314ac6e4c46af9bec508bc76772c3da2a3a77cfbc20a5ae
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles, but the sheer volume and the dominant host suggest a link farm or SEO manipulation tactic. While the URLs themselves are currently marked as benign, the pattern indicates a potential for hosting malicious content or redirecting users to malicious sites. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4731737735731732/Plant-the-Tiny-Seed-by-Christie-Matheson.pdf
    • http://cefasfese.4pu.com/2737731730739739/Plant-Seed-Pull-Weed-by-Geri-Larkin.pdf
    • http://cefasfese.4pu.com/1730735731737735/Tiny-Sunbirds-Far-Away-by-Christie-Watson.pdf
    • http://cefasfese.4pu.com/1730734733735739736/2019---2020-Planner-2-Years-Monthly-Weekly-Calendar-Organizer-Diary-Decorated-Interior-with-Pentagram-Triquetra-Triskele-Witch-Craft---Plant-Seed-Mint-Green-by-New-Age-Wicca-Journal.pdf
    • http://cefasfese.4pu.com/7736732731731737/Clues-to-Christie-The-Definitive-Guide-to-Miss-Marple-Hercule-Poirot-Tommy-amp-Tuppence-and-All-of-Agatha-Christie-s-Mysteries-by-Agatha-Christie.pdf
    • http://cefasfese.4pu.com/4735735737730739/Circus-Queen-and-Tinker-Bell-The-Memoir-of-Tiny-Kline-by-Tiny-Kline.pdf
    • http://cefasfese.4pu.com/4735735736739735/Circus-Queen-and-Tinker-Bell-The-Memoir-of-Tiny-Kline-by-Tiny-Kline.pdf
    • http://cefasfese.4pu.com/2737730738733/The-Complete-Christie-An-Agatha-Christie-Encyclopedia-by-Matthew-Bunson.pdf
    • http://cefasfese.4pu.com/2731737732734738/Ten-Tiny-Breaths-Ten-Tiny-Breaths-1-by-K-A-Tucker.pdf
    • http://cefasfese.4pu.com/2739736735735736/Ten-Tiny-Breaths-Ten-Tiny-Breaths-1-by-K-A-Tucker.pdf
    • http://cefasfese.4pu.com/7731731737736738/De-verfilmde-bestsellers-van-Agatha-Christie-Moord-in-de-Ori-nt-Expres-De-moordenaar-waagt-een-gok-Drama-in-drie-bedrijven-by-Agatha-Christie.pdf
    • http://cefasfese.4pu.com/1730735736737733738/Murder-on-the-Orient-Express-The-Agatha-Christie-Collection-by-Agatha-Christie.pdf
    • http://cefasfese.4pu.com/1733738734730738/Third-from-the-Sun-by-Richard-Matheson.pdf
    • http://cefasfese.4pu.com/6738730731739732/The-Best-of-Richard-Matheson-by-Richard-Matheson.pdf
    • http://cefasfese.4pu.com/6738730733730735/By-the-Gun-by-Richard-Matheson.pdf
    • http://cefasfese.4pu.com/3733733730730/I-Am-Legend-by-Richard-Matheson.pdf
    • http://cefasfese.4pu.com/2734733731737733/Somewhere-In-Time-by-Richard-Matheson.pdf
    • http://cefasfese.4pu.com/2732737730736731/I-Am-Legend-by-Richard-Matheson.pdf
    • http://cefasfese.4pu.com/6738730733730736/Abu-and-the-7-Marvels-by-Richard-Matheson.pdf
    • http://cefasfese.4pu.com/6738730732739735/Bloodlines-by-Richard-Matheson.pdf
    • http://cefasfese.4pu.com/7736732731731737/Clues-to-Christie-The-Definitive-Guide-to-Miss-Marple-Hercule-Poir