Malicious PDF — malware analysis report

Static analysis result for SHA-256 3f58cde448192e98…

MALICIOUS

PDF

19.1 KB Created: 2019-11-07 17:07:24 +00:00 Authoring application: mPDF 5.7
MD5: 3cffcedb740b825d64300774e0ba260d SHA-1: efce1a2875f7a8f77f3eb1946a9288f306d71000 SHA-256: 3f58cde448192e98ed6bebd83147f7126483d9f1151e917ba4443615dd6368aa
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further payloads. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9733732736738736/An-integration-of-the-existential-understanding-of-anxiety-in-the-writings-of-Rollo-May-Irvin-Yalom-and-Kirk-Schneider-by-Alberto-De-Castro.pdf
    • http://cefasfese.4pu.com/1730734732734731/The-Yalom-Reader-Selections-From-The-Work-Of-A-Master-Therapist-And-Storyteller-by-Irvin-D-Yalom.pdf
    • http://cefasfese.4pu.com/9733732736738737/Existential-Psychology-by-Rollo-May.pdf
    • http://cefasfese.4pu.com/4739731736735735/Staring-at-the-Sun-by-Irvin-D-Yalom.pdf
    • http://cefasfese.4pu.com/9733732738734736/Carrasco-do-Amor-by-Irvin-D-Yalom.pdf
    • http://cefasfese.4pu.com/1730731731737739732/Therapie-als-geschenk-by-Irvin-D-Yalom.pdf
    • http://cefasfese.4pu.com/9733732738734734/Mentiras-no-Div-by-Irvin-D-Yalom.pdf
    • http://cefasfese.4pu.com/8737738737736735/Inpatient-Group-Psychotherapy-by-Irvin-D-Yalom.pdf
    • http://cefasfese.4pu.com/5738736737733/Creatures-of-a-Day-And-Other-Tales-of-Psychotherapy-by-Irvin-D-Yalom.pdf
    • http://cefasfese.4pu.com/3736732733731738/Every-Day-Gets-a-Little-Closer-A-Twice-Told-Therapy-by-Irvin-D-Yalom.pdf
    • http://cefasfese.4pu.com/6734739736737/Love-s-Executioner-amp-Other-Tales-of-Psychotherapy-by-Irvin-D-Yalom.pdf
    • http://cefasfese.4pu.com/1736739736737737/The-Theory-and-Practice-of-Group-Psychotherapy-by-Irvin-D-Yalom.pdf
    • http://cefasfese.4pu.com/5730730735733739/Love-s-Executioner-and-Other-Tales-of-Psychotherapy-by-Irvin-D-Yalom.pdf
    • http://cefasfese.4pu.com/3736732733732731/Love-s-Executioner-And-Other-Tales-Of-Psychotherapy-by-Irvin-D-Yalom.pdf
    • http://cefasfese.4pu.com/9733732738733738/Concise-Guide-to-Group-Psychotherapy-by-Irvin-D-Yalom.pdf
    • http://cefasfese.4pu.com/9733732736737736/Treating-Women-Molested-In-Childhood-by-Irvin-D-Yalom.pdf
    • http://cefasfese.4pu.com/5732734738736/Momma-and-the-Meaning-of-Life-Tales-of-Psychotherapy-by-Irvin-D-Yalom.pdf
    • http://cefasfese.4pu.com/8737738737730731/When-Nietzsche-Wept-by-Irvin-D-Yalom-Summary-amp-Study-Guide-by-BookRags.pdf
    • http://cefasfese.4pu.com/8739731735730735/Theorie-und-Praxis-der-Gruppenpsychotherapie-Ein-Lehrbuch---Leben-Lernen-Jubil-umsedition-by-Irvin-D-Yalom.pdf
    • http://cefasfese.4pu.com/9733732736738735/Writing-the-Talking-Cure-Irvin-D-Yalom-and-the-Literature-of-Psychotherapy-by-Jeffrey-Berman.pdf
    • http://cefasfese.4pu.com/5738736737733/Creatures-of-a-Day-And-Other-Tales-of-Psychotherapy-by-Irvin-D-Yalom