Malicious PDF — malware analysis report

Static analysis result for SHA-256 4625b43f17a77ca9…

MALICIOUS

PDF

16.7 KB Created: 2019-05-03 20:21:42 +01:00 Authoring application: mPDF 5.7
MD5: 684f6ea2b38ff070b17f04d80de3f6f5 SHA-1: 601349bf9d6c6ca7ccf3fd7cfe85d4291fd8200f SHA-256: 4625b43f17a77ca91a0d5258874188bdef6399d77f51b1ed60d31880ec2302f6
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, primarily hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a mechanism to distribute malicious content indirectly. While no scripts were extracted, the heuristic 'PDF_SEO_LINK_FARM' strongly suggests malicious intent through the sheer volume of links. The document body itself is heavily obfuscated and contains repeated URLs, reinforcing the link farm observation.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu
    • http://cefasfese.4pu.com/4738737732733735/Ashes-to-New-Angel-Fire-Rock-Romance-0-5-by-Ellie-Masters.pdf
    • http://cefasfese.4pu.com/2731732730738732/Masters-at-Arms-amp-Nobody-s-Angel-Rescue-Me-Saga-0-5-1-by-Kallypso-Masters.pdf
    • http://cefasfese.4pu.com/1734734739735739/Masters-at-Arms-amp-Nobody-s-Angel-Rescue-Me-Saga-0-5-1-by-Kallypso-Masters.pdf
    • http://cefasfese.4pu.com/4731735733737730/My-Rock-5-The-Rock-Star-Romance-5-by-Alycia-Taylor.pdf
    • http://cefasfese.4pu.com/4737734737732732/Exposed-New-Adult-Rock-Star-Romance-Not-Exactly-A-Stepbrother-Romance-Book-2-by-Kristen-Strassel.pdf
    • http://cefasfese.4pu.com/7738732737738733/ROMANCE-MILITARY-ROMANCE-Menage-Heroes-Navy-Seal-Alpha-Male-Menage-Romance-by-Passon-Fire-Books.pdf
    • http://cefasfese.4pu.com/4738736739737737/Learning-to-Breathe-Part-One-The-Collective-Season-1-Episode-3-by-Ellie-Masters.pdf
    • http://cefasfese.4pu.com/1731730738731731/Rock-Paper-Tiger-Ellie-McEnroe-1-by-Lisa-Brackmann.pdf
    • http://cefasfese.4pu.com/2733731732737730/Angel-s-Tip-Ellie-Hatcher-2-by-Alafair-Burke.pdf
    • http://cefasfese.4pu.com/1737730736730736/Fallen-Angel-Part-2---A-Mafia-Romance-Fallen-Angel-2-by-Tracie-Podger.pdf
    • http://cefasfese.4pu.com/1732735734732739/Fallen-Angel-Part-3---A-Mafia-Romance-Fallen-Angel-3-by-Tracie-Podger.pdf
    • http://cefasfese.4pu.com/3738732734730735/After-the-Fire-Embers-and-Ashes-4-by-T-K-Chapin.pdf
    • http://cefasfese.4pu.com/1733735733734737/Somebody-s-Angel-Rescue-Me-Saga-4-by-Kallypso-Masters.pdf
    • http://cefasfese.4pu.com/1733735733738734/Nobody-s-Angel-Rescue-Me-Saga-1-by-Kallypso-Masters.pdf
    • http://cefasfese.4pu.com/3739736732733/Ice-Like-Fire-Snow-Like-Ashes-2-by-Sara-Raasch.pdf
    • http://cefasfese.4pu.com/1739735733739732/Ashes-in-the-Sky-Fire-in-the-Woods-2-by-Jennifer-M-Eaton.pdf
    • http://cefasfese.4pu.com/2735736733739731/From-the-Ashes-Fire-and-Rain-1-by-Daisy-Harris.pdf
    • http://cefasfese.4pu.com/1738730736733/Inca-Fire-Light-of-the-Masters-by-Val-Jon-Farris.pdf
    • http://cefasfese.4pu.com/4732733732739731/The-Seekers-of-Fire-The-Masters-That-Be-1-by-Lynna-Merrill.pdf
    • http://cefasfese.4pu.com/1731739733735739/First-Chance-Rock-Romance-1-by-A-L-Wood.pdf