Malicious PDF — malware analysis report

Static analysis result for SHA-256 46d6c5fb79bbcc07…

MALICIOUS

PDF

20.9 KB Created: 2019-05-02 05:43:38 +01:00 Authoring application: mPDF 5.7
MD5: 47942663e303d23e5ac74741dc3061c5 SHA-1: 743f5c9b4b18a44244a430540456d97a405dd272 SHA-256: 46d6c5fb79bbcc0726b5bf542ef4870398252af2f47a2d0e6faabf6dc9c3ac7a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. The document body, though partially corrupted, also contains these URLs. The primary function appears to be directing users to a vast collection of external websites, likely for SEO manipulation or to host malicious content disguised as legitimate documents. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4739735736730733/Sailor-The-Hangashore-Newfoundland-Dog-by-Catherine-Simpson.pdf
    • http://cefasfese.4pu.com/5733739733738730/The-Honest-Sailor-or-virtuous-misfortune-not-an-Object-for-Childish-Ridicule-by-The-Newfoundland-Dog.pdf
    • http://cefasfese.4pu.com/1730733735731739735/Literature-And-Folk-Culture-Ireland-And-Newfoundland-Papers-From-The-Ninth-Annual-Seminar-Of-The-Canadian-Association-For-Irish-Studies-At-Memorial-University-Of-Newfoundland-February-11-15-1976-by-Bernice-Schrank.pdf
    • http://cefasfese.4pu.com/4737738739736735/Sailor-Scouts-Unite-Sailor-Moon-Junior-Chapter-Books-1-by-Tracey-West.pdf
    • http://cefasfese.4pu.com/2730730730730732/The-Return-of-Sailor-Moon-Sailor-Moon-Junior-Chapter-Books-1-by-Tracey-West.pdf
    • http://cefasfese.4pu.com/1731732735736737/Codename-Sailor-V-Vol-1-Codename-Sailor-V-Renewal-Edition-1-by-Naoko-Takeuchi.pdf
    • http://cefasfese.4pu.com/4737738734737734/Sailor-Moon-Vol-01-Pretty-Soldier-Sailor-Moon-1-by-Naoko-Takeuchi.pdf
    • http://cefasfese.4pu.com/4734737734739/Pretty-Guardian-Sailor-Moon-Vol-1-Pretty-Soldier-Sailor-Moon-Renewal-Edition-1-by-Naoko-Takeuchi.pdf
    • http://cefasfese.4pu.com/2737739732731733/Pretty-Guardian-Sailor-Moon-Vol-9-Pretty-Soldier-Sailor-Moon-Renewal-Edition-9-by-Naoko-Takeuchi.pdf
    • http://cefasfese.4pu.com/1730738738733735730/Sailor-Moon-5-Sailor-Moon-5-by-Naoko-Takeuchi.pdf
    • http://cefasfese.4pu.com/8732739738730/Sailor-Moon-Vol-1-Sailor-Moon-1-by-Naoko-Takeuchi.pdf
    • http://cefasfese.4pu.com/1739733731739738/Sailor-Moon-SuperS-1-Sailor-Moon-SuperS-1-by-Naoko-Takeuchi.pdf
    • http://cefasfese.4pu.com/1730730733737735/Bibliography-of-Newfoundland-by-Agnes-C-O-39-Dea.pdf
    • http://cefasfese.4pu.com/1730730734736731/A-History-Of-Newfoundland-And-Labrador-by-Frederick-W-Rowe.pdf
    • http://cefasfese.4pu.com/2735736738739735/The-Day-the-World-Came-to-Town-9-11-in-Gander-Newfoundland-by-Jim-DeFede.pdf
    • http://cefasfese.4pu.com/5730737737739733/Newfoundland-and-Labrador-A-History-by-Sean-T-Cadigan.pdf
    • http://cefasfese.4pu.com/8738730738739734/Come-and-I-Will-Sing-You-A-Newfoundland-Songbook-by-Genevieve-Lehr.pdf
    • http://cefasfese.4pu.com/1734734735733730/As-Near-To-Heaven-By-Sea-A-History-Of-Newfoundland-And-Labrador-by-Kevin-Major.pdf
    • http://cefasfese.4pu.com/6735737735736/Rogues-amp-Heroes-of-the-Island-of-Newfoundland-by-Paul-Butler.pdf
    • http://cefasfese.4pu.com/4730732730734739/As-Near-To-Heaven-By-Sea-A-History-Of-Newfoundland-And-Labrador-by-Kevin-Major.pdf
    • http://cefasfese.4pu.com/4737738734737734/Sailor-Moon-Vol-01-Pretty-Soldier-Sailor-Moon-1-by-Naok