Malicious PDF — malware analysis report

Static analysis result for SHA-256 475b43e7f2f60e39…

MALICIOUS

PDF

18.7 KB Created: 2019-09-12 20:28:43 +01:00 Authoring application: mPDF 5.7
MD5: 4172e1bbbc997f35642bdf4edbf3fc2f SHA-1: e5ee5280ea12f186023c538b71d5eab9a1b5b9a6 SHA-256: 475b43e7f2f60e39568d2c15861da2b616bc6b17c5211c9cd17d93d082dce84e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links predominantly point to book titles hosted on the 'cefasfese.4pu.com' domain, suggesting a potential SEO spam campaign or a redirection scheme. While the URLs themselves are currently marked as benign, the sheer volume and structure of the links indicate a malicious intent to manipulate search engine results or to redirect users to potentially harmful content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4739733737731730/Die-For-Me-Romantic-Suspense-7-Daniel-Vartanian-1-by-Karen-Rose.pdf
    • http://cefasfese.4pu.com/2734736734739738/Don-t-Tell-Romantic-Suspense-1-Chicago-1-by-Karen-Rose.pdf
    • http://cefasfese.4pu.com/8738731731731/Count-to-Ten-Romantic-Suspense-6-Chicago-5-by-Karen-Rose.pdf
    • http://cefasfese.4pu.com/3734731732733733/You-Belong-to-Me-Romantic-Suspense-12-Baltimore-1-by-Karen-Rose.pdf
    • http://cefasfese.4pu.com/8732739739739735/A-Morte-Chama-te-Romantic-Suspense-5-by-Karen-Rose.pdf
    • http://cefasfese.4pu.com/3735737736732731/Closer-Than-You-Think-Romantic-Suspense-16-Cincinnati-1-by-Karen-Rose.pdf
    • http://cefasfese.4pu.com/2732732732739735/Nothing-To-Fear-Romantic-Suspense-4-Chicago-3-by-Karen-Rose.pdf
    • http://cefasfese.4pu.com/7730731731737/You-Belong-to-Me-Romantic-Suspense-12-Baltimore-1-by-Karen-Rose.pdf
    • http://cefasfese.4pu.com/8738735737739734/Edge-of-Darkness-Romantic-Suspense-20-Cincinnati-4-by-Karen-Rose.pdf
    • http://cefasfese.4pu.com/2731731736739730/Whiskey-Tango-A-Romantic-Suspense-by-Shay-Lawless.pdf
    • http://cefasfese.4pu.com/1737738736730737/Against-The-Wind-Florida-Sands-Romantic-Suspense-1-by-Virginia-Kelly.pdf
    • http://cefasfese.4pu.com/2738733733738738/Nefarious-Rock-Candy-Romantic-Suspense-1-by-Tina-D-C-Hayes.pdf
    • http://cefasfese.4pu.com/1734735739737737/One-Cool-Lawman-Silhouette-Romantic-Suspense-1466-by-Diane-Pershing.pdf
    • http://cefasfese.4pu.com/5739730736733739/Criminal-Deception-Silhouette-Romantic-Suspense-1591-by-Marilyn-Pappano.pdf
    • http://cefasfese.4pu.com/4734730738731736/Can-t-Take-My-Eyes-Off-You-A-Small-Town-Romantic-Suspense-Wishing-For-A-Hero-3-by-Kait-Nolan.pdf
    • http://cefasfese.4pu.com/1731731736735739739/Midsummer-Bride---a-full-length-romantic-suspense-adventure-by-Nina-Bruhns.pdf
    • http://cefasfese.4pu.com/6738734734737734/Slow-and-Steady-2-A-Small-Town-Romantic-Suspense-Shameless-Southern-Nights-Book-5-by-J-H-Croix.pdf
    • http://cefasfese.4pu.com/8736738738737/American-Rose-A-Nation-Laid-Bare-The-Life-and-Times-of-Gypsy-Rose-Lee-by-Karen-Abbott.pdf
    • http://cefasfese.4pu.com/4731736730732738/Harlequin-Romantic-Suspense-June-2018-Box-Set-The-Colton-Cowboy-The-Bounty-Hunter-s-Baby-Surprise-Hometown-Detective-Seduced-by-the-Badge-by-Carla-Cassidy.pdf
    • http://cefasfese.4pu.com/5735732730730737/Nathan-s-Vow-by-Karen-Rose-Smith.pdf