Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b595fb25c9d63f2…

MALICIOUS

PDF

18.4 KB Created: 2019-11-10 00:36:00 +00:00 Authoring application: mPDF 5.7
MD5: 70ed5060a623c7d638d9633ab0c59f8d SHA-1: d9193463a30677538cba9322dce2938f8b55d1d9 SHA-256: 4b595fb25c9d63f2637e1ff0bd96a027a7a0df56cf03ddebac79ce9d98f05d41
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, identified as a link farm. These links predominantly point to book titles hosted on the domain 'cefasfese.4pu.com'. While the individual linked PDFs are marked as benign, the sheer volume and structure suggest a malicious intent to drive traffic or potentially mask other malicious activities. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5730736737735/Guiding-the-Blue-Flame-Guardian-Series-Book-One-by-J-W-Baccaro.pdf
    • http://cefasfese.4pu.com/9739731733734/Siege-of-Darkness-Guardian-of-the-Seventh-Realm-2-by-J-W-Baccaro.pdf
    • http://cefasfese.4pu.com/9738734736737/The-Sword-of-Righteousness-Guardian-of-the-Seventh-Realm-4-by-J-W-Baccaro.pdf
    • http://cefasfese.4pu.com/1736739739733731/Stolen-Flame-The-Seven-Chamber-Series-Book-1-by-D-W-Marshall.pdf
    • http://cefasfese.4pu.com/1731730738730731736/Lorelei-and-Darin-Dark-Guardian-Series-Book-4-by-T-Walker.pdf
    • http://cefasfese.4pu.com/4730730736733737/The-Code---Book-4-of-the-God-Book-Series-by-Celestial-Blue-Star.pdf
    • http://cefasfese.4pu.com/1735732733736734/Guardian-of-the-Flame-Seven-Wonders-4-by-T-L-Higley.pdf
    • http://cefasfese.4pu.com/5734734738731/Blue-Flame-by-K-M-Grant.pdf
    • http://cefasfese.4pu.com/2731737733731736/Blue-Flame-Firefighter-2-by-Jill-Shalvis.pdf
    • http://cefasfese.4pu.com/1732732731735/Blue-Flame-Firefighter-2-by-Jill-Shalvis.pdf
    • http://cefasfese.4pu.com/2734739733730737/Prophecy-of-the-Flame---Book-Two-Prophecy-of-the-Flame-2-by-Lynn-Hardy.pdf
    • http://cefasfese.4pu.com/8738738737739733/Lavender-s-Blue-Dilly-Dilly-Singing-With-Childern-Series-Song-Book-And-Cd-by-Mary-Thienes-Schunemann.pdf
    • http://cefasfese.4pu.com/2734732739734735/Ethereal-The-Guardian-Series-1-by-Michele-Faison.pdf
    • http://cefasfese.4pu.com/7736731738732738/The-Irises-of-Flame-Hayden-Cressida-Series-Volume-1-by-S-K-Robitaille.pdf
    • http://cefasfese.4pu.com/7735735733738733/James-Lee-Burke-Series-Reading-Order-amp-Checklist-Series-List-in-Order---Dave-Robicheaux-Series-Hackberry-Holland-Series-amp-All-Other-Books-Listabook-Series-Order-Book-29-by-Listabook.pdf
    • http://cefasfese.4pu.com/5731737737736/In-the-Shadow-of-Monsters-The-Guardian-Series-2-by-Fanny-Lee-Savage.pdf
    • http://cefasfese.4pu.com/2736739731733735/If-I-Stay-The-Guardian-Angel-Series-1-by-Melissa-Johnson.pdf
    • http://cefasfese.4pu.com/1738731737732737/Reluctant-Guardian-Ransomed-Soul-Series-1-by-Melissa-J-Cunningham.pdf
    • http://cefasfese.4pu.com/6735739735731736/Deep-Blue-The-Complete-Series-Deep-Blue-1-3-by-Amie-Nichols.pdf
    • http://cefasfese.4pu.com/4734732739735733/Vampiracy-Crimson-Savior-Hell-s-Guardian-Chronicles-Series-1-by-Isabella-Tredway.pdf
    • http://cefasfese.4pu.com/17327327317