Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b5c966dc9fdc854…

MALICIOUS

PDF

17.1 KB Created: 2019-11-07 20:46:39 +00:00 Authoring application: mPDF 5.7
MD5: 70b80ed24751ce854214940e86ff243d SHA-1: 7bea7f61fa30d4f215fdc49f4311b2fdead84db4 SHA-256: 4b5c966dc9fdc854dc12e971696d37b7a2b38699b6ab029473c89f49cf750771
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links point to what appears to be benign book download sites, the sheer volume and the nature of the heuristic suggest a potential for SEO manipulation or a lure to a malicious domain disguised as a legitimate one. No scripts were extracted from this sample, and the document body was unreadable, limiting further analysis of the specific intent beyond link distribution.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3733737739730737/Salvation-The-Protectors-2-by-Sloane-Kennedy.pdf
    • http://cefasfese.4pu.com/3733736737732730/Revelation-The-Protectors-7-by-Sloane-Kennedy.pdf
    • http://cefasfese.4pu.com/7731732736/Shattered-The-Protectors-11-by-Sloane-Kennedy.pdf
    • http://cefasfese.4pu.com/7739734736734736/Vengeance-The-Protectors-5-by-Sloane-Kennedy.pdf
    • http://cefasfese.4pu.com/3735735734732732/Retribution-The-Protectors-3-by-Sloane-Kennedy.pdf
    • http://cefasfese.4pu.com/3733736737730738/Unexpected-The-Protectors-10-by-Sloane-Kennedy.pdf
    • http://cefasfese.4pu.com/3731734736/Absolution-The-Protectors-1-by-Sloane-Kennedy.pdf
    • http://cefasfese.4pu.com/9733731739736734/Discovering-Daisy-A-Protectors-Novella-by-Sloane-Kennedy.pdf
    • http://cefasfese.4pu.com/3736736733730734/Loving-Vin-Barretti-Security-1-by-Sloane-Kennedy.pdf
    • http://cefasfese.4pu.com/4733734733732734/Shane-s-Fall-The-Escort-2-by-Sloane-Kennedy.pdf
    • http://cefasfese.4pu.com/3733736737731733/Finding-Hope-Finding-Series-5-by-Sloane-Kennedy.pdf
    • http://cefasfese.4pu.com/3734730734738732/Finding-Trust-Finding-2-by-Sloane-Kennedy.pdf
    • http://cefasfese.4pu.com/5730733733739731/Finding-Forgiveness-Finding-4-by-Sloane-Kennedy.pdf
    • http://cefasfese.4pu.com/4738738730739739/The-Official-Sloane-Ranger-Diary-The-First-Guide-to-the-Sloane-Year-by-Ann-Barr.pdf
    • http://cefasfese.4pu.com/3730738737731738/My-Salvation-Salvation-1-by-Michelle-Dare.pdf
    • http://cefasfese.4pu.com/4732735731735739/The-Other-Mrs-Kennedy-An-intimate-and-revealing-look-at-the-hidden-life-of-Ethel-Skakel-Kennedy-by-Jerry-Oppenheimer.pdf
    • http://cefasfese.4pu.com/3738733735738738/Kick-Kennedy-The-Charmed-Life-and-Tragic-Death-of-the-Favorite-Kennedy-Daughter-by-Barbara-Leaming.pdf
    • http://cefasfese.4pu.com/4731737734732/The-Best-Loved-Poems-of-Jacqueline-Kennedy-Onassis-by-Caroline-Kennedy.pdf
    • http://cefasfese.4pu.com/1730732739733731739/The-Kennedy-Wit-The-Humor-and-Wisdom-of-John-F-Kennedy-by-John-F-Kennedy.pdf
    • http://cefasfese.4pu.com/7736735738730739/Simple-Decor-Extravagant-Living-The-Watson-Kennedy-A-to-Z-Guide-to-a-More-Beautiful-Life-by-Ted-Kennedy-Watson.pdf