Malicious PDF — malware analysis report

Static analysis result for SHA-256 50063019a202c311…

MALICIOUS

PDF

14.8 KB Created: 2019-04-30 17:49:18 +01:00 Authoring application: mPDF 5.7
MD5: 77b11369efceaa766e344a3ba4516e11 SHA-1: 6be10ab15c19762d32adeec5ce2192ee64780677 SHA-256: 50063019a202c311f4cf49db05a4e6f9c131c2ad2e7845f6847431d316c921d1
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links pointing to external PDF documents. The heuristic 'PDF_SEO_LINK_FARM' indicates this is a link farm, likely intended to manipulate search engine results or redirect users to malicious content. While the specific URLs are marked as benign, the sheer volume and the use of a suspicious domain ('cefasfese.4pu.com') suggest a malicious intent to drive traffic. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the exact lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8738730736739737/Weather-Air-Masses-Clouds-Rainfall-Storms-Weather-Maps-Climate-by-Paul-E-Lehr.pdf
    • http://cefasfese.4pu.com/9737733737738730/Weather-Proverbs-How-600-Proverbs-Sayings-and-Poems-Accurately-Explain-Our-Weather-by-George-D-Freier.pdf
    • http://cefasfese.4pu.com/1736732738736739/Talking-Down-the-Northern-Lights-by-Shelley-A-Leedahl.pdf
    • http://cefasfese.4pu.com/4734734736736737/No-Apologies-by-J-M-Snyder.pdf
    • http://cefasfese.4pu.com/2731731734735735/No-Apologies-by-Seressia-Glass.pdf
    • http://cefasfese.4pu.com/1739739731731732/No-Apologies-Hollywood-1-by-Tibby-Armstrong.pdf
    • http://cefasfese.4pu.com/3736735736730734/Spiritual-Secret-of-Hudson-Taylor-by-Howard-Taylor.pdf
    • http://cefasfese.4pu.com/1734730734737730/Weather-by-Michael-Allaby.pdf
    • http://cefasfese.4pu.com/1734736735733730/Getting-to-Know-the-Weather-by-Pamela-Painter.pdf
    • http://cefasfese.4pu.com/4734732731735737/Fair-Weather-by-Joe-Matt.pdf
    • http://cefasfese.4pu.com/5736730735736738/The-Weather-Stations-by-Ryan-Call.pdf
    • http://cefasfese.4pu.com/2738738737736738/The-Weather-in-the-Streets-by-Rosamond-Lehmann.pdf
    • http://cefasfese.4pu.com/5730736733735732/Strange-Weather-by-Becky-Hagenston.pdf
    • http://cefasfese.4pu.com/1731736732733732739/American-Weather-by-Charles-McLeod.pdf
    • http://cefasfese.4pu.com/3735731734730/Days-Without-Weather-by-Cecil-Brown.pdf
    • http://cefasfese.4pu.com/4732732735737733/Applesauce-Weather-by-Helen-Frost.pdf
    • http://cefasfese.4pu.com/9730735730736736/The-Collector-Of-Cold-Weather-by-Lawrence-Raab.pdf
    • http://cefasfese.4pu.com/3732731731733738/Red-Hot-Rain-Weather-Warden-10-by-Rachel-Caine.pdf
    • http://cefasfese.4pu.com/4734737730734731/The-Weather-of-the-Pacific-Northwest-by-Cliff-Mass.pdf
    • http://cefasfese.4pu.com/7735736737735739/Nice-Weather-Poems-by-Frederick-Seidel.pdf