Malicious PDF — malware analysis report

Static analysis result for SHA-256 500896352a993f98…

MALICIOUS

PDF

19.9 KB Created: 2019-06-04 14:55:27 +01:00 Authoring application: mPDF 5.7
MD5: 6055554a0b2fc1950653f60530821ffe SHA-1: 43276c22fb1e7f86495b54ca1cc995c58befe5ac SHA-256: 500896352a993f982296b8fed42dd1777f527ecfaa42f320bb46c2a292943e47
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various book titles hosted on the same domain, suggesting a potential SEO spam or content farm operation. While the URLs themselves are marked as benign, the sheer volume and nature of the links indicate a malicious intent to manipulate search engine results or distribute potentially harmful content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2730739735734737/Cutters-vs-Jocks-Chicago-Sports-Romance-1-by-Elizabeth-Marx.pdf
    • http://cefasfese.4pu.com/1739738732730734/Binding-Arbitration-Chicago-1-by-Elizabeth-Marx.pdf
    • http://cefasfese.4pu.com/2731739738731736/Just-in-Case-Alabama-Secrets-1-by-Elizabeth-Marx.pdf
    • http://cefasfese.4pu.com/1738737739734732/Ascent-Of-Blood-The-Red-Veil-Series-Book-2-by-Elizabeth-Marx.pdf
    • http://cefasfese.4pu.com/1732730731730732/All-s-Fair-in-Vanity-s-War-Deadly-Fairy-Tales-2-by-Elizabeth-Marx.pdf
    • http://cefasfese.4pu.com/1732730733736734/It-Had-to-Be-You-Chicago-Stars-1-by-Susan-Elizabeth-Phillips.pdf
    • http://cefasfese.4pu.com/4731733732730/Match-Me-If-You-Can-Chicago-Stars-6-by-Susan-Elizabeth-Phillips.pdf
    • http://cefasfese.4pu.com/3737730732738/This-Heart-of-Mine-Chicago-Stars-5-by-Susan-Elizabeth-Phillips.pdf
    • http://cefasfese.4pu.com/1732737735737/Heaven-Texas-Chicago-Stars-2-by-Susan-Elizabeth-Phillips.pdf
    • http://cefasfese.4pu.com/5735739733736737/Healthful-Sports-for-Boys-The-American-Boy-s-Ultimate-Guide-to-Building-Confidence-Strength-and-Good-Moral-Character-Through-Sports-Games-CAM-by-Alfred-Rochefort.pdf
    • http://cefasfese.4pu.com/5730738734730734/Marx-s-Lost-Aesthetic-Karl-Marx-and-the-Visual-Arts-by-Margaret-A-Rose.pdf
    • http://cefasfese.4pu.com/1731736737731737735/Chicago-by-Gaslight-A-History-of-Chicago-s-Netherworld-1880-1920-by-Richard-Lindberg.pdf
    • http://cefasfese.4pu.com/6732730736738736/The-Gangs-of-Chicago-An-Informal-History-of-the-Chicago-Underworld-by-Herbert-Asbury.pdf
    • http://cefasfese.4pu.com/2732732734735739/Dream-a-Little-Dream-Chicago-Stars-4-by-Susan-Elizabeth-Phillips.pdf
    • http://cefasfese.4pu.com/6736733738734739/La-Guerre-Civile-en-France-Avec-introduction-d-Engels-et-lettres-de-Marx-et-d-Engels-sur-la-Commune-de-Paris-by-Karl-Marx.pdf
    • http://cefasfese.4pu.com/1731738739735736735/Jenseits-der-Illusionen-Die-Bedeutung-von-Marx-und-Freud-Beyond-the-Chains-of-Illusion-My-Encounter-with-Marx-and-Freud-by-Erich-Fromm.pdf
    • http://cefasfese.4pu.com/4739734732730735/The-Pirate-the-Three-Cutters-by-Frederick-Marryat.pdf
    • http://cefasfese.4pu.com/9735734736735734/Chicago-Volume-2-Chicago-2-by-Yumi-Tamura.pdf
    • http://cefasfese.4pu.com/1730731733736739738/Sports-Illustrated-Brett-Favre-The-Tribute-by-Sports-Illustrated.pdf
    • http://cefasfese.4pu.com/4733732731730730/No-Jocks-Don-t-Date-Guys-Jock-2-by-Wade-Kelly.pdf
    • http://cefasfese.4pu.com/5735739733736737/Healthful-Sport