Malicious PDF — malware analysis report

Static analysis result for SHA-256 58ee7726eec34aac…

MALICIOUS

PDF

15.3 KB Created: 2019-05-03 05:24:05 +01:00 Authoring application: mPDF 5.7
MD5: 3910c3183ede9570091b48e813c448e3 SHA-1: 8179a7f35df184806029ddfbdb1bac03def89102 SHA-256: 58ee7726eec34aac0c2e8ee2e146b932a165e85fab3283f40af8767aa0ada6eb
68 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily corrupted, the presence of numerous links suggests a malicious intent, possibly for SEO manipulation or to distribute malware. The SE_URGENCY_LURE heuristic indicates the document may have contained deceptive text, but this could not be fully verified due to data corruption. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2730734736731736/How-the-West-Was-Wed-Two-Time-Texas-3-by-Margaret-Brownley.pdf
    • http://cefasfese.4pu.com/8732739736739/A-Long-Way-Home-by-Margaret-Brownley.pdf
    • http://cefasfese.4pu.com/5733732735731730/Buttons-and-Beaus-by-Margaret-Brownley.pdf
    • http://cefasfese.4pu.com/4739739734735734/The-12-Brides-of-Christmas-Collection-by-Margaret-Brownley.pdf
    • http://cefasfese.4pu.com/2739731738739734/Gunpowder-Tea-The-Brides-of-Last-Chance-Ranch-3-by-Margaret-Brownley.pdf
    • http://cefasfese.4pu.com/2733734739733737/A-Vision-of-Lucy-A-Rocky-Creek-Romance-3-by-Margaret-Brownley.pdf
    • http://cefasfese.4pu.com/2737737737736736/A-Suitor-for-Jenny-A-Rocky-Creek-Romance-2-by-Margaret-Brownley.pdf
    • http://cefasfese.4pu.com/1730736739734734731/West-Texas-by-Joe-Kamm.pdf
    • http://cefasfese.4pu.com/1732736736736/Heaven-in-West-Texas-by-Susan-Kay-Law.pdf
    • http://cefasfese.4pu.com/2739731739737/West-Texas-Kill-by-Johnny-D-Boggs.pdf
    • http://cefasfese.4pu.com/2737737738734737/Stallions-at-Burnt-Rock-West-Texas-Sunrise-1-by-Paul-Bagdon.pdf
    • http://cefasfese.4pu.com/3736733733731738/Heart-of-a-Warrior-by-Margaret-West.pdf
    • http://cefasfese.4pu.com/1739731735737735/In-the-Keep-of-Time-by-Margaret-J-Anderson.pdf
    • http://cefasfese.4pu.com/3733734733733735/The-Mists-of-Time-by-Margaret-J-Anderson.pdf
    • http://cefasfese.4pu.com/4735736738730730/Running-Out-of-Time-by-Margaret-Peterson-Haddix.pdf
    • http://cefasfese.4pu.com/4739730735733739/The-Time-It-Takes-to-Fall-by-Margaret-Lazarus-Dean.pdf
    • http://cefasfese.4pu.com/2731738735739731/Time-of-the-Twins-Dragonlance-Legends-1-by-Margaret-Weis.pdf
    • http://cefasfese.4pu.com/3735730730730736/An-Outlaw-in-Wonderland-Once-Upon-a-Time-in-the-West-2-by-Lori-Austin.pdf
    • http://cefasfese.4pu.com/4733731736735733/Heart-of-Texas-Vol-2-Caroline-s-Child-Dr-Texas-Heart-of-Texas-3-4-by-Debbie-Macomber.pdf
    • http://cefasfese.4pu.com/1731735739735/Beauty-and-the-Bounty-Hunter-Once-Upon-a-Time-in-the-West-1-by-Lori-Austin.pdf
    • http://cefasfese.4pu.com/3736733733731738/Heart-of-a-Warrior