Malicious PDF — malware analysis report

Static analysis result for SHA-256 79fdb2361e5bf409…

MALICIOUS

PDF

18.0 KB Created: 2019-05-26 17:11:53 +01:00 Authoring application: mPDF 5.7
MD5: 6ab567c7bfc4c26033e688d82ddbb2e4 SHA-1: 9a1978e549b28f8454d2c8aafe5a43dfc0859993 SHA-256: 79fdb2361e5bf4092a10f41d248d8f3e2c36831088ddfe97ff74d831115d9b04
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links pointing to external PDF files, a technique often used for SEO spam or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external PDF link farm, with the dominant host being 'cefasfese.4pu.com'. While the extracted URLs are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent to drive traffic or distribute further payloads. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4735731738738733/Better-Than-Good-Better-Than-1-by-Lane-Hayes.pdf
    • http://cefasfese.4pu.com/2735736733736734/Better-Than-Good-Better-Than-1-by-Lane-Hayes.pdf
    • http://cefasfese.4pu.com/1739732734732731/A-Kind-of-Truth-A-Kind-of-Stories-1-by-Lane-Hayes.pdf
    • http://cefasfese.4pu.com/3733739736733730/A-Kind-of-Honesty-A-Kind-of-Stories-3-by-Lane-Hayes.pdf
    • http://cefasfese.4pu.com/8732739739730736/A-Kind-of-Romance-A-Kind-of-Stories-2-by-Lane-Hayes.pdf
    • http://cefasfese.4pu.com/8732739739730739/Good-Things-Come-In-Small-Packages-The-Amazing-Days-of-Abby-Hayes-12-by-Anne-Mazer.pdf
    • http://cefasfese.4pu.com/3733739732738730/Leaning-Into-Love-Leaning-Into-1-by-Lane-Hayes.pdf
    • http://cefasfese.4pu.com/2737732733737736/The-Good-Luck-Girls-of-Shipwreck-Lane-by-Kelly-Harms.pdf
    • http://cefasfese.4pu.com/3739730733739736/The-Wrong-Man-Right-and-Wrong-2-by-Lane-Hayes.pdf
    • http://cefasfese.4pu.com/3734730737730731/Leaning-Into-A-Wish-Leaning-Into-5-by-Lane-Hayes.pdf
    • http://cefasfese.4pu.com/4737732737737731/A-Few-Good-Fish-Fish-Out-of-Water-3-by-Amy-Lane.pdf
    • http://cefasfese.4pu.com/1730735734733739737/The-Witch-of-Willoughby-Lane-455-Willoughby-Lane-Tales-from-Mockingbird-Reef-Book-1-by-Alex-Tilt.pdf
    • http://cefasfese.4pu.com/3733734730736734/The-Children-Of-Lovely-Lane-Lovely-Lane-2-by-Nadine-Dorries.pdf
    • http://cefasfese.4pu.com/4739737730730730/Music-as-Medicine-Deforia-Lane-s-Life-of-Music-Healing-and-Faith-by-Deforia-Lane.pdf
    • http://cefasfese.4pu.com/4730731736734/The-Good-The-Bad-And-The-Bullied-The-Good-Girl-s-Bad-Boys-1-by-Rubix-Cube-89201.pdf
    • http://cefasfese.4pu.com/4736732739731736/Once-Upon-a-Maiden-Lane-Maiden-Lane-12-5-by-Elizabeth-Hoyt.pdf
    • http://cefasfese.4pu.com/3736735738733734/Churches-That-Make-a-Difference-Reaching-Your-Community-with-Good-News-and-Good-Works-by-Ronald-J-Sider.pdf
    • http://cefasfese.4pu.com/1730734736739730/The-Good-Good-Pig-The-Extraordinary-Life-of-Christopher-Hogwood-by-Sy-Montgomery.pdf
    • http://cefasfese.4pu.com/7731734730730/40-Ways-to-Please-a-Good-Woman-For-Good-Men-by-Aleja-Bennett.pdf
    • http://cefasfese.4pu.com/4733739734739739/Since-Nobody-s-Perfect-How-Good-is-Good-Enough-by-Andy-Stanley.pdf
    • http://cefasfese.4pu.com/4737732737737731/A-Few-G