Malicious PDF — malware analysis report

Static analysis result for SHA-256 8c487ec50390389c…

MALICIOUS

PDF

19.2 KB Created: 2019-05-03 22:58:09 +01:00 Authoring application: mPDF 5.7
MD5: 3d2f48d54945d358cc8f1d9e8aa8ef58 SHA-1: 1936a704632f606f053f88bf63172fa0f45d563c SHA-256: 8c487ec50390389cc95c5ac7c3b33554174473be56822db8b2466d8abacdf9e4
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external link farm. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent to drive traffic or potentially host further malicious payloads. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7735737731735734/uTOpia-Towards-a-New-Toronto-by-Alana-Wilcox.pdf
    • http://cefasfese.4pu.com/7735737731739739/GreenTOpia-Reimagining-Green-in-Toronto-by-Alana-Wilcox.pdf
    • http://cefasfese.4pu.com/8738738734736730/Verkehr-Toronto-Strasse-in-Toronto-Toronto-Subway-Strassenbahn-Toronto-Yonge-University-Spadina-Line-Toronto-Transit-Commission-by-Quelle-Wikipedia.pdf
    • http://cefasfese.4pu.com/9736736736733733/-quot-dampf-quot-Dessen-Erzeugung-Und-Verwendung-Nebst-Katalog-Der-Fabrikate-Der-Babcock-and-Wilcox-Co-30-Cortlandt-Street-New-York-Und-Von-Babcock-and-Wilcox-Limited-114-Newgate-Street-London-by-Babcock-and-Wilcox-Company.pdf
    • http://cefasfese.4pu.com/7738736738734733/Fraternidades-Fraternities-Una-Nueva-Utopia-A-New-Utopia-by-Jacques-Attali.pdf
    • http://cefasfese.4pu.com/5736736738738734/The-Wilcox-Guide-to-the-Best-Watercolor-Paints-by-Michael-Wilcox.pdf
    • http://cefasfese.4pu.com/7735737731735733/Dateline-Toronto-The-Complete-Toronto-Star-Dispatches-1920-24-by-Ernest-Hemingway.pdf
    • http://cefasfese.4pu.com/7735737731735732/Toronto-Comics-Volume-3-Toronto-Comics-3-by-Steven-Andrews.pdf
    • http://cefasfese.4pu.com/5730735739738732/Come-Next-Spring-by-Alana-White.pdf
    • http://cefasfese.4pu.com/9732730736734/Imbroglio-by-Alana-Woods.pdf
    • http://cefasfese.4pu.com/4739731733730733/Torn-Asunder-by-Alana-Terry.pdf
    • http://cefasfese.4pu.com/4734735737735733/The-Beloved-Daughter-by-Alana-Terry.pdf
    • http://cefasfese.4pu.com/1734735731731735/RAGE-Death-Dealers-MC-1-3-5-by-Alana-Sapphire.pdf
    • http://cefasfese.4pu.com/2738731736737738/Renascence-Death-Dealers-MC-5-by-Alana-Sapphire.pdf
    • http://cefasfese.4pu.com/4735731738731731/The-Sign-of-the-Weeping-Virgin-by-Alana-White.pdf
    • http://cefasfese.4pu.com/3739732735735736/Deception-A-Death-Dealers-MC-Novella-by-Alana-Sapphire.pdf
    • http://cefasfese.4pu.com/6733731736737730/Chronic-Se7en-Deadly-SEALs-1-2-by-Alana-Albertson.pdf
    • http://cefasfese.4pu.com/4732732738730739/Alana-amp-Alyssa-s-Secret-Rise-from-the-Ashes-by-Joana-James.pdf
    • http://cefasfese.4pu.com/5730737736/All-the-Lives-I-Want-Essays-About-My-Best-Friends-Who-Happen-to-Be-Famous-Strangers-by-Alana-Massey.pdf
    • http://cefasfese.4pu.com/7735738738735736/Utopia-by-Thomas-More.pdf