Malicious PDF — malware analysis report

Static analysis result for SHA-256 8eb4c5382cb58a7c…

MALICIOUS

PDF

21.2 KB Created: 2019-06-04 19:33:02 +01:00 Authoring application: mPDF 5.7
MD5: 4dfbbc7fde23b0048cf2b661aa19bbb1 SHA-1: 948a77372daf7e9ff571c51574b8946efa0fee47 SHA-256: 8eb4c5382cb58a7c4574d7f6ad56d0d6b5fb87adabfe9d4e8bb065a9779ca9d0
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. While the extracted URLs themselves are marked as benign, the sheer volume and structure suggest a malicious intent to drive traffic or potentially host further malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2738736739739733/Mad-Kings-amp-Queens-History-s-Most-Famous-Raving-Royals-by-Alison-Rattle.pdf
    • http://cefasfese.4pu.com/4736730735735731/Kings-amp-Queens-of-Great-Britain-A-Very-Peculiar-History-by-Antony-Mason.pdf
    • http://cefasfese.4pu.com/1737737737735737/A-Treasury-of-Royal-Scandals-The-Shocking-True-Stories-of-History-s-Wickedest-Weirdest-Most-Wanton-Kings-Queens-Tsars-Popes-and-Emperors-by-Michael-Farquhar.pdf
    • http://cefasfese.4pu.com/4735732734736738/Kings-And-Queens-by-Tony-Robinson.pdf
    • http://cefasfese.4pu.com/4732737737730737/Kings-And-Queens-by-Terry-Tyler.pdf
    • http://cefasfese.4pu.com/1730735733732733/Cruel-Kings-and-Mean-Queens-by-Terry-Deary.pdf
    • http://cefasfese.4pu.com/5733736736732/Kings-and-Queens-of-England-by-Antonia-Fraser.pdf
    • http://cefasfese.4pu.com/1730730732735730737/3-Kings-3-Queens-Finale-by-Porscha-Sterling.pdf
    • http://cefasfese.4pu.com/8738737732739735/Arthur-Prince-of-the-Roses-Six-Tudor-Queens-0-5-by-Alison-Weir.pdf
    • http://cefasfese.4pu.com/5733739731730730/Cocaine-Kings-A-Queens-Nation-by-LLady-LLuck.pdf
    • http://cefasfese.4pu.com/5738731735730737/Kings-amp-Queens-of-Cent-Africa-by-Sylviane-A-Diouf.pdf
    • http://cefasfese.4pu.com/3732736730/Katherine-of-Arag-n-The-True-Queen-Six-Tudor-Queens-1-by-Alison-Weir.pdf
    • http://cefasfese.4pu.com/8731734737/Jane-Seymour-The-Haunted-Queen-Six-Tudor-Queens-3-by-Alison-Weir.pdf
    • http://cefasfese.4pu.com/4733730730733730/Kings-Queens-Heroes-amp-Fools-The-Wardstone-Trilogy-2-by-M-R-Mathias.pdf
    • http://cefasfese.4pu.com/4739737739734739/Technomad-Global-Raving-Countercultures-Popular-Music-History-by-Graham-St-John.pdf
    • http://cefasfese.4pu.com/6736739738736732/Within-Royal-Palaces-A-Brilliant-and-Charmingly-Written-Inner-View-of-Emperors-Kings-Queens-Princes-and-Princesses-by-Marquise-de-Fontenoy.pdf
    • http://cefasfese.4pu.com/7736738739730735/Famous-Phonies-Legends-Fakes-and-Frauds-Who-Changed-History-Changed-History-1-by-Brianna-DuMont.pdf
    • http://cefasfese.4pu.com/6736739738737730/The-Marquise-de-Fontenoy-s-Revelation-of-High-Life-Within-Royal-Palaces-The-Private-Life-of-Emperors-Kings-Queens-Princes-and-Princesses-by-Marguerite-Cunliffe-Owen.pdf
    • http://cefasfese.4pu.com/2735732735732735/History-s-Great-Queens-by-C-W-Gortner.pdf
    • http://cefasfese.4pu.com/7739730737731738/Cypriot-Monarchs-Cypriot-Queens-Consort-Kings-of-Cyprus-Amalric-II-of-Jerusalem-Cinyras-Guy-of-Lusignan-List-of-Cypriot-Consorts-by-Source-Wikipedia.pdf
    • http://cefasfese.4pu.com/57