Malicious PDF — malware analysis report

Static analysis result for SHA-256 8faeb04f4a05328a…

MALICIOUS

PDF

19.2 KB Created: 2019-09-06 07:37:34 +01:00 Authoring application: mPDF 5.7
MD5: 3ce58794209bd30dd28abb174989af76 SHA-1: 03121a9ffe6b3f9cc1b4feacf48f3add4b97a8b5 SHA-256: 8faeb04f4a05328aebe815e4e85856920a27235e7f6c3b6b96ec060777c5ec1a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, many of which use numeric slugs in their URLs. This is indicative of a link farm or SEO poisoning technique, likely intended to drive traffic to the 'cefasfese.4pu.com' domain. The document body is heavily obfuscated and unreadable, but the presence of numerous links suggests a social engineering attempt to direct users to potentially malicious content.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1735735737730739/Winter-s-Wrath-Sacrifice-Winter-s-Saga-3-by-Karen-Luellen.pdf
    • http://cefasfese.4pu.com/2732730732737736/Winter-s-Scars-The-Forsaken-Winter-s-Saga-5-by-Karen-Luellen.pdf
    • http://cefasfese.4pu.com/1735735737732737/Winter-s-Storm-Retribution-Winter-s-Saga-2-by-Karen-Luellen.pdf
    • http://cefasfese.4pu.com/1731739732736731/Winter-Solstice-Winter-Viking-Blood-Saga-1-by-E-J-Squires.pdf
    • http://cefasfese.4pu.com/2730736730734736/Backlash-Winter-s-Wrath-1-by-Bianca-Sommerland.pdf
    • http://cefasfese.4pu.com/2734736732732735/The-Winter-of-Her-Discontent-Rosie-Winter-2-by-Kathryn-Miller-Haines.pdf
    • http://cefasfese.4pu.com/3736735734739730/Call-of-Winter-Winter-Princess-Serial-1-by-Skye-MacKinnon.pdf
    • http://cefasfese.4pu.com/3736735734736735/Winter-Princess-Daughter-of-Winter-1-by-Skye-MacKinnon.pdf
    • http://cefasfese.4pu.com/3737736739736732/Winter-of-Passion-Shelter-from-the-Winter-3-by-D-W-Adler.pdf
    • http://cefasfese.4pu.com/1730738730730737731/Rotes-Meer-Der-achte-Fall-f-r-Erik-Winter-Ein-Erik-Winter-Krimi-by-ke-Edwardson.pdf
    • http://cefasfese.4pu.com/1730738738736732738/Hush-Little-Baby-A-Jefferson-Winter-Thriller-0-6-The-Jefferson-Winter-Chronicles-2-by-James-Carol.pdf
    • http://cefasfese.4pu.com/2739732735739736/Dark-Winter-The-Wicca-Circle-Dark-Winter-1-by-John-Hennessy.pdf
    • http://cefasfese.4pu.com/8733730737737736/The-Marvelous-Misadventures-of-Ingrid-Winter-Ingrid-Winter-Misadventure-1-by-J-S-Drangsholt.pdf
    • http://cefasfese.4pu.com/6738733735734739/With-Glowing-Hearts-The-Official-Commemorative-Book-Of-The-XXI-Olympic-Winter-Games-And-The-X-Paralympic-Winter-Games-Des-Plus-Brillants-Exploits-Le-Dhiver-Et-Des-Xes-Jeux-Paralympiques-Dhiver-by-Alison-Gardiner.pdf
    • http://cefasfese.4pu.com/7739731737735/Brian-s-Winter-Brian-s-Saga-3-by-Gary-Paulsen.pdf
    • http://cefasfese.4pu.com/1739738737736731/Winter-Fire-Winter-Fire-1-by-Laurie-Dubay.pdf
    • http://cefasfese.4pu.com/9738734739737735/The-Stones-of-Winter-The-Stones-of-Winter-1-by-Oskar-Jensen.pdf
    • http://cefasfese.4pu.com/2739731734731733/Winter-Garden-Winter-Garden-2-by-Adele-Ashworth.pdf
    • http://cefasfese.4pu.com/2732734735739734/Winter-Ball-Winter-Ball-1-by-Amy-Lane.pdf
    • http://cefasfese.4pu.com/4731735730731735/Wrath-of-a-Mad-God-The-Darkwar-Saga-3-by-Raymond-E-Feist.pdf
    • http://cefasfese.4pu.com/1730738730730737731/Rotes-Meer-Der-achte-F