Malicious PDF — malware analysis report

Static analysis result for SHA-256 9109eaeb2704f87f…

MALICIOUS

PDF

20.3 KB Created: 2019-05-02 17:52:25 +01:00 Authoring application: mPDF 5.7
MD5: 781b91aab09b9cb5acf88661decd007c SHA-1: 43b4332e4f5347b5e3da6c9a677394132cc012ff SHA-256: 9109eaeb2704f87feb31ec22bcd7660295da21c8a6f6675aca876237c8f4124b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified as a link farm. The primary heuristic indicates a mass of external PDF links, with a dominant host of 'cefasfese.4pu.com'. The document body, though partially corrupted, contains URLs that are consistent with the link farm heuristic. This suggests the PDF is designed to redirect users to a large collection of other documents, likely for SEO manipulation or to host malicious content.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7738730736734738/Creepaway-Camp-Diary-of-a-Minecraft-Zombie-6-by-Zack-Zombie.pdf
    • http://cefasfese.4pu.com/7738730736735731/Zombie-Family-Reunion-Diary-of-a-Minecraft-Zombie-7-by-Zack-Zombie.pdf
    • http://cefasfese.4pu.com/8730733737735733/Back-to-Scare-School-Diary-of-a-Minecraft-Zombie-8-by-Zack-Zombie.pdf
    • http://cefasfese.4pu.com/7738730736734736/Bullies-and-Buddies-Diary-of-a-Minecraft-Zombie-2-by-Zack-Zombie.pdf
    • http://cefasfese.4pu.com/2736735/A-Scare-of-a-Dare-Diary-of-a-Minecraft-Zombie-1-by-Zack-Zombie.pdf
    • http://cefasfese.4pu.com/1737736732737730/Minecraft-Seeds-Handbook-The-Top-25-MUST-HAVE-Seeds-of-2015-PC-Edition-Minecraft-Seeds-Minecraft-PE-Minecraft-Handbook-Minecraft-Diary-Minecraft-Free-Books-by-Steve-Creepers.pdf
    • http://cefasfese.4pu.com/1731734736731735733/The-Rise-and-Fall-of-the-Zombie-Empire-Part-III-King-Zombie-by-Steven-Orlowski.pdf
    • http://cefasfese.4pu.com/5730738736738/The-Zombie-Rule-Book-A-Zombie-Apocalypse-Survival-Guide-by-Tony-Newton.pdf
    • http://cefasfese.4pu.com/9739734730731738/Enter-the-Zombie-Nathan-Abercrombie-Accidental-Zombie-5-by-David-Lubar.pdf
    • http://cefasfese.4pu.com/1730734735739737731/Zombie-Badge-of-Courage-The-Tale-of-an-Infantryman-Fighting-in-the-American-Zombie-War-by-Jonathan-Biermann.pdf
    • http://cefasfese.4pu.com/4734739730735735/Zombie-Country-Zombie-Apocalypse-2-by-Samantha-Hoffman.pdf
    • http://cefasfese.4pu.com/2733731739731735/Zombie-Cruise-Zombie-Vacations-1-by-Janiera-Eldridge.pdf
    • http://cefasfese.4pu.com/7738735735735739/--1-Zombie-From-Now-On-1-Kyo-Kara-Zombie-1-by-Yugo-Ishikawa.pdf
    • http://cefasfese.4pu.com/9735738735737735/Minecraft-Diary-of-a-Minecraft-Farm-Boy-Book-1-Attack-of-The-Enderman-An-unofficial-Minecraft-Book-for-kids-by-Vern-Vandermeer.pdf
    • http://cefasfese.4pu.com/3735739735730739/My-Zombie-My-I-Zombie-2-by-Jack-Wallen.pdf
    • http://cefasfese.4pu.com/3736731733730735/Zombie-Spring-s-Trooper-Tyree-A-First-Sequel-Zombie-Spring-2-by-Chris-Okusako.pdf
    • http://cefasfese.4pu.com/8734730736739738/Since-the-Sirens-Zombie-s-1st-Bite-Edition-Sirens-of-the-Zombie-Apocalypse-1-3-by-E-E-Isherwood.pdf
    • http://cefasfese.4pu.com/1733732733733735/Revenge-amp-the-Zombie-Apocalypse-Zombie-Apocalypse-3-by-Chelsea-Luna.pdf
    • http://cefasfese.4pu.com/4733733733734/Death-amp-the-Zombie-Apocalypse-Zombie-Apocalypse-2-by-Chelsea-Luna.pdf
    • http://cefasfese.4pu.com/9732730730739/Love-amp-the-Zombie-Apocalypse-Zombie-Apocalypse-1-by-Chelsea-Luna.pdf