Malicious PDF — malware analysis report

Static analysis result for SHA-256 9695a861a144f00c…

MALICIOUS

PDF

16.8 KB Created: 2020-01-03 01:54:00 +00:00 Authoring application: mPDF 5.7
MD5: 66272d33dd9d10725a4c470c63ee84ae SHA-1: fec684fa6980e9625bc9c6146291303733f62f20 SHA-256: 9695a861a144f00cd11111e2cc283a93f57c1a99f8547db9da278305ce86f109
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The primary heuristic indicates this is a critical finding, suggesting the document's purpose is to direct users to a high volume of external sites. No scripts were extracted from this sample. The embedded URLs are likely intended to lead users to malicious content or phishing pages.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1735736730731733/The-Weaver-s-Loom-by-P-L-Reid.pdf
    • http://cefasfese.4pu.com/9735734733733736/Rainbow-Loom-Magic-10-Awesome-New-And-Fun-Loom-Designs-For-Any-Level-Of-Skill-by-Brooke-Wegner.pdf
    • http://cefasfese.4pu.com/4738730730/The-Alchemists-of-Loom-Loom-Saga-1-by-Elise-Kova.pdf
    • http://cefasfese.4pu.com/1736737739738730/The-Ilia-Stone-by-R-J-Loom.pdf
    • http://cefasfese.4pu.com/1736736734730738/Loom-by-Th-r-se-Soukar-Chehade.pdf
    • http://cefasfese.4pu.com/4738736734735730/The-Loom-of-Youth-by-Alec-Waugh.pdf
    • http://cefasfese.4pu.com/2731732735735736/Colors-in-the-Dreamweaver-s-Loom-by-Beth-Hilgartner.pdf
    • http://cefasfese.4pu.com/2737738731735736/Daughter-of-the-Loom-Bells-of-Lowell-1-by-Tracie-Peterson.pdf
    • http://cefasfese.4pu.com/6731730731737730/Bead-Tapestry-Patterns-Loom-Adele-Besson-by-Renoir-by-Georgia-Grisolia.pdf
    • http://cefasfese.4pu.com/1731739731738734730/Rainbow-Loom---Fr-chtchen-Die-erste-deutsche-Kindle-Buch-Serie-ber-diese-tolle-Basteltechnik-by-Karolinchen.pdf
    • http://cefasfese.4pu.com/9735735735732731/While-America-Aged-How-Pension-Debts-Ruined-General-Motors-Stopped-the-NYC-Subways-Bankrupted-San-Diego-and-Loom-as-the-Next-Financial-Crisis-by-Roger-Lowenstein.pdf
    • http://cefasfese.4pu.com/4735737736739731/See-You-in-The-Morning-by-A-T-Weaver.pdf
    • http://cefasfese.4pu.com/1735736730732731/The-Weaver-by-Kai-Strand.pdf
    • http://cefasfese.4pu.com/2736739739733732/Sun-Walker-by-L-M-Weaver.pdf
    • http://cefasfese.4pu.com/1737733739732736/Always-by-Amanda-Weaver.pdf
    • http://cefasfese.4pu.com/4734730732739736/Against-the-Magic-by-Donna-K-Weaver.pdf
    • http://cefasfese.4pu.com/7737733731736735/Cole-by-Kristina-Weaver.pdf
    • http://cefasfese.4pu.com/1732736737735738/The-Survivors-Memory-Boy-2-by-Will-Weaver.pdf
    • http://cefasfese.4pu.com/1731737734733738/The-Winter-House-by-Dee-Weaver.pdf
    • http://cefasfese.4pu.com/9739734730733733/Kobra-II-The-Continuance-by-Kalvin-Weaver.pdf