Malicious PDF — malware analysis report

Static analysis result for SHA-256 97525378f8086714…

MALICIOUS

PDF

16.0 KB Created: 2019-05-04 05:39:49 +01:00 Authoring application: mPDF 5.7
MD5: 93581e584ac7a7b33d23ffc3b09eed2c SHA-1: ead3f780136ebfc58cd3120d6050f6070954a397 SHA-256: 97525378f808671458e8700949ff9c4a30b2acaadd0a976e857708de3c057769
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, forming a link farm. The heuristic PDF_SEO_LINK_FARM indicates that this is a technique to artificially inflate search engine rankings or to distribute malicious content. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent to redirect users to potentially harmful content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7735738733733738/Life-of-the-Prophet---A-Biography-of-Prophet-Mohammed-by-Leila-Abouzeid.pdf
    • http://cefasfese.4pu.com/7735738734732735/Mohammed-the-Prophet-of-Islam-by-Herbert-Edward-Elton-Hayes.pdf
    • http://cefasfese.4pu.com/4732739735735737/The-Prophet-of-Akhran-Rose-of-the-Prophet-3-by-Margaret-Weis.pdf
    • http://cefasfese.4pu.com/1733738731730736/The-Sealed-Nectar-Biography-of-Prophet-Muhammad-by-Safiy-al-Rahman-al-Mubarakfuri.pdf
    • http://cefasfese.4pu.com/4732734731736738/C-S-Lewis---A-Life-Eccentric-Genius-Reluctant-Prophet-by-Alister-E-McGrath.pdf
    • http://cefasfese.4pu.com/1734739736737/Lost-Prophet-The-Life-and-Times-of-Bayard-Rustin-by-John-D-39-Emilio.pdf
    • http://cefasfese.4pu.com/4737733734732736/Year-of-the-Elephant-A-Moroccan-Woman-s-Journey-Toward-Independence-by-Leila-Abouzeid.pdf
    • http://cefasfese.4pu.com/6735739737739739/The-Double-Life-of-Laurence-Oliphant-Victorian-Pilgrim-and-Prophet-by-Bart-Casey.pdf
    • http://cefasfese.4pu.com/5737730730732/The-Reluctant-Prophet-The-Reluctant-Prophet-1-by-Nancy-N-Rue.pdf
    • http://cefasfese.4pu.com/3739736736734737/Lies-of-the-Prophet-by-Ike-Hamill.pdf
    • http://cefasfese.4pu.com/1731735738734734738/The-Prophet-by-Kahlil-Gibran.pdf
    • http://cefasfese.4pu.com/1733739737736731/The-Prophet-by-Kahlil-Gibran.pdf
    • http://cefasfese.4pu.com/6736733733736732/WHO-IS-MOHAMED-Prophet-Muhammad-by-A-MABROUK.pdf
    • http://cefasfese.4pu.com/3732732737732737/The-Prophet-and-His-Work-by-Gordon-B-Hinckley.pdf
    • http://cefasfese.4pu.com/6733738733732735/Story-of-Prophet-Adam-by-Faiza-Gul.pdf
    • http://cefasfese.4pu.com/8731737735736/Prophet-Books-of-the-Infinite-1-by-R-J-Larson.pdf
    • http://cefasfese.4pu.com/7734730737738732/American-Prophet-by-Paul-Beatty.pdf
    • http://cefasfese.4pu.com/7738739731733733/Ennui-Prophet-by-Christopher-Kennedy.pdf
    • http://cefasfese.4pu.com/3739736732737731/The-Prophet-Calls-by-Melanie-Sumrow.pdf
    • http://cefasfese.4pu.com/8733733734730734/The-Prophet-s-Daughter-by-Kilayla-Pilon.pdf
    • http://cefasfese.4pu.com/4737733734732736/Year-of-the-Elephant-A-Moroccan-Woman-s-Journey-Toward-Independ