Malicious PDF — malware analysis report

Static analysis result for SHA-256 97c5a9e8c939f7ec…

MALICIOUS

PDF

20.1 KB Created: 2019-11-07 22:06:17 +00:00 Authoring application: mPDF 5.7
MD5: 46bf7d49629cf4f318a483a032d030b4 SHA-1: 71efb381461b3061710475219ade93f4cce9d51a SHA-256: 97c5a9e8c939f7ecb3a0e34e9e709132f7d82aea80f90b8f9360947d13b0c2c1
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a content-luring scheme, potentially designed to drive traffic or host malicious content disguised as legitimate documents. The heuristic 'PDF_SEO_LINK_FARM' confirms the presence of numerous external PDF links, with a dominant host identified as 'cefasfese.4pu.com'. While the extracted URLs themselves are currently marked as benign, the sheer volume and the nature of the domain suggest a malicious intent to direct users to potentially harmful content.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731739732736731/Winter-Solstice-Winter-Viking-Blood-Saga-1-by-E-J-Squires.pdf
    • http://cefasfese.4pu.com/1735735737730739/Winter-s-Wrath-Sacrifice-Winter-s-Saga-3-by-Karen-Luellen.pdf
    • http://cefasfese.4pu.com/2732730732737736/Winter-s-Scars-The-Forsaken-Winter-s-Saga-5-by-Karen-Luellen.pdf
    • http://cefasfese.4pu.com/1735735737732737/Winter-s-Storm-Retribution-Winter-s-Saga-2-by-Karen-Luellen.pdf
    • http://cefasfese.4pu.com/8736732737737738/Winter-Solstice-PB-by-Rosamunde-Pilcher.pdf
    • http://cefasfese.4pu.com/7732735738734731/NO-SPHERE-The-Winter-Solstice-Celebration-NOOS-MAG-Book-20-by-Anastasia-Fennell.pdf
    • http://cefasfese.4pu.com/6739739738730/Fires-of-Winter-Haardrad-Viking-Family-1-by-Johanna-Lindsey.pdf
    • http://cefasfese.4pu.com/3736735734739730/Call-of-Winter-Winter-Princess-Serial-1-by-Skye-MacKinnon.pdf
    • http://cefasfese.4pu.com/2734736732732735/The-Winter-of-Her-Discontent-Rosie-Winter-2-by-Kathryn-Miller-Haines.pdf
    • http://cefasfese.4pu.com/3736735734736735/Winter-Princess-Daughter-of-Winter-1-by-Skye-MacKinnon.pdf
    • http://cefasfese.4pu.com/3737736739736732/Winter-of-Passion-Shelter-from-the-Winter-3-by-D-W-Adler.pdf
    • http://cefasfese.4pu.com/4734736732731734/The-Blood-Tainted-Winter-The-Song-of-the-Ash-Tree-1-by-T-L-Greylock.pdf
    • http://cefasfese.4pu.com/1730738730730737731/Rotes-Meer-Der-achte-Fall-f-r-Erik-Winter-Ein-Erik-Winter-Krimi-by-ke-Edwardson.pdf
    • http://cefasfese.4pu.com/1730738738736732738/Hush-Little-Baby-A-Jefferson-Winter-Thriller-0-6-The-Jefferson-Winter-Chronicles-2-by-James-Carol.pdf
    • http://cefasfese.4pu.com/1739736733734730/Blood-Winter-Horngate-Witches-4-by-Diana-Pharaoh-Francis.pdf
    • http://cefasfese.4pu.com/1735738736730738/The-Blood-of-Winter-Demons-of-Lost-Souls-1-by-John-Ozmore.pdf
    • http://cefasfese.4pu.com/2739732735739736/Dark-Winter-The-Wicca-Circle-Dark-Winter-1-by-John-Hennessy.pdf
    • http://cefasfese.4pu.com/8733730737737736/The-Marvelous-Misadventures-of-Ingrid-Winter-Ingrid-Winter-Misadventure-1-by-J-S-Drangsholt.pdf
    • http://cefasfese.4pu.com/6738733735734739/With-Glowing-Hearts-The-Official-Commemorative-Book-Of-The-XXI-Olympic-Winter-Games-And-The-X-Paralympic-Winter-Games-Des-Plus-Brillants-Exploits-Le-Dhiver-Et-Des-Xes-Jeux-Paralympiques-Dhiver-by-Alison-Gardiner.pdf
    • http://cefasfese.4pu.com/7739731737735/Brian-s-Winter-Brian-s-Saga-3-by-Gary-Paulsen.pdf
    • http://cefasfese.4pu.com/37367357347367