Malicious PDF — malware analysis report

Static analysis result for SHA-256 9af2d681a25f2f3f…

MALICIOUS

PDF

16.1 KB Created: 2019-05-02 06:08:43 +01:00 Authoring application: mPDF 5.7
MD5: 7cd1308b7a5364f9ea5772e1425cd2a6 SHA-1: 9540402fd89ba334369e8d02e0606b86fdae7950 SHA-256: 9af2d681a25f2f3f75e236a7f9d0ce196569fbd623e7709ed02314780b77caba
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, all hosted on the domain 'cefasfese.4pu.com'. This is indicative of a link farm, likely used for SEO manipulation or to distribute potentially malicious content. While the individual linked PDFs are currently marked as benign, the sheer volume and pattern suggest a malicious intent to drive traffic or distribute further payloads. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1734735731734737/Let-Me-Go-Let-Me-3-by-Lily-Foster.pdf
    • http://cefasfese.4pu.com/1734735730738738/Let-Me-Love-You-Let-Me-2-by-Lily-Foster.pdf
    • http://cefasfese.4pu.com/1734734737739734/Let-Me-Fall-Let-Me-5-by-Lily-Foster.pdf
    • http://cefasfese.4pu.com/1734734736733734/Let-Me-Heal-Your-Heart-Let-Me-4-by-Lily-Foster.pdf
    • http://cefasfese.4pu.com/6739734735739734/Lily-and-the-Creep-Young-Women-of-Faith-Lily-Series-3-by-Nancy-N-Rue.pdf
    • http://cefasfese.4pu.com/2737738736732737/A-New-Home-for-Lily-The-Adventures-of-Lily-Lapp-2-by-Mary-Ann-Kinsinger.pdf
    • http://cefasfese.4pu.com/1731732737738732738/Blue-Lily-Lily-Blue-The-Raven-Cycle-3-Free-Preview-Edition-by-Maggie-Stiefvater.pdf
    • http://cefasfese.4pu.com/4733736738735734/God-s-Needle-How-Lily-Gaynor-Brought-Hope-and-Healing-to-the-Land-of-the-Witchdoctors-by-Lily-Gaynor.pdf
    • http://cefasfese.4pu.com/6733734736736730/Dead-of-Winter-Lily-Dale-Mystery-3-amp-Lily-Dale-7-by-Wendy-Corsi-Staub.pdf
    • http://cefasfese.4pu.com/2738730730732732/Dash-amp-Lily-s-Book-of-Dares-Dash-amp-Lily-1-by-Rachel-Cohn.pdf
    • http://cefasfese.4pu.com/2735730734731736/Blue-Lily-Lily-Blue-The-Raven-Cycle-3-by-Maggie-Stiefvater.pdf
    • http://cefasfese.4pu.com/1738737733738732/Dash-amp-Lily-s-Book-of-Dares-Dash-amp-Lily-1-by-Rachel-Cohn.pdf
    • http://cefasfese.4pu.com/2730738734737733/The-Life-and-Death-of-Lily-Drake-Lily-Drake-1-by-T-Michelle-Nelson.pdf
    • http://cefasfese.4pu.com/5736731731736733/Tiger-Lily-Part-One-Tiger-Lily-1-by-Am-lie-S-Duncan.pdf
    • http://cefasfese.4pu.com/1731733739736739/Outside-the-Magic-Circle-The-Autobiography-of-Virginia-Foster-Durr-by-Virginia-Foster-Durr.pdf
    • http://cefasfese.4pu.com/9739733737737730/The-David-Foster-Wallace-Reader-by-David-Foster-Wallace.pdf
    • http://cefasfese.4pu.com/2737739736736738/Try-by-Lily-Burana.pdf
    • http://cefasfese.4pu.com/4737736738733732/Hot-for-Joe-by-Lily-Rede.pdf
    • http://cefasfese.4pu.com/9738738733734730/My-Dad-is-a-Superhero-by-Lily-Lexington.pdf
    • http://cefasfese.4pu.com/3736735734737730/Lily-The-Seer-1-by-R-M-Walker.pdf
    • http://cefasfese.4pu.com/673373473673