Malicious PDF — malware analysis report

Static analysis result for SHA-256 9ed0307b779eec22…

MALICIOUS

PDF

14.1 KB Created: 2019-05-01 11:21:44 +01:00 Authoring application: mPDF 5.7
MD5: 8ee2a8bfd689305dc668697da5942d6a SHA-1: 44fa39c0bb672e5068ca369daa7a5a8a7e0a7e63 SHA-256: 9ed0307b779eec2202453612e3a11b643b4affecfa4ccc2c6a7502f3ef3a160f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs pointing to external websites, as indicated by the PDF_SEO_LINK_FARM heuristic. While the extracted URLs themselves are labeled as benign, the sheer volume and structure suggest a malicious intent, likely for SEO manipulation or to serve as a distribution point for further threats. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4737730732733739/Ivan-s-Captive-Submissive-Submissive-s-Wish-1-by-Ann-Mayburn.pdf
    • http://cefasfese.4pu.com/3738737733737/The-Submissive-Submissive-1-by-Tara-Sue-Me.pdf
    • http://cefasfese.4pu.com/3731736737738732/The-Submissive-Submissive-1-by-Tara-Sue-Me.pdf
    • http://cefasfese.4pu.com/2734734739731730/Yes-Ma-am-by-Kay-Jaybee.pdf
    • http://cefasfese.4pu.com/3739735739739736/Not-Her-Type-by-Kay-Jaybee.pdf
    • http://cefasfese.4pu.com/3734736734739737/The-Exhibitionist-Submissive-7-by-Tara-Sue-Me.pdf
    • http://cefasfese.4pu.com/1738736730737735/Testing-the-Submissive-by-Al-Daltrey.pdf
    • http://cefasfese.4pu.com/4737739734731739/The-Master-Submissive-8-by-Tara-Sue-Me.pdf
    • http://cefasfese.4pu.com/7739735/The-Enticement-Submissive-5-by-Tara-Sue-Me.pdf
    • http://cefasfese.4pu.com/4735739735731736/Testing-the-Submissive-by-Al-Daltrey.pdf
    • http://cefasfese.4pu.com/4734736732738/The-Training-Submissive-3-by-Tara-Sue-Me.pdf
    • http://cefasfese.4pu.com/4732736732737733/Perfect-The-Inside-Story-of-Baseball-s-Sixteen-Perfect-Games-by-James-Buckley-Jr-.pdf
    • http://cefasfese.4pu.com/2735737739738733/The-Perfect-Union-Perfect-Love-Series-1-by-Trina-Lane.pdf
    • http://cefasfese.4pu.com/3733737737734733/The-Billionaire-s-Passion-His-Submissive-3-by-Ava-Claire.pdf
    • http://cefasfese.4pu.com/9730735736736/The-Billionaire-s-Forever-His-Submissive-12-by-Ava-Claire.pdf
    • http://cefasfese.4pu.com/1737730730739734/Undercover-Submissive-by-Michelle-Hughes.pdf
    • http://cefasfese.4pu.com/3734737732732733/Brie-s-Montana-Dreams-Submissive-in-Love-4-by-Red-Phoenix.pdf
    • http://cefasfese.4pu.com/2734734737735735/The-Billionaire-Submissive-Billionaires-in-Bondage-1-by-Joely-Sue-Burkhart.pdf
    • http://cefasfese.4pu.com/1737730732737739/Made-to-be-Submissive-Newly-Subservient-1-by-Mecha-Dahl.pdf
    • http://cefasfese.4pu.com/3734735739738730/Perfect-Illusion-Perfect-Series-1-by-Claudia-Tan.pdf