Malicious PDF — malware analysis report

Static analysis result for SHA-256 a15fd2860e2e6ac2…

MALICIOUS

PDF

16.9 KB Created: 2019-08-02 07:36:32 +01:00 Authoring application: mPDF 5.7
MD5: 8f5c6c8ada487a0cc3535a21a5fb017f SHA-1: 5dd22cdf66f9ead8bd499b6298b1cfc687042c65 SHA-256: a15fd2860e2e6ac2cdc35ac7c54d1125fbc408dfbdd5b3bf9d4e5682c515e731
120 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs point to benign book titles, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO spam or to mask malicious redirects. The ClamAV detection as Pdf.Dropper.Agent-7126609-0 further supports its malicious classification. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7126609-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7126609-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731738734732739/Blood-and-Snow-Volumes-1-4-Blood-and-Snow-Revenant-in-Training-The-Vampire-Christopher-Blood-Soaked-Promises-by-RaShelle-Workman.pdf
    • http://cefasfese.4pu.com/4735739732730739/The-Vampire-Christopher-Blood-and-Snow-3-by-RaShelle-Workman.pdf
    • http://cefasfese.4pu.com/4738739735730738/Masquerade-s-Moon-Blood-and-Snow-6-by-RaShelle-Workman.pdf
    • http://cefasfese.4pu.com/2730733732733737/Blood-and-Snow-Blood-and-Snow-1-by-RaShelle-Workman.pdf
    • http://cefasfese.4pu.com/1732733739736736/Dovetailed-Immortal-Essence-3-by-RaShelle-Workman.pdf
    • http://cefasfese.4pu.com/1731730730737736735/The-Cindy-Chronicles-The-Complete-Set-by-RaShelle-Workman.pdf
    • http://cefasfese.4pu.com/4732739732734/The-Last-Vampire-and-Black-Blood-The-Last-Vampire-1-2-by-Christopher-Pike.pdf
    • http://cefasfese.4pu.com/9730736734738/Black-Blood-The-Last-Vampire-2-by-Christopher-Pike.pdf
    • http://cefasfese.4pu.com/7731734736737736/Blood-on-Snow-Der-Auftrag-Blood-on-Snow-1-by-Jo-Nesb-.pdf
    • http://cefasfese.4pu.com/4731736737733/The-Last-Vampire-The-Last-Vampire-1-by-Christopher-Pike.pdf
    • http://cefasfese.4pu.com/2733733730730736/The-Last-Vampire-The-Last-Vampire-1-by-Christopher-Pike.pdf
    • http://cefasfese.4pu.com/4731736736733/Vampire-Kisses-Blood-Relatives-Vol-1-Vampire-Kisses-Blood-Relatives-1-by-Ellen-Schreiber.pdf
    • http://cefasfese.4pu.com/4733731731730739/Snow-White-and-the-7-Vampire-Hunters-by-Kat-Halstead.pdf
    • http://cefasfese.4pu.com/2737733738734739/The-Blood-Coven-Vampires-Volume-1-Blood-Coven-Vampire-1-2-by-Mari-Mancusi.pdf
    • http://cefasfese.4pu.com/3733737732738735/Blood-on-Snow-by-Jo-Nesb-.pdf
    • http://cefasfese.4pu.com/2734735736730732/Buffy-the-Vampire-Slayer-Spike-amp-Dru-Buffy-the-Vampire-Slayer-Comic-3-by-Christopher-Golden.pdf
    • http://cefasfese.4pu.com/1738739735737739/Blood-and-Snow-by-Felicity-Heaton.pdf
    • http://cefasfese.4pu.com/4731730730730731/Blood-upon-the-Snow-by-Hilda-Lawrence.pdf
    • http://cefasfese.4pu.com/5737737730734735/V-r-a-havon-Blood-on-Snow-1-by-Jo-Nesb-.pdf
    • http://cefasfese.4pu.com/1731730738/Midnight-Sun-Blood-on-Snow-2-by-Jo-Nesb-.pdf
    • http://cefasfese.4pu.com/7731734736737736/Blood-on-S