Malicious PDF — malware analysis report

Static analysis result for SHA-256 a94a72cc233ff48a…

MALICIOUS

PDF

17.5 KB Created: 2019-05-03 05:05:17 +01:00 Authoring application: mPDF 5.7
MD5: 3c589f5ea6e79ab9e087841f6482497a SHA-1: 6d6e55ea300041d2880f99fcb378dc4bb7112acd SHA-256: a94a72cc233ff48afb5ecf558adb136cc62fea3a5c4b4d3e56f8e04166d05e34
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document exhibits a critical heuristic firing for a link farm, containing numerous embedded URLs. These URLs point to other PDF files, suggesting a tactic to manipulate search engine results or distribute content. While the URLs themselves are currently marked as benign, the sheer volume and nature of the links indicate a malicious intent, likely for SEO spam or as a distribution vector for further malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1733736730735737/Flight-The-Crescent-Chronicles-1-by-Alyssa-Rose-Ivy.pdf
    • http://cefasfese.4pu.com/4736736737730739/First-amp-Forever-The-Crescent-Chronicles-4-by-Alyssa-Rose-Ivy.pdf
    • http://cefasfese.4pu.com/7737736739733733/Love-The-Allure-Chronicles-4-by-Alyssa-Rose-Ivy.pdf
    • http://cefasfese.4pu.com/3735738739733730/Stay-The-Empire-Chronicles-3-by-Alyssa-Rose-Ivy.pdf
    • http://cefasfese.4pu.com/1733735730730739/Hunt-The-Grizzly-Brothers-Chronicles-1-by-Alyssa-Rose-Ivy.pdf
    • http://cefasfese.4pu.com/3734738739735731/Seduction-s-Kiss-The-Allure-Chronicles-0-5-by-Alyssa-Rose-Ivy.pdf
    • http://cefasfese.4pu.com/3730735733733738/Dire-The-Dire-Wolves-Chronicles-1-by-Alyssa-Rose-Ivy.pdf
    • http://cefasfese.4pu.com/1737738739732730/Veer-Clayton-Falls-2-by-Alyssa-Rose-Ivy.pdf
    • http://cefasfese.4pu.com/3739732739738731/Shaken-Not-Stirred-Mixology-1-by-Alyssa-Rose-Ivy.pdf
    • http://cefasfese.4pu.com/5736734732730731/Articles-on-Aviation-Accidents-and-Incidents-in-1961-Including-Sabena-Flight-548-United-Airlines-Flight-859-Northwest-Orient-Airlines-Flight-706-1961-Cincinnati-Zantop-DC-4-Crash-Aero-Flight-311-1961-Yuba-City-B-52-Crash-by-Hephaestus-Books.pdf
    • http://cefasfese.4pu.com/2738733734735734/The-Hazards-of-Sex-on-the-Beach-Hazards-3-by-Alyssa-Rose-Ivy.pdf
    • http://cefasfese.4pu.com/3733737730735736/Corded-The-Corded-Saga-1-by-Alyssa-Rose-Ivy.pdf
    • http://cefasfese.4pu.com/3734738737730737/Raven-Flight-Ravynwyng-Chronicles-Universe-0-3-by-Anna-Dobritt.pdf
    • http://cefasfese.4pu.com/4731738731736731/Amster-Damned-Time-Flight-Chronicles-1-by-Nils-Nisse-Visser.pdf
    • http://cefasfese.4pu.com/7732739730734/Imitatore-The-Donna-Chronicles-1-by-A-Rose.pdf
    • http://cefasfese.4pu.com/4735733739735732/Fusion-Portal-Chronicles-5-by-Imogen-Rose.pdf
    • http://cefasfese.4pu.com/9731733731737735/Retaliation-Bonfire-Chronicles-3-by-Imogen-Rose.pdf
    • http://cefasfese.4pu.com/3731735732733739/Faustine-Bonfire-Chronicles-1-by-Imogen-Rose.pdf
    • http://cefasfese.4pu.com/1738739736731735/The-Afterglow-Trilogy-The-Afterglow-Trilogy-1-3-by-Alyssa-Rose-Ivy.pdf
    • http://cefasfese.4pu.com/2736737731736737/Outside-the-Limelight-Ballet-Theatre-Chronicles-2-by-Terez-Mertes-Rose.pdf
    • http://cefasfese.4pu.com/5736734732730731/Articles-on-Aviation-Accidents-and-Incidents-in-1961-Including-Sabena-Flight-548-United-Airlines-Flight-859-Northwest-Orien