Malicious PDF — malware analysis report

Static analysis result for SHA-256 acc7b3040c03ac48…

MALICIOUS

PDF

21.1 KB Created: 2019-11-07 21:24:49 +00:00 Authoring application: mPDF 5.7
MD5: 3ec7bf9757b7bf946a6b9b539a034f53 SHA-1: f5fe39f8396efc597bd8d3ac4e17d0bb070f7f6a SHA-256: acc7b3040c03ac487cd5dc816c5c960071e06314c718998619b773f4f28154cb
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a link farm, with numerous embedded URLs pointing to external PDF documents. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO spam or to host further malicious content. No scripts were extracted, limiting the ability to determine a more specific attack pattern or family.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3734735736736/Percy-Jackson-and-the-Olympians-Boxed-Set-Percy-Jackson-and-the-Olympians-1-5-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/3732738731735/Percy-Jackson-and-the-Olympians-Percy-Jackson-and-the-Olympians-1-3-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/4731730734733/The-Sea-of-Monsters-Percy-Jackson-and-the-Olympians-2-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/8731737737733/The-Last-Olympian-Percy-Jackson-and-the-Olympians-5-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/3733734733739736/The-Sea-of-Monsters-Percy-Jackson-and-the-Olympians-2-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/2735738737736732/The-Lightning-Thief-Percy-Jackson-and-the-Olympians-1-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/4734739733730/The-Battle-of-the-Labyrinth-Percy-Jackson-and-the-Olympians-4-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/1730739737736734730/The-Lightning-Thief-Percy-Jackson-and-the-Olympians-1-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/2739737732736738/The-Lightning-Thief-Percy-Jackson-and-the-Olympians-1-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/2737734734731736/The-Battle-of-the-Labyrinth-Percy-Jackson-and-the-Olympians-4-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/3737735732730731/The-Battle-of-the-Labyrinth-Percy-Jackson-and-the-Olympians-4-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/1735738739734738/The-Titan-s-Curse-Percy-Jackson-and-the-Olympians-3-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/3738734732733/Demigods-and-Monsters-Your-Favorite-Authors-on-Rick-Riordan-s-Percy-Jackson-and-the-Olympians-Series-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/7733732731732737/The-Titan-s-Curse-Percy-Jackson-and-the-Olympians-Book-3-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/7738737732739/Percy-Jackson-Collection-Percy-Jackson-and-the-Lightning-Thief-the-Last-Olympian-the-Titans-Curse-the-Sea-of-Monsters-the-Battle-of-the-Labyrinth-the-Demigod-Files-and-the-Red-Pyramid-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/8736732738737730/The-Battle-of-the-Labyrinth-The-Graphic-Novel-Percy-Jackson-and-the-Olympians-4-by-Robert-Venditti.pdf
    • http://cefasfese.4pu.com/3735736731735/Percy-Jackson-amp-the-Olympians-The-Ultimate-Guide-by-Mary-Jane-Knight.pdf
    • http://cefasfese.4pu.com/6736732738737/Percy-Jackson-s-Greek-Gods-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/7733732730732738/Percy-Jackson-and-the-Sea-of-Monsters-Book-2-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/2735738734730738/Percy-Jackson-s-Greek-Gods-by-Rick-Riordan.pdf
    • http://cefasfese.4pu.com/1730739737736734730/The-Lightning-Thief-P