Malicious PDF — malware analysis report

Static analysis result for SHA-256 b082c9451769ed1d…

MALICIOUS

PDF

12.5 KB Created: 2019-11-07 21:54:01 +00:00 Authoring application: mPDF 5.7
MD5: 05801fa2330204635c1683cfd5455dae SHA-1: 522b8fa725b35933014b0f0ba3188e973ef946a3 SHA-256: b082c9451769ed1dddd9cc46ba45f83b6d3890f7d1071557af6555a92ca6418d
68 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. While the specific intent of these links is not fully clear from the provided data, the heuristic 'PDF_SEO_LINK_FARM' indicates a pattern often used for SEO manipulation or to distribute malicious content. No scripts were extracted from this sample, limiting the ability to determine a more precise attack vector. The SE_URGENCY_LURE heuristic suggests a social engineering attempt, but lacks specific text to confirm.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7736737734733733/The-Noisy-Way-To-Bed-by-Ian-Whybrow.pdf
    • http://cefasfese.4pu.com/3730734737/Right-Wrong-2-by-Jana-Aston.pdf
    • http://cefasfese.4pu.com/3738730732739739/Mr-Noisy-by-Roger-Hargreaves.pdf
    • http://cefasfese.4pu.com/1730736734730730/Dogabet-by-Dianna-Bonder.pdf
    • http://cefasfese.4pu.com/1732734734733730/The-Hidden-Son-by-Dianna-T-Benson.pdf
    • http://cefasfese.4pu.com/6738730736736734/Camelia-by-Dianna-Dann.pdf
    • http://cefasfese.4pu.com/1735730737736737/Mr-Darcy-s-Daughters-by-Elizabeth-Aston.pdf
    • http://cefasfese.4pu.com/5738738730735/The-Noisy-Paint-Box-by-Barb-Rosenstock.pdf
    • http://cefasfese.4pu.com/7730732739739730/Times-Square-by-Jana-Aston.pdf
    • http://cefasfese.4pu.com/2736734734737732/Mr-Darcy-s-Daughters-by-Elizabeth-Aston.pdf
    • http://cefasfese.4pu.com/5730735736732738/Fling-Wrong-2-5-by-Jana-Aston.pdf
    • http://cefasfese.4pu.com/9735732732730738/Love-in-Transit-by-Jana-Aston.pdf
    • http://cefasfese.4pu.com/9739735732735736/The-Day-Marcus-Flew-by-Dianna-L-Brisco.pdf
    • http://cefasfese.4pu.com/4730734734738732/George-and-the-Noisy-Ghost-by-Robert-Bright.pdf
    • http://cefasfese.4pu.com/3738739736737738/The-True-Darcy-Spirit-by-Elizabeth-Aston.pdf
    • http://cefasfese.4pu.com/3730732733730737/Christmas-in-Noisy-Village-by-Astrid-Lindgren.pdf
    • http://cefasfese.4pu.com/1731730736735/Last-Chance-to-Run-Slye-Temp-0-5-by-Dianna-Love.pdf
    • http://cefasfese.4pu.com/7736736735731739/Repurposing-amp-Home-Decor-by-Dianna-Greenamyer.pdf
    • http://cefasfese.4pu.com/3732737734735732/Tristan-s-Escape-Belador-6-5-by-Dianna-Love.pdf
    • http://cefasfese.4pu.com/5732733735734732/Nowhere-Safe-Slye-Temp-1-by-Dianna-Love.pdf
    • http://cefasfese.4pu.com/3730732733730737/Christmas-in-Noisy-Village-by-