Malicious PDF — malware analysis report

Static analysis result for SHA-256 b7d639efbfade3cc…

MALICIOUS

PDF

26.3 KB Created: 2019-05-02 05:38:16 +01:00 Authoring application: mPDF 5.7
MD5: 4eaaf565af12e93223d3d27fe513b5c7 SHA-1: f4247abaf702a961ed4cac2fc19012b25b802949 SHA-256: b7d639efbfade3ccf8250ee7bbe0421ba43348e3a5a41317e95a0a4aad925e3e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'cefasfese.4pu.com'. This domain appears to be used for hosting a link farm, likely to attract traffic or distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links, suggesting a deceptive or spamming intent. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7733736737730738/Shakespeare-Romeo-And-Juliet-Total-Study-Edition-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/6736736730735730/Romeo-and-Juliet-Shakespeare-Appreciated-SmartPass-Audio-Education-Study-Guide-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/7730737738735735/Romeo-amp-Juliet-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/8736732731733736/Romeo-und-Julia-Romeo-and-Juliet-Zweisprachig-Englisch-Deutsch-ebook-Seite-f-r-Seite-Bilingual-English-German-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/7738735738732735/The-Tragedie-of-Romeo-amp-Juliet-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/7731735735731739/Shakespeare-s-Romeo-and-Juliet-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/7739734736735733/Romeo-and-Juliet-Tragedy-Classic-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/1730737733731736737/Romeo-and-Juliet-The-Most-Popular-DRAM-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/6734736739734734/Tragedy-of-Romeo-and-Juliet-Edited-with-Notes-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/7731735734736734/Romeo-and-Juliet-Chinese-Edition-----by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/5737738733737738/Romeo-and-Juliet-Third-Series-The-Arden-Shakespeare-Third-Series-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/6732731733732735/Romeo-and-Juliet---Special-Illustrated-Edition-Includes-Star-Cross-d-Lovers-Photobook-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/5738731733730731/Romeo-amp-Juliet-the-full-play-includes-essays-and-annotations-by-Callie-Feyen-of-The-Teacher-Diaries-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/6731736732734730/Romeo-and-Juliet-as-Arranged-for-the-Stage-by-Forbes-Robertson-and-Presented-at-the-Lyceum-Theatre-on-Saturday-September-21st-1895-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/6730735736733739/Romeo-and-Juliet-a-tragedy-Adapted-to-the-stage-by-David-Garrick-rev-by-J-P-Kemble-and-published-as-it-is-acted-at-the-Theatre-Royal-in-Covent-Garden-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/5732739730733738/Romeo-and-Juliet-Parallel-Texts-of-the-First-2-Quartos-Quarto-1-1597-and-Quarto-2-1599-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/5739733731738730/Romeo-and-Juliet-a-Tragedy-Altered-from-Shakspeare-by-David-Garrick-Esquire-Marked-with-the-Variations-in-the-Managers-Books-at-the-Theatres-Royal-Drury-Lane-and-Covent-Garden-a-New-Edition-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/1731738734734732738/Romeo-and-Juliet-of-Shakespeare-by-shogo-kisaragi.pdf
    • http://cefasfese.4pu.com/4734733731731735/Manga-Shakespeare-Romeo-and-Juliet-by-Richard-Appignanesi.pdf
    • http://cefasfese.4pu.com/1734731736733731/Romeo-and-Juliet-No-Fear-Shakespeare-Graphic-Novels-by-Matt-Wiegle.pdf
    • http://cefasfese.4pu.com/1