Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba9e70c6aabcd93f…

MALICIOUS

PDF

23.1 KB Created: 2019-11-09 22:08:55 +00:00 Authoring application: mPDF 5.7
MD5: 65a84e5bee3e55f5803b79f0b695191e SHA-1: ed8ca067f270100b2c79819fa9358f293ed46ddc SHA-256: ba9e70c6aabcd93f070429efba863bf6ab0e2e03f2dc780a0c6615d47748cd1a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for a link farm, indicating a large number of embedded external URLs. While many of these URLs are marked as benign, the sheer volume and the nature of the 'PDF_SEO_LINK_FARM' heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a distribution point for further malware. No scripts were extracted from this sample. The primary attack pattern involves leveraging these embedded links.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4732730739736730/Flight-of-the-Hawk-The-River-A-Novel-of-the-American-West-1-by-W-Michael-Gear.pdf
    • http://cefasfese.4pu.com/2739733738739/The-Real-Wild-West-The-101-Ranch-and-the-Creation-of-the-American-West-by-Michael-Wallis.pdf
    • http://cefasfese.4pu.com/2731730731730738/American-Pie-by-Michael-Lee-West.pdf
    • http://cefasfese.4pu.com/8735736732734730/Upstairs-Girls-Prostitution-in-the-American-West-by-Michael-Rutter.pdf
    • http://cefasfese.4pu.com/3733731736734731/Starstrike-by-W-Michael-Gear.pdf
    • http://cefasfese.4pu.com/6732737737730736/Old-Man-River-The-Mississippi-River-in-North-American-History-by-Paul-Schneider.pdf
    • http://cefasfese.4pu.com/6736732730736/Dark-Inheritance-by-W-Michael-Gear.pdf
    • http://cefasfese.4pu.com/3738739739737735/Fire-the-Sky-Contact-The-Battle-for-America-2-by-W-Michael-Gear.pdf
    • http://cefasfese.4pu.com/1731731737739735735/Counter-Measures-Forbidden-Borders-3-by-W-Michael-Gear.pdf
    • http://cefasfese.4pu.com/3739734735731735/A-Searing-Wind-Contact-The-Battle-for-America-3-by-W-Michael-Gear.pdf
    • http://cefasfese.4pu.com/4734733737736/People-of-the-Wolf-North-America-s-Forgotten-Past-1-by-W-Michael-Gear.pdf
    • http://cefasfese.4pu.com/3735737733737732/The-Bank-of-the-River-The-River-1-by-Michael-Richan.pdf
    • http://cefasfese.4pu.com/8732730733732/People-of-the-Weeping-Eye-Moundville-Duology-1-North-America-s-Forgotten-Past-15-by-W-Michael-Gear.pdf
    • http://cefasfese.4pu.com/2737738730738734/Soaring-With-Hawk-by-Sean-Michael.pdf
    • http://cefasfese.4pu.com/5736734732730731/Articles-on-Aviation-Accidents-and-Incidents-in-1961-Including-Sabena-Flight-548-United-Airlines-Flight-859-Northwest-Orient-Airlines-Flight-706-1961-Cincinnati-Zantop-DC-4-Crash-Aero-Flight-311-1961-Yuba-City-B-52-Crash-by-Hephaestus-Books.pdf
    • http://cefasfese.4pu.com/7737738733734737/The-Duel-Pakistan-on-the-Flight-Path-of-American-Power-by-Tariq-Ali.pdf
    • http://cefasfese.4pu.com/5731739732735738/First-Flight-Around-the-World-The-Adventures-of-the-American-Fliers-Who-Won-the-Race-by-Tim-Grove.pdf
    • http://cefasfese.4pu.com/5733732738739/Feather-of-Hawk---Rebellion-Epic-historical-fiction-based-on-a-true-story-by-Dave-Michael.pdf
    • http://cefasfese.4pu.com/9738737730736736/The-Next-American-Nation-The-New-Nationalism-and-the-Fourth-American-Revolution-by-Michael-Lind.pdf
    • http://cefasfese.4pu.com/1733730732734734/Flight-of-the-Hummingbird-A-Parable-for-the-Environment-by-Michael-Nicoll-Yahgulanaas.pdf
    • http://cefasfese.4pu.com/3739734735731735/A-Searing-Wind-Contact-The-Battle-for-America-3-by-W-Micha