Malicious PDF — malware analysis report

Static analysis result for SHA-256 be5c691e86a37de5…

MALICIOUS

PDF

26.1 KB Created: 2019-11-07 11:24:09 +00:00 Authoring application: mPDF 5.7
MD5: 95c74c31cd6a6e04013a1b48f79870d5 SHA-1: 26ed38dcb39645202be1d806c8304a5f5551a335 SHA-256: be5c691e86a37de52679d0b0ef261bb1bf18937f83fd4da9db2d0f45dcfabc84
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a heuristic firing for PDF_SEO_LINK_FARM, indicating it hosts a large number of external links. The document body, though partially corrupted, contains numerous URLs pointing to PDF files, suggesting a link farm or SEO spamming technique. The primary purpose appears to be directing users to a large collection of external documents, likely for traffic generation or to host malicious content indirectly.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7731734730738732/Candida-Diet-How-To-Cure-Candida-With-A-100-Natural-Candida-Cleanse-Diet-candida-cure-candida-cookbook-candida-crusher-candida-moss-candida-cleanse-diet-candida-yeast-candida-albicans-by-Candida-Program.pdf
    • http://cefasfese.4pu.com/7731734732730738/The-Candida-Cure-A-Simple-Easy-to-Follow-5-Step-Candida-Diet-Solution-Guide-FREE-Book-Offer-Included-Candida-Cookbook-Yeast-Infection-Candida-Crusher-Candida-Cleanse-by-Natalie-Jackson.pdf
    • http://cefasfese.4pu.com/7731734732730735/The-Candida-Cure-Become-Candida-Free-With-The-Natural-Candida-Treatment-by-Ralph-Avery.pdf
    • http://cefasfese.4pu.com/7731734732737730/The-Mariner-s-Star-by-Candida-Clark.pdf
    • http://cefasfese.4pu.com/7731734731735734/Candida-Candida-Diet---Secrets-on-how-to-cure-your-yeast-infection-restore-friendly-bacteria-and-cleanse-your-gut-fast-with-the-Candida-Diet-by-Melanie-White.pdf
    • http://cefasfese.4pu.com/7731734733730736/The-Candida-Cleanse-Solution-How-To-Cure-Candida-Naturally-in-21-days-by-Paul-DeVecchi.pdf
    • http://cefasfese.4pu.com/7731734732736732/Candida-The-Ultimate-Cookbook-That-Will-Help-You-Cure-Candida-by-George-Walton.pdf
    • http://cefasfese.4pu.com/7731734732736736/Candida-How-to-cure-Candida-by-Erik-Smith.pdf
    • http://cefasfese.4pu.com/7731734731735738/Candida-Cleanse-Cleanse-Your-Body-to-Cure-Candida-and-Yeast-Infections-Naturally-by-Aubrey-Azzaro.pdf
    • http://cefasfese.4pu.com/2739739737736/Love-Bites-Darkness-amp-Light-Duology-1-by-T-L-Clark.pdf
    • http://cefasfese.4pu.com/4735737732739732/Ancient-House-of-Cards-by-Bryan-T-Clark.pdf
    • http://cefasfese.4pu.com/1735736737736731/Light-Under-the-House-by-Aaron-L-.pdf
    • http://cefasfese.4pu.com/4737734739739731/The-Price-of-Desire-The-House-of-Light-and-Shadow-1-by-P-J-Fox.pdf
    • http://cefasfese.4pu.com/2734733733739739/Light-Outside-the-Closet-Haven-Coffee-House-Boys-1-by-Stephani-Hecht.pdf
    • http://cefasfese.4pu.com/2737730731734733/Chasing-Light-Michelle-Obama-Through-the-Lens-of-a-White-House-Photographer-by-Amanda-Lucidon.pdf
    • http://cefasfese.4pu.com/4737735739736736/Jim-Clark-at-the-Wheel-The-World-s-Greatest-Motor-Racing-Champion-Tells-His-Own-Supercharged-Success-Story-by-Jim-Clark.pdf
    • http://cefasfese.4pu.com/2732734737737730/Father-Son-and-Constitution-How-Justice-Tom-Clark-and-Attorney-General-Ramsey-Clark-Shaped-American-Democracy-by-Alexander-Wohl.pdf
    • http://cefasfese.4pu.com/2733738733731730/Libraries-by-Candida-H-fer.pdf
    • http://cefasfese.4pu.com/7731734733730734/Candida-by-Angela-M-Alghisi.pdf
    • http://cefasfese.4pu.com/7731734730738735/Candida-Albicans-by-Leon-Chaitow.pdf
    • http://cefasfese.4pu.com/7731734732730738/The-Candida-Cure-A-Simple-Easy-to-Follow-5-Step-Candida-Diet-S