Malicious PDF — malware analysis report

Static analysis result for SHA-256 c034ad2cabffda50…

MALICIOUS

PDF

18.5 KB Created: 2019-05-02 05:11:23 +01:00 Authoring application: mPDF 5.7
MD5: 5d4af31c7704929ef2c2e7027e30ed99 SHA-1: 81b9cb0b63103c4e29c044a295ce368b776e36f6 SHA-256: c034ad2cabffda509050cf3696f737733a0f32e1e2e1be111316453db0076517
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to distribute further payloads. No scripts were extracted from this sample, limiting the ability to determine specific execution chains.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5732734732735731/Boule-de-Suif-And-Other-Stories-by-Guy-de-Maupassant.pdf
    • http://cefasfese.4pu.com/5732734732734736/Boule-de-Suif-Followed-by-The-Port-by-Guy-de-Maupassant.pdf
    • http://cefasfese.4pu.com/5732734732737731/A-Study-Guide-for-Guy-de-Maupassant-s-quot-Boule-de-Suif-quot-by-Cengage-Learning-Gale.pdf
    • http://cefasfese.4pu.com/5732734732735738/Notre-Coeur---A-Woman-s-Pastime-Psychological-Novel-from-one-of-the-greatest-French-writers-widely-regarded-as-the-Father-of-Modern-Short-Story-writing-Necklace-Boule-de-Suif-Bel-Ami-A-Life-by-Guy-de-Maupassant.pdf
    • http://cefasfese.4pu.com/5733734736731738/The-Complete-Short-Stories-of-Guy-de-Maupassant-Part-Two-by-Guy-de-Maupassant.pdf
    • http://cefasfese.4pu.com/4739738738733739/The-Necklace-and-Other-Stories-Maupassant-for-Modern-Times-by-Guy-de-Maupassant.pdf
    • http://cefasfese.4pu.com/5733734736731735/The-Guy-de-Maupassant-Megapack-144-Novels-and-Short-Stories-by-Guy-de-Maupassant.pdf
    • http://cefasfese.4pu.com/5739731731732739/Boule-et-Bill---Le-roi-de-la-jungle-Biblio-Mango-Boule-et-Bill-by-d-39-apr-s-Roba.pdf
    • http://cefasfese.4pu.com/5733734735737737/A-Day-in-the-Country-and-Other-Stories-by-Guy-de-Maupassant.pdf
    • http://cefasfese.4pu.com/5733734735731734/A-Parisian-Affair-and-Other-Stories-by-Guy-de-Maupassant.pdf
    • http://cefasfese.4pu.com/6730735737731733/Album-No-7-Des-gags-de-Boule-et-Bill-Boule-et-Bill-7-by-Jean-Roba.pdf
    • http://cefasfese.4pu.com/5732733735734/Abandoned-A-Collection-of-Great-Stories-by-Guy-de-Maupassant.pdf
    • http://cefasfese.4pu.com/8732732730731734/Ball-Of-Tallow-And-Short-Stories-1910-by-Guy-de-Maupassant.pdf
    • http://cefasfese.4pu.com/6735734733737739/Complete-Works-Madame-Tellier-s-Establishment-and-Short-Stories-by-Guy-de-Maupassant.pdf
    • http://cefasfese.4pu.com/5733734735736738/The-Works-of-Guy-de-Maupassant-by-Guy-de-Maupassant.pdf
    • http://cefasfese.4pu.com/5739731731732736/Boule-et-Bill---Embrouillamini-by-d-39-apr-s-Roba.pdf
    • http://cefasfese.4pu.com/7739739737733736/P-tit-Boule-amp-Bill---Cabanes-by-Jos-Luis-Munuera.pdf
    • http://cefasfese.4pu.com/6730735739731737/Un-amour-de-cocker-Boule-amp-Bill-34-by-Laurent-Verron.pdf
    • http://cefasfese.4pu.com/6730735735735735/Letters-in-the-Snow-Turning-Creek-3-by-Michelle-Boule.pdf
    • http://cefasfese.4pu.com/5739731731733734/Boule-et-Bill---Chiens-et-chats-by-d-39-apr-s-Roba.pdf
    • http://cefasfese.4pu.com/5733734735737737/A-Day-in-th