Malicious PDF — malware analysis report

Static analysis result for SHA-256 c117af65939a5fb3…

MALICIOUS

PDF

16.4 KB Created: 2019-05-05 05:02:25 +01:00 Authoring application: mPDF 5.7
MD5: 7aa8600d14e5088f02019f2d726bc468 SHA-1: c7fb6e91b2c152088ccd11bfe44c8f1ca4f7cf09 SHA-256: c117af65939a5fb329bb8fc8541630d951a8fc4ea9ff9c0049eb26dd98ffad91
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. The primary heuristic indicates a critical finding related to this link farm, suggesting a malicious intent to redirect users. While no scripts were extracted, the sheer volume of links and the heuristic firing point towards a deceptive or manipulative purpose, likely SEO abuse or a redirection to malicious content. The URLs themselves are not directly malicious but are part of a pattern designed to mislead.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731730735731739732/Magic-in-the-Air-Stardust-3-by-Linda-Chapman.pdf
    • http://cefasfese.4pu.com/1731730735732732731/Midnight-Magic-Stardust-7-by-Linda-Chapman.pdf
    • http://cefasfese.4pu.com/1731730735732736737/Lucy-s-Magic-Journal-by-Linda-Chapman.pdf
    • http://cefasfese.4pu.com/8737734730737739/Wolke-in-Not-Sternenfohlen-6-by-Linda-Chapman.pdf
    • http://cefasfese.4pu.com/1730737739737736736/Ferien-im-Palast-Sternenfohlen-19-by-Linda-Chapman.pdf
    • http://cefasfese.4pu.com/4731737734734731/Starlight-Surprise-My-Secret-Unicorn-4-by-Linda-Chapman.pdf
    • http://cefasfese.4pu.com/8737734733733733/Manege-frei-f-r-Wolke-Sternenfohlen-29-by-Linda-Chapman.pdf
    • http://cefasfese.4pu.com/3730730734736735/A-Special-Friend-My-Secret-Unicorn-6-by-Linda-Chapman.pdf
    • http://cefasfese.4pu.com/1731730737730732734/Eine-Freundin-f-r-Waldfee-Sternenschweif-50-by-Linda-Chapman.pdf
    • http://cefasfese.4pu.com/1731730735732731737/Stardust-Destiny-Stardust-Love-Story-1-by-Nazarea-Andrews.pdf
    • http://cefasfese.4pu.com/4737731736739739/For-the-Love-of-Magic-Spellbound-Falls-5-by-Janet-Chapman.pdf
    • http://cefasfese.4pu.com/7737734734731738/Barney-Bipple-s-Magic-Dandelions-by-Carol-Chapman.pdf
    • http://cefasfese.4pu.com/4735736733738733/The-Magic-Labyrinth-of-Philip-Jos-Farmer-by-Edgar-L-Chapman.pdf
    • http://cefasfese.4pu.com/1731730735730733738/From-Stardust-to-Stardust-by-Samantha-Garman.pdf
    • http://cefasfese.4pu.com/1731730735732732735/Stardust-Diaries-Coming-Out-Stardust-Diaries-0-by-Tarn-Swan.pdf
    • http://cefasfese.4pu.com/3731730737733739/More-Bread-Machine-Magic-by-Linda-Rehberg.pdf
    • http://cefasfese.4pu.com/1731739735733/Prince-of-Magic-Children-of-the-Sun-1-by-Linda-Winstead-Jones.pdf
    • http://cefasfese.4pu.com/6735733730730739/A-Joyful-Mother-of-Children-The-Magic-and-Mayhem-of-Motherhood-by-Linda-Eyre.pdf
    • http://cefasfese.4pu.com/4738738737738736/The-Magic-School-Bus-In-The-Haunted-Museum-A-Book-About-Sound-by-Linda-Ward-Beech.pdf
    • http://cefasfese.4pu.com/3731730737734736/Bread-Machine-Magic-138-Exciting-Recipes-Created-Especially-for-Use-in-All-Types-of-Bread-Machines-by-Linda-Rehberg.pdf
    • http://cefasfese.4pu.com/4735736733738733/The-Magic-Labyrinth-of-Philip-Jos-