Malicious PDF — malware analysis report

Static analysis result for SHA-256 c14bc67ef121222d…

MALICIOUS

PDF

20.3 KB Created: 2019-05-04 06:41:59 +01:00 Authoring application: mPDF 5.7
MD5: 4a5e1da374c331f1d01e645ccb01ddd9 SHA-1: bd53db3ffe4664a926f5abef3bba820326d009d4 SHA-256: c14bc67ef121222d21403cd01dfbb8a5b8db5a628d17e09de1355f2622db7f48
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged for containing a large number of external links, a technique often used for SEO manipulation or to host malicious payloads. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing indicate a suspicious pattern. The document body contains numerous URLs, suggesting a link farm or redirection mechanism. No scripts were extracted, limiting further analysis of direct malicious actions.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3730737739735736/Batman-and-the-Mad-Monk-by-Matt-Wagner.pdf
    • http://cefasfese.4pu.com/1731730735733732/Matt-Archer-Monster-Hunter-Matt-Archer-1-by-Kendra-C-Highley.pdf
    • http://cefasfese.4pu.com/2733739733733/Grendel-Black-White-and-Red-by-Matt-Wagner.pdf
    • http://cefasfese.4pu.com/1733739731731733/Sandman-Mystery-Theatre-Vol-1-The-Tarantula-by-Matt-Wagner.pdf
    • http://cefasfese.4pu.com/2734734732738/Madame-Xanadu-Volume-2-Exodus-Noir-by-Matt-Wagner.pdf
    • http://cefasfese.4pu.com/8737737731731736/Der-lachende-Wagner-Das-unbekannte-Leben-des-Bayreuther-Meisters-Richard-Wagner-by-Joachim-K-hler.pdf
    • http://cefasfese.4pu.com/3730738731732735/Absolute-Batman-amp-Robin-Batman-Reborn-by-Grant-Morrison.pdf
    • http://cefasfese.4pu.com/1730735733739/Batman-amp-Robin-Batman-Reborn-by-Grant-Morrison.pdf
    • http://cefasfese.4pu.com/1731730733734733738/Clarence-Monster-s-Monster-Christmas-Story-by-John-E-Dorey.pdf
    • http://cefasfese.4pu.com/6738737731738735/Monster-Graphic-Novels-Monster-Mess-by-Lewis-Trondheim.pdf
    • http://cefasfese.4pu.com/1731736734735732738/Monster-for-a-Day-Or-the-Monster-in-Gregory-s-Pajamas-by-Frank-Kaff.pdf
    • http://cefasfese.4pu.com/2734730731739737/Monster-High-My-Monster-Life-by-Parragon-Publishing.pdf
    • http://cefasfese.4pu.com/1731737739730735/Monster-Makers-Monster-Chronicles-1-by-C-V-Cook.pdf
    • http://cefasfese.4pu.com/1731732735734730730/Batman-33-New-52-Batman-33-by-Scott-Snyder.pdf
    • http://cefasfese.4pu.com/6738731734735730/Mighty-Monster-Machines-Blaze-and-the-Monster-Machines-Little-Golden-Book-by-Nickelodeon-Publishing.pdf
    • http://cefasfese.4pu.com/6739737734739730/Dinosaur-and-Monster-and-The-Magic-Carpet-Dinosaur-and-Monster-stories-Book-1-by-Suzanne-Pollen.pdf
    • http://cefasfese.4pu.com/1732734735731734/Monster-Seeker-2-Rise-of-the-Phoenix-King-Monster-Seeker-Academy-2-by-Ian-Michael-Terry.pdf
    • http://cefasfese.4pu.com/3731731732735736/Walk-on-the-Wild-Side-The-Best-Horror-Stories-of-Karl-Edward-Wagner-Volume-Two-by-Karl-Edward-Wagner.pdf
    • http://cefasfese.4pu.com/3737737733736739/Monster-High-The-Freaky-Fabulous-Collector-s-Set-Monster-High-1-4-by-Lisi-Harrison.pdf
    • http://cefasfese.4pu.com/3731730733737734/Where-the-Summer-Ends-The-Best-Horror-Stories-of-Karl-Edward-Wagner-Volume-One-by-Karl-Edward-Wagner.pdf