Malicious PDF — malware analysis report

Static analysis result for SHA-256 c14dd7be9e38cb85…

MALICIOUS

PDF

25.2 KB Created: 2019-05-02 05:26:49 +01:00 Authoring application: mPDF 5.7
MD5: 8135f51362860618ffca6a1dcf5c0bac SHA-1: 872864ea8a74b5e2d236c04403988f676561910a SHA-256: c14dd7be9e38cb853a044b80be6858469b72bbe6e2d0af67d9d55c3bb78ba82f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was flagged for containing a large number of external links, a technique often used for SEO manipulation or to distribute malicious content. While the document body is heavily obfuscated, the presence of numerous URLs suggests a redirection or phishing attempt. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7737737735736732/Muppet---Illustrated-Characters-Abbot-Alice-Andy-the-Armadillo-Anson-Anderson-Arabs-Ariel-Aunt-Agnes-Snuffleupagus-Aunt-Edna-Aunt-Sue-Baby-Monster-Babyface-Magee-Bean-Bunny-Becca-Bird-Big-Boy-Bigfoot-Billy-Bird-Buddy-Bird-Cabbages-Calvi-by-Source-Wikia.pdf
    • http://cefasfese.4pu.com/8737736737739/Aunt-Dimity-Beats-the-Devil-Aunt-Dimity-Mystery-6-by-Nancy-Atherton.pdf
    • http://cefasfese.4pu.com/8736739735732/Aunt-Dimity-Takes-a-Holiday-Aunt-Dimity-Mystery-8-by-Nancy-Atherton.pdf
    • http://cefasfese.4pu.com/1736739734735734/Aunt-Dimity-Vampire-Hunter-Aunt-Dimity-Mystery-13-by-Nancy-Atherton.pdf
    • http://cefasfese.4pu.com/3733731737738736/Aunt-Dimity-and-the-Deep-Blue-Sea-Aunt-Dimity-Mystery-11-by-Nancy-Atherton.pdf
    • http://cefasfese.4pu.com/7737737735736734/Disney---Animated-Characters-Al-McWhiggin-Alexander-Alfredo-Linguini-Alley-Cats-Alpha-Anchor-Andy-Davis-Anton-Ego-Ashley-Spinelli-Atta-Auguste-Gusteau-Babyface-Barbie-Bashful-Belle-Bernard-Beta-and-Gamma-Big-Baby-Bloat-Bo-Peep-Bob-CRA-by-Source-Wikia.pdf
    • http://cefasfese.4pu.com/8737731730739/Aunt-Dimity-s-Christmas-Aunt-Dimity-Mystery-5-by-Nancy-Atherton.pdf
    • http://cefasfese.4pu.com/4735731739736/May-Bird-Among-the-Stars-May-Bird-2-by-Jodi-Lynn-Anderson.pdf
    • http://cefasfese.4pu.com/6736739731734731/Aunt-Jo-s-Scrap-Bag-Aunt-Jo-s-Scrap-Bag-1-by-Louisa-May-Alcott.pdf
    • http://cefasfese.4pu.com/2731735733739734/Bird-by-Bird-Some-Instructions-on-Writing-and-Life-by-Anne-Lamott.pdf
    • http://cefasfese.4pu.com/5734730730736737/Fly-High-With-Birds-The-Best-Book-Guide-On-Bird-Watching-Including-All-The-Things-You-Need-To-Know-About-Birding-Including-Bird-Watching-Scopes-The-Different-Birds-Bird-Feeders-and-Backyard-Birding-Why-Watch-Birds-And-Where-To-Find-Them-For-A-Rewardin-by-Mains.pdf
    • http://cefasfese.4pu.com/2734731736735739/Bird-The-Bird-Trilogy-1-by-Tami-Egonu.pdf
    • http://cefasfese.4pu.com/8738739738736/Bird-Eating-Bird-by-Kristin-Naca.pdf
    • http://cefasfese.4pu.com/9734731730734739/The-Bird-Tribunal-by-Agnes-Ravatn.pdf
    • http://cefasfese.4pu.com/5733735734734732/Aunt-Jen-by-Paulette-Ramsay.pdf
    • http://cefasfese.4pu.com/4731733738739731/Aunt-Adeline-s-Bequest-by-Amy-Rae-Durreson.pdf
    • http://cefasfese.4pu.com/1733739735737736/The-Aunt-s-Story-by-Patrick-White.pdf
    • http://cefasfese.4pu.com/5730738733739734/The-Dinosaur-Debut-by-Aunt-Eeebs.pdf
    • http://cefasfese.4pu.com/5732739737731738/Aunt-Jeanne-by-Georges-Simenon.pdf
    • http://cefasfese.4pu.com/2734732734731730/The-Sex-Life-of-My-Aunt-by-Mavis-Cheek.pdf
    • http://cefasfese.4pu.com/7737737735736734/Disney---Animated-Characters-Al-McWhiggin-Alexander-Alfredo-Linguini-Alley-Cats-Alpha-Anchor-And