Malicious PDF — malware analysis report

Static analysis result for SHA-256 c2ae74f9663c6f4b…

MALICIOUS

PDF

17.3 KB Created: 2019-05-03 05:26:20 +01:00 Authoring application: mPDF 5.7
MD5: 41bcb08705c17568d9336dc7d39c2f7f SHA-1: 9319cc2d7f0373dfa33d870ff71cb462bf09f98b SHA-256: c2ae74f9663c6f4bcea0c9a0cd29f3c6d72cb8d8c096575d4b82cdafd3170836
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. While the extracted URLs are currently marked as benign, the sheer volume and the heuristic firing of PDF_SEO_LINK_FARM indicate a malicious intent to drive traffic to these external resources. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2730734735732730/Highland-Dragon-Warrior-Dawn-of-the-Highland-Warrior-1-by-Isabel-Cooper.pdf
    • http://cefasfese.4pu.com/3735732736733732/The-Highland-Dragon-s-Lady-Highland-Dragon-2-by-Isabel-Cooper.pdf
    • http://cefasfese.4pu.com/3738733736733738/Beyond-the-Highland-Mist-To-Tame-a-Highland-Warrior-Highlander-1-2-by-Karen-Marie-Moning.pdf
    • http://cefasfese.4pu.com/1737737734737735/Highland-Warrior-by-Connie-Mason.pdf
    • http://cefasfese.4pu.com/4737735731733733/Highland-Warrior-by-Hannah-Howell.pdf
    • http://cefasfese.4pu.com/2736734732732736/The-Beast-of-Clan-Kincaid-Highland-Warrior-1-by-Lily-Blackwood.pdf
    • http://cefasfese.4pu.com/1736736732733737/Tempted-by-the-Highland-Warrior-MacKinloch-Clan-3-by-Michelle-Willingham.pdf
    • http://cefasfese.4pu.com/3735732735739732/Just-in-Time-for-a-Highland-Christmas-Highland-Gardens-2-5-by-Dawn-Marie-Hamilton.pdf
    • http://cefasfese.4pu.com/4737737732732737/The-Last-Warrior-of-Unigaea-The-Last-Warrior-of-Unigaea-1-by-Harmon-Cooper.pdf
    • http://cefasfese.4pu.com/3734739731739736/Beauty-and-the-Highland-Beast-A-Highland-Fairy-Tale-1-by-Lecia-Cornwall.pdf
    • http://cefasfese.4pu.com/6739735738730736/Highland-Steam-A-Scrapbook-of-Images-from-the-Kyle-Mallaig-and-Highland-Lines-by-Bill-Williams.pdf
    • http://cefasfese.4pu.com/4733736733733730/Temptation-of-a-Highland-Scoundrel-Highland-Warriors-2-by-Sue-Ellen-Welfonder.pdf
    • http://cefasfese.4pu.com/3739737738731730/Highland-Hunger-Game-One-Highland-Wars-1-1-by-Eliza-Knight.pdf
    • http://cefasfese.4pu.com/2735732731737739/My-Highland-Lord-Highland-Lords-2-by-Tarah-Scott.pdf
    • http://cefasfese.4pu.com/9732738737739730/His-Highland-Rose-His-Highland-Heart-0-5-by-Willa-Blair.pdf
    • http://cefasfese.4pu.com/2732737732735739/Highland-Deception-Highland-Pride-1-by-Lori-Ann-Bailey.pdf
    • http://cefasfese.4pu.com/2730734734731736/Highland-Flame-Highland-Weddings-4-by-Mary-Wine.pdf
    • http://cefasfese.4pu.com/3737732731735734/A-Highland-Home-Highland-Heart-2-by-Cali-MacKay.pdf
    • http://cefasfese.4pu.com/4739736736736737/Return-of-the-Highland-Laird-Highland-Force-4-by-Amy-Jarecki.pdf
    • http://cefasfese.4pu.com/6733738731739/On-a-Highland-Shore-Highland-1-by-Kathleen-Givens.pdf
    • http://cefasfese.4pu.com/4737737732732737/The-Last-Warrior-of-Unigaea-The-Last-Warrior-of-Unigae