Malicious PDF — malware analysis report

Static analysis result for SHA-256 c885773cc16757eb…

MALICIOUS

PDF

24.0 KB Created: 2019-05-02 16:51:57 +01:00 Authoring application: mPDF 5.7
MD5: 5416e2578ede6362c48511669f63e121 SHA-1: 5423e68489abcc56d6a7e566015673f8d962f373 SHA-256: c885773cc16757ebf6d3a7601c61a05336678e506da96cd05797366d29c2737e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The majority of these links point to the domain 'cefasfese.4pu.com', which appears to be a link farm designed to host numerous book-related PDFs. This suggests a social engineering tactic to direct users to a potentially malicious or unwanted collection of files. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8730733730731735/Paradise-Lost-Color-Illustrated-Formatted-for-E-Readers-by-John-Milton.pdf
    • http://cefasfese.4pu.com/8730733730739730/The-Pilgrim-s-Progress-Color-Illustrated-Formatted-for-E-Readers-by-John-Bunyan.pdf
    • http://cefasfese.4pu.com/5735731731732735/Paradise-Lost-By-John-Milton-Illustrated---Original-amp-Unabridged-Free-Audiobook-Inside-by-John-Milton.pdf
    • http://cefasfese.4pu.com/8730732739737730/Persuasion-Color-Illustrated-Formatted-for-E-Readers-by-Jane-Austen.pdf
    • http://cefasfese.4pu.com/8730732739738738/Ulysses-Color-Illustrated-Formatted-for-E-Readers-by-James-Joyce.pdf
    • http://cefasfese.4pu.com/8730732739736738/Hamlet-Color-Illustrated-Formatted-for-E-Readers-by-William-Shakespeare.pdf
    • http://cefasfese.4pu.com/8730733730738734/My-ntonia-Color-Illustrated-Formatted-for-E-Readers-by-Willa-Cather.pdf
    • http://cefasfese.4pu.com/8730733730733734/Around-The-World-In-80-Days-Color-Illustrated-Formatted-for-E-Readers-by-Jules-Verne.pdf
    • http://cefasfese.4pu.com/8730733730733733/The-Divine-Comedy-Color-Illustrated-Formatted-for-E-Readers-by-Dante-Alighieri.pdf
    • http://cefasfese.4pu.com/8730732739736736/THE-SCARLET-LETTER-Color-Illustrated-Formatted-for-E-Readers-by-Nathaniel-Hawthorne.pdf
    • http://cefasfese.4pu.com/8730733730734730/Thus-Spoke-Zarathustra-Color-Illustrated-Formatted-for-E-Readers-by-Friedrich-Nietzsche.pdf
    • http://cefasfese.4pu.com/7732731737736734/The-Importance-of-Being-Earnest-Color-Illustrated-Formatted-for-E-Readers-by-Oscar-Wilde.pdf
    • http://cefasfese.4pu.com/8730732739738732/Don-Quixote-Color-Illustrated-Formatted-for-E-Readers-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://cefasfese.4pu.com/8730733730731730/The-Phantom-Of-The-Opera-Color-Illustrated-Formatted-for-E-Readers-by-Gaston-Leroux.pdf
    • http://cefasfese.4pu.com/6736739733734737/Crime-and-Punishment-Color-Illustrated-Formatted-for-E-Readers-by-Fyodor-Dostoyevsky.pdf
    • http://cefasfese.4pu.com/8730733730735730/The-Tenant-of-Wildfell-Hall-Color-Illustrated-Formatted-for-E-Readers-by-Anne-Bront-.pdf
    • http://cefasfese.4pu.com/6736739733734736/The-Count-Of-Monte-Cristo-Color-Illustrated-Formatted-for-E-Readers-by-Alexandre-Dumas.pdf
    • http://cefasfese.4pu.com/8730733730731732/Twenty-Thousand-Leagues-Under-The-Sea-Color-Illustrated-Formatted-for-E-Readers-by-Jules-Verne.pdf
    • http://cefasfese.4pu.com/7732731735734733/Paradise-Lost-Illustrated-Platinum-Edition-Free-Audiobook-Included-by-John-Milton.pdf
    • http://cefasfese.4pu.com/1730730730733735736/Epic-poem-by-John-Milton-Paradise-Lost-with-Paradise-Regained-and-Lycidas-by-John-Milton.pdf
    • http://cefasfese.4pu.com/8730733730733734/Ar