Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca3635d589b4b9d4…

MALICIOUS

PDF

18.9 KB Created: 2019-05-02 17:36:36 +01:00 Authoring application: mPDF 5.7
MD5: 915713c28493126597a5f60c484cc586 SHA-1: 23cb25844f524287473bb5eb852f30b553abd912 SHA-256: ca3635d589b4b9d4f036e24be3269f5714fdd3b5b5c1f8d8494891e9fb917f82
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, forming a link farm. The heuristic PDF_SEO_LINK_FARM indicates that these links are likely intended to direct users to external content, potentially for SEO manipulation or to host malicious payloads. The document body is heavily obfuscated, preventing a deeper analysis of its specific intent beyond the link farm. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2736731732730730/Divorce-Interrupted-Lake-Willowbee-1-by-Jill-James.pdf
    • http://cefasfese.4pu.com/1734730732730/How-It-Feels-When-Parents-Divorce-by-Jill-Krementz.pdf
    • http://cefasfese.4pu.com/6733732734730738/LAILAH---God-s-Divorce-from-Her-by-H-James-Kutscka.pdf
    • http://cefasfese.4pu.com/2731737734732734/Happy-Divorce-How-to-turn-your-divorce-into-the-most-brilliant-and-rewarding-opportunity-of-your-life-by-Rossana-Condoleo.pdf
    • http://cefasfese.4pu.com/6733732734738733/LAILAH-God-s-Divorce-from-Her-The-Rick-Hammad-series-Book-1-by-Hilton-James-Kutscka.pdf
    • http://cefasfese.4pu.com/1730730730734731/The-Grief-Recovery-Handbook-A-Program-for-Moving-Beyond-Death-Divorce-and-Other-Devastating-Losses-by-John-W-James.pdf
    • http://cefasfese.4pu.com/2732735730733739/The-Christmas-Con-by-Jill-James.pdf
    • http://cefasfese.4pu.com/5730731738733731/The-Lake-House-by-James-Patterson.pdf
    • http://cefasfese.4pu.com/9733730739737737/Whisper-Lake-by-James-Melzer.pdf
    • http://cefasfese.4pu.com/3730730734733737/Love-in-the-Time-of-Zombies-by-Jill-James.pdf
    • http://cefasfese.4pu.com/3733738732737733/The-Shepherd-s-Life-A-Tale-of-the-Lake-District-by-James-Rebanks.pdf
    • http://cefasfese.4pu.com/4730731733735738/Benedict-Arnold-s-Navy-The-Ragtag-Fleet-That-Lost-the-Battle-of-Lake-Champlain-But-Won-the-American-Revolution-by-James-L-Nelson.pdf
    • http://cefasfese.4pu.com/5737732733733731/Benedict-Arnold-s-Navy-The-Ragtag-Fleet-That-Lost-the-Battle-of-Lake-Champlain-But-Won-the-American-Revolution-by-James-L-Nelson.pdf
    • http://cefasfese.4pu.com/2730738735738730/A-View-of-the-Lake-Living-the-Dream-on-Lake-Superior-by-Beryl-Singleton-Bissell.pdf
    • http://cefasfese.4pu.com/2738730731738734/The-Lake-The-Lake-Trilogy-1-by-AnnaLisa-Grant.pdf
    • http://cefasfese.4pu.com/1731730735737739736/Big-Lake-Blizzard-Big-Lake-4-by-Nick-Russell.pdf
    • http://cefasfese.4pu.com/6731735735730733/Antigone-Interrupted-by-Bonnie-Honig.pdf
    • http://cefasfese.4pu.com/2733733739733732/Interrupted-Lullaby-by-Dana-R-Lynn.pdf
    • http://cefasfese.4pu.com/8738730737739/Girl-Interrupted-by-Susanna-Kaysen.pdf
    • http://cefasfese.4pu.com/4733739735737736/Girl-Interrupted-by-Susanna-Kaysen.pdf
    • http://cefasfese.4pu.com/1730730730734731/Th