Malicious PDF — malware analysis report

Static analysis result for SHA-256 caa32f1c6a07548e…

MALICIOUS

PDF

23.7 KB Created: 2019-06-04 14:55:02 +01:00 Authoring application: mPDF 5.7
MD5: 7e9b3518b6d7a5858a27563509014a71 SHA-1: 975076f3c91e9e6241b2788c40c1c219e7d0b51d SHA-256: caa32f1c6a07548e9157cd641f289d3dcfbef745b8a4c60d8900a8a6dec95cdc
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a link farm, with 26 external PDF links embedded. The primary purpose appears to be SEO manipulation or to serve as a distribution point for other malicious content. While no scripts were extracted, the sheer volume of links suggests a malicious intent to direct users to potentially harmful sites. The URLs themselves are not directly malicious but are part of a larger malicious infrastructure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2731732737731736/Powerless-Against-You-by-Gail-Simone.pdf
    • http://cefasfese.4pu.com/1739733732738735/Red-Sonja-1-by-Gail-Simone.pdf
    • http://cefasfese.4pu.com/3737733735738734/Welcome-to-Tranquility-Vol-1-by-Gail-Simone.pdf
    • http://cefasfese.4pu.com/3732738734732732/Crosswind-Vol-1-by-Gail-Simone.pdf
    • http://cefasfese.4pu.com/1739733737732734/Wonder-Woman-The-Circle-by-Gail-Simone.pdf
    • http://cefasfese.4pu.com/4734733736734736/Batgirl-Vol-4-Wanted-by-Gail-Simone.pdf
    • http://cefasfese.4pu.com/3737733735735732/The-Movement-Vol-1-Class-Warfare-by-Gail-Simone.pdf
    • http://cefasfese.4pu.com/1739733730736736/Birds-of-Prey-Volume-1-End-Run-by-Gail-Simone.pdf
    • http://cefasfese.4pu.com/2733736739731/Clean-Room-Vol-1-Immaculate-Conception-by-Gail-Simone.pdf
    • http://cefasfese.4pu.com/2735730731734730/Birds-of-Prey-Volume-2-The-Death-of-Oracle-by-Gail-Simone.pdf
    • http://cefasfese.4pu.com/3733734730732733/Clean-Room-Vol-3-Waiting-for-the-Stars-to-Fall-by-Gail-Simone.pdf
    • http://cefasfese.4pu.com/2733731734732730/Swords-of-Sorrow-Complete-Collection-Volume-1-by-Gail-Simone.pdf
    • http://cefasfese.4pu.com/1735731736730732/Even-Villains-Fall-In-Love-Heroes-and-Villains-1-by-Liana-Brooks.pdf
    • http://cefasfese.4pu.com/2739731730731735/Even-Villains-Have-Interns-Heroes-and-Villains-3-by-Liana-Brooks.pdf
    • http://cefasfese.4pu.com/3737733735737735/Gen-Volume-1-Best-of-a-Bad-Lot-Gen-Vol-IV-1-by-Gail-Simone.pdf
    • http://cefasfese.4pu.com/1730736737738737739/Simone-Weil-A-Life-by-Simone-P-trement.pdf
    • http://cefasfese.4pu.com/7731734738734738/Elizabeth-Gail-and-Double-Trouble-Elizabeth-Gail-Wind-Rider-Series-11-by-Hilda-Stahl.pdf
    • http://cefasfese.4pu.com/1730731734733733731/United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-1912-Vol-5-of-6-Transcript-of-Record-William-F-Kettenbach-and-George-H-Kester-Plaintiffs-in-Error-Vs-The-United-States-of-America-Defendant-in-Error-Pages-1521-to-1916-Inclusive-by-United-States-Court-of-Appeals.pdf
    • http://cefasfese.4pu.com/1730731734732739737/United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-Vol-7-The-United-States-of-America-Appellant-vs-William-F-Kettenbach-George-H-Kester-Clarence-W-Robnett-William-Dwyer-and-Frank-W-Kettenbach-Appellees-Transcript-of-Record-Pages-by-United-States-Court-of-Appeals.pdf
    • http://cefasfese.4pu.com/1730731734733733730/United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-No-2209-Vol-9-The-United-States-of-America-Appellant-vs-William-F-Kettenbach-George-H-Kester-Clarence-W-Robnett-William-Dwyer-and-Frank-W-Kettenbach-Appellees-Transcript-of-Rec-by-United-States-Court-of-Appeals.pdf
    • http://cefasfese.4pu.com/17357317367