Malicious PDF — malware analysis report

Static analysis result for SHA-256 d0141db1eda4fa00…

MALICIOUS

PDF

16.2 KB Created: 2019-08-02 07:36:21 +01:00 Authoring application: mPDF 5.7
MD5: 447c7edbf16cac4b86a79f6767058f71 SHA-1: 7d9ce8018486e655c8a622a85e67eeab99e195a4 SHA-256: d0141db1eda4fa00e914fe6860e5ee4219fc5b7c63715330b9ca7c198d96b9cb
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF document contains a large number of embedded links pointing to external PDF files hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a mechanism to distribute malicious content indirectly. No scripts were extracted, and the document body primarily consists of these links, making it difficult to determine a more specific attack pattern or family. The primary IOCs are the URLs associated with the link farm.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4733733737735739/Complete-Surrender-LaCasse-3-by-Ju-Ephraime.pdf
    • http://cefasfese.4pu.com/4733734731734733/State-of-Ecstasy-LaCasse-1-by-Ju-Ephraime.pdf
    • http://cefasfese.4pu.com/1732735737730733/The-Flies-by-Ju-Ephraime.pdf
    • http://cefasfese.4pu.com/1733734733738735/Surrender-the-Heart-Surrender-to-Destiny-1-by-MaryLu-Tyndall.pdf
    • http://cefasfese.4pu.com/1731735739731730/Surrender-Love-Surrender-Trilogy-1-by-Kayelle-Allen.pdf
    • http://cefasfese.4pu.com/3737736732733735/Weekend-Surrender-The-Surrender-Trilogy-1-by-Lori-King.pdf
    • http://cefasfese.4pu.com/1731733736734734/The-Odor-of-Violet-by-Ju-Ephraime.pdf
    • http://cefasfese.4pu.com/9739733730738/One-Dance-with-a-Stranger-by-Ju-Ephraime.pdf
    • http://cefasfese.4pu.com/7731733733733/Surrender-to-Me-I-Surrender-2-by-Monica-James.pdf
    • http://cefasfese.4pu.com/4732734737738736/Surrender-Surrender-1-by-Melody-Anne.pdf
    • http://cefasfese.4pu.com/1737734731730735/Surrender-to-Me-Surrender-1-by-Alexis-Noelle.pdf
    • http://cefasfese.4pu.com/7731739737733730/Le-Pretre-Et-Ses-Detracteurs-Ou-Le-Pretre-Venge-Une-Troisieme-Mine-by-Zacharie-Lacasse.pdf
    • http://cefasfese.4pu.com/2735733731737732/The-Surrender-Your-Love-Trilogy-Surrender-Your-Love-Conquer-Your-Love-Treasure-Your-Love-by-J-C-Reed.pdf
    • http://cefasfese.4pu.com/1734737738733731/Surrender-Your-Love-Surrender-Your-Love-1-by-J-C-Reed.pdf
    • http://cefasfese.4pu.com/1730733733734/Surrender-Your-Love-Surrender-Your-Love-1-by-J-C-Reed.pdf
    • http://cefasfese.4pu.com/5735735730732/Surrender-by-Roy-Miki.pdf
    • http://cefasfese.4pu.com/1738733731735730/The-Complete-Idiot-s-Guide-to-Vegan-Cooking-Complete-Idiot-s-Guides-by-Beverly-Lynn-Bennett.pdf
    • http://cefasfese.4pu.com/3734734738736736/Surrender-Devine-1-by-D-H-Sidebottom.pdf
    • http://cefasfese.4pu.com/1737730736730738/Mountain-Surrender-by-Mae-Shields.pdf
    • http://cefasfese.4pu.com/1736730736738732/Unconditional-Surrender-by-Cat-Grant.pdf
    • http://cefasfese.4pu.com/2735733731737732/The-Surrender-Your-Love-Trilogy-Surrender-Your-Love-Conquer-Your-Love-Treasure-Your