Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8d7a05932e75cfc…

MALICIOUS

PDF

15.7 KB Created: 2019-06-04 08:35:42 +01:00 Authoring application: mPDF 5.7
MD5: 540dc4b1a9bda1077bbe5cf6a0e0c34b SHA-1: be8c21a8da6fd3dd81be52f25903a2dc85308d73 SHA-256: e8d7a05932e75cfca50b0395f35b9fa2e2dce56001d372851d4bc8f0f229c365
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles hosted on the 'cefasfese.4pu.com' domain. While the individual URLs are marked as benign, the sheer volume and structure suggest a link farm or redirection scheme, which is a common tactic for SEO manipulation or distributing malicious payloads. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5730730737733736/The-Solitary-Envoy-Heirs-of-Acadia-1-by-T-Davis-Bunn.pdf
    • http://cefasfese.4pu.com/7736730737733732/The-Fragment-by-Davis-Bunn.pdf
    • http://cefasfese.4pu.com/9730734737738/All-Through-the-Night-by-Davis-Bunn.pdf
    • http://cefasfese.4pu.com/4737734735737737/The-Messenger-by-T-Davis-Bunn.pdf
    • http://cefasfese.4pu.com/5737732735730/The-Great-Divide-by-T-Davis-Bunn.pdf
    • http://cefasfese.4pu.com/2733733739734731/The-Domino-Effect-by-Davis-Bunn.pdf
    • http://cefasfese.4pu.com/1730734738734735731/The-Black-Madonna-Storm-Syrrell-2-by-Davis-Bunn.pdf
    • http://cefasfese.4pu.com/1732736734730739/Solitary-Solitary-Tales-1-by-Travis-Thrasher.pdf
    • http://cefasfese.4pu.com/2732734739739731/Solitary-Solitary-1-by-Melissa-Copeland.pdf
    • http://cefasfese.4pu.com/4736730736730739/Acadia-s-Law-Undying-Love-1-by-Tracy-Ellen.pdf
    • http://cefasfese.4pu.com/9734736733736737/HALO-Envoy-by-Tobias-S-Buckell.pdf
    • http://cefasfese.4pu.com/6733732739732/The-Envoy-from-Mirror-City-Autobiography-3-by-Janet-Frame.pdf
    • http://cefasfese.4pu.com/2733733730735739/Sir-William-Hamilton-Envoy-Extraordinary-by-Brian-Fothergill.pdf
    • http://cefasfese.4pu.com/2736735738738730/Acadia-National-Park-Motorists-Guide-Park-Loop-Road-by-Unknown.pdf
    • http://cefasfese.4pu.com/9734739737731/The-Envoy-The-Epic-Rescue-of-the-Last-Jews-of-Europe-in-the-Desperate-Closing-Months-of-World-War-II-by-Alex-Kershaw.pdf
    • http://cefasfese.4pu.com/4730732734733733/The-Envoy-The-Epic-Rescue-of-the-Last-Jews-of-Europe-in-the-Desperate-Closing-Months-of-World-War-II-by-Alex-Kershaw.pdf
    • http://cefasfese.4pu.com/4730737733731/The-Brink-Stories-by-Austin-Bunn.pdf
    • http://cefasfese.4pu.com/2738737739737731/Harrow-County-4-by-Cullen-Bunn.pdf
    • http://cefasfese.4pu.com/2737739739739735/Creeping-Stones-by-Cullen-Bunn.pdf
    • http://cefasfese.4pu.com/1739733731736736/Fearless-Defenders-1-by-Cullen-Bunn.pdf
    • http://cefasfese.4pu.com/27367357387