Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1236ffeeeb10a62…

MALICIOUS

PDF

22.1 KB Created: 2019-05-03 06:26:09 +01:00 Authoring application: mPDF 5.7
MD5: 945b1e6f18175c12b922b9639c628e49 SHA-1: 733970d7e4653570bb90c38f2e1c45ec7387d912 SHA-256: f1236ffeeeb10a62e00cd7a6ec97a986a3fdcb5d86b4fe248ef3786d98f9242e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified as a link farm. While most of the linked URLs were confirmed benign, the heuristic 'PDF_SEO_LINK_FARM' indicates a malicious intent to generate traffic or potentially lead users to malicious content. The document body is heavily obfuscated, preventing a clear understanding of its direct purpose beyond the link farm.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4732731730738737/A-Century-of-Great-Western-Stories-An-Anthology-of-Western-Fiction-by-John-Jakes.pdf
    • http://cefasfese.4pu.com/7736738731733739/Gunfight-At-Benson-s-Creek-The-Creek-Battle-A-Western-Adventure-The-Blood-on-the-Plains-Western-Series-Book-2-by-John-D-Fie-Jr-.pdf
    • http://cefasfese.4pu.com/2739737736736730/The-Western-Literary-Canon-in-Context-by-John-M-Bowers.pdf
    • http://cefasfese.4pu.com/1730737735733735736/Die-gro-en-Western-122-T-te-ihn-zweimal-by-John-Gray.pdf
    • http://cefasfese.4pu.com/6730735738733735/Yellowstone-A-John-Cutler-Western-Book-6-by-H-V-Elkin.pdf
    • http://cefasfese.4pu.com/3733731738737739/The-Wheel-of-Life-The-Autobiography-of-a-Western-Buddhist-by-John-Blofeld.pdf
    • http://cefasfese.4pu.com/1732734732731735/Outin-Inner-Movement-2-by-Brandt-Legg.pdf
    • http://cefasfese.4pu.com/7730737732738/Outview-Inner-Movement-1-by-Brandt-Legg.pdf
    • http://cefasfese.4pu.com/2739738733734/Line-in-the-Sand-A-History-of-the-Western-U-S--Mexico-Border-by-Rachel-St-John.pdf
    • http://cefasfese.4pu.com/1737737735737734/Outview-The-Inner-Movement-Book-1-by-Brandt-Legg.pdf
    • http://cefasfese.4pu.com/8735731735736732/Outview-The-Inner-Movement-Book-1-by-Brandt-Legg.pdf
    • http://cefasfese.4pu.com/3737735737736739/The-Secret-War-Against-the-Jews-How-Western-Espionage-Betrayed-The-Jewish-People-by-John-Loftus.pdf
    • http://cefasfese.4pu.com/1739737734734734/Mountain-Masters-Slavery-and-the-Sectional-Crisis-in-Western-North-Carolina-by-John-C-Inscoe.pdf
    • http://cefasfese.4pu.com/1731736738737734737/Feeding-Mars-Logistics-In-Western-Warfare-From-The-Middle-Ages-To-The-Present-by-John-A-Lynn.pdf
    • http://cefasfese.4pu.com/2732730731739/Christianity-Social-Tolerance-and-Homosexuality-Gay-People-in-Western-Europe-from-the-Beginning-of-the-Christian-Era-to-the-Fourteenth-Century-by-John-Boswell.pdf
    • http://cefasfese.4pu.com/2731735730735730/Christianity-Social-Tolerance-and-Homosexuality-Gay-People-in-Western-Europe-from-the-Beginning-of-the-Christian-Era-to-the-Fourteenth-Century-by-John-Boswell.pdf
    • http://cefasfese.4pu.com/9734737732732/Number-One-Bestseller-by-Brian-Morley.pdf
    • http://cefasfese.4pu.com/9734737737737737/Bathyraja-panthera-a-new-species-of-skate-Rajidae-Arhynchobatinae-from-the-western-Aleutian-Islands-and-resurrection-of-the-subgenus-Arctoraja-Ishiyama-by-John-D-McEachran.pdf
    • http://cefasfese.4pu.com/1731737735735731732/Wie-schreibe-ich-einen-Bestseller-Band-II-by-Ha-A-Mehler.pdf
    • http://cefasfese.4pu.com/5734735736739/How-My-Private-Personal-Journal-Became-a-Bestseller-by-Julia-DeVillers.pdf
    • http://cefasfese.4pu.com/7730737732738/Outview-Inner-Movement-1-by-B