Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1f603a68275202c…

MALICIOUS

PDF

16.0 KB Created: 2019-11-28 22:37:31 +00:00 Authoring application: mPDF 5.7
MD5: ff9e0050d365a1e65059c75d393983a0 SHA-1: 6860b0cb950c03253a5769eea954c1666854135e SHA-256: f1f603a68275202c662c4461a44ff89258e3feec841d588d6eed6b6548d09a6f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links pointing to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. The dominant host for these links is 'cefasfese.4pu.com'. While the document body is unreadable, the structure and heuristics suggest a link-farming or SEO poisoning attack, aiming to drive traffic to potentially malicious or spam content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6733733735734737/All-Aboard-the-Zombie-Express-by-Shantnu-Tiwari.pdf
    • http://cefasfese.4pu.com/1731735730735732733/Achtung-Nazi-Zombies-by-Shantnu-Tiwari.pdf
    • http://cefasfese.4pu.com/7738730736735731/Zombie-Family-Reunion-Diary-of-a-Minecraft-Zombie-7-by-Zack-Zombie.pdf
    • http://cefasfese.4pu.com/8738731731739733/I-Tagged-Her-in-My-Heart-by-Anuj-Tiwari.pdf
    • http://cefasfese.4pu.com/5730738736738/The-Zombie-Rule-Book-A-Zombie-Apocalypse-Survival-Guide-by-Tony-Newton.pdf
    • http://cefasfese.4pu.com/1731734736731735733/The-Rise-and-Fall-of-the-Zombie-Empire-Part-III-King-Zombie-by-Steven-Orlowski.pdf
    • http://cefasfese.4pu.com/9739734730731738/Enter-the-Zombie-Nathan-Abercrombie-Accidental-Zombie-5-by-David-Lubar.pdf
    • http://cefasfese.4pu.com/8730733737735733/Back-to-Scare-School-Diary-of-a-Minecraft-Zombie-8-by-Zack-Zombie.pdf
    • http://cefasfese.4pu.com/1730734735739737731/Zombie-Badge-of-Courage-The-Tale-of-an-Infantryman-Fighting-in-the-American-Zombie-War-by-Jonathan-Biermann.pdf
    • http://cefasfese.4pu.com/2736735/A-Scare-of-a-Dare-Diary-of-a-Minecraft-Zombie-1-by-Zack-Zombie.pdf
    • http://cefasfese.4pu.com/7738730736734738/Creepaway-Camp-Diary-of-a-Minecraft-Zombie-6-by-Zack-Zombie.pdf
    • http://cefasfese.4pu.com/7738730736734736/Bullies-and-Buddies-Diary-of-a-Minecraft-Zombie-2-by-Zack-Zombie.pdf
    • http://cefasfese.4pu.com/7738735735735739/--1-Zombie-From-Now-On-1-Kyo-Kara-Zombie-1-by-Yugo-Ishikawa.pdf
    • http://cefasfese.4pu.com/2733731739731735/Zombie-Cruise-Zombie-Vacations-1-by-Janiera-Eldridge.pdf
    • http://cefasfese.4pu.com/4734739730735735/Zombie-Country-Zombie-Apocalypse-2-by-Samantha-Hoffman.pdf
    • http://cefasfese.4pu.com/3735739735730739/My-Zombie-My-I-Zombie-2-by-Jack-Wallen.pdf
    • http://cefasfese.4pu.com/1730737738734734739/All-Aboard-with-Johanna-by-Kathrin-Sch-rer.pdf
    • http://cefasfese.4pu.com/2732730735734731/Permission-to-Come-Aboard-by-Shayne-McClendon.pdf
    • http://cefasfese.4pu.com/3736731733730735/Zombie-Spring-s-Trooper-Tyree-A-First-Sequel-Zombie-Spring-2-by-Chris-Okusako.pdf
    • http://cefasfese.4pu.com/2737732738738738/Semester-Aboard-More-than-Magic-1-by-Elizabeth-Kirke.pdf
    • http://cefasfese.4pu.com/