Malicious PDF — malware analysis report

Static analysis result for SHA-256 f287b21e8e2d2b42…

MALICIOUS

PDF

22.1 KB Created: 2019-05-05 13:26:58 +01:00 Authoring application: mPDF 5.7
MD5: 7947be06030d06b96e05bf5d2174878d SHA-1: 8295c1e2f11f793c0145d830630877dcad342d8f SHA-256: f287b21e8e2d2b42df438563f3353e6552b3f5ae4b07701f904365dbcd651164
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1566.002 Spearphishing Link

The PDF contains a large number of embedded links to external PDF files, hosted on the domain 'cefasfese.4pu.com'. This pattern is indicative of SEO poisoning or a link farm designed to drive traffic to potentially malicious or unwanted content. No scripts were extracted, and the document body primarily consists of obfuscated data and URLs.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731735738732739730/Kindle-User-s-Guide-by-Amazon.pdf
    • http://cefasfese.4pu.com/5732733734732732/Kindle-Voyage-User-s-Guide-by-Amazon.pdf
    • http://cefasfese.4pu.com/1731738731733733737/Amazon-Echo-Amazon-Echo-Advanced-User-Guide-2016-Updated-Echo-Amazon-Echo-User-Manual-Amazon-Alexa-Amazon-Echo-Dot-Amazon-Echo-ebook-by-Jamy-Jackson.pdf
    • http://cefasfese.4pu.com/1731738731733738732/Kindle-Fire-HD-User-Manual-Newbie-to-Expert-in-60-Mins-kindle-fire-kindle-fire-hd-8-kindle-fire-manual-kindle-fire-manual-user-guide-Book-4-by-Jamy-Jackson.pdf
    • http://cefasfese.4pu.com/9730731731739737/Kindle-Publishing-Guide-How-To-Rank-Your-Kindle-Book-1-On-Amazon-In-30-Days-Or-Less-by-Romy-Banciu.pdf
    • http://cefasfese.4pu.com/3737735733731730/The-Kindle-Publishing-Bible-How-to-Sell-More-Kindle-eBooks-on-Amazon-by-Tom-Corson-Knowles.pdf
    • http://cefasfese.4pu.com/2735735730733733/What-is-Amazon-Prime-The-Complete-Guide-to-the-Amazon-Prime-Membership-by-Lynda-Warwick.pdf
    • http://cefasfese.4pu.com/1731734734732739730/Amazon-Prime-Learn-Everything-About-Amazon-Prime-A-Complete-Guide-by-Ivan-Peretti.pdf
    • http://cefasfese.4pu.com/1731733738736730735/HOW-TO-DELETE-BOOKS-FROM-MY-KINDLE-DEVICE-Step-by-Step-Guide-to-Delete-Books-from-Your-Kindle-in-Minutes-by-Felix-Joseph.pdf
    • http://cefasfese.4pu.com/4735732738736736/Love-A-User-s-Guide-by-Clare-Naylor.pdf
    • http://cefasfese.4pu.com/1730730734731/Economics-The-User-s-Guide-by-Ha-Joon-Chang.pdf
    • http://cefasfese.4pu.com/2737731736734738/You-Are-Here-A-User-s-Guide-to-the-Universe-by-Richard-Farr.pdf
    • http://cefasfese.4pu.com/3736736731738730/The-Elements-of-User-Experience-User-Centered-Design-for-the-Web-Voices-by-Jesse-James-Garrett.pdf
    • http://cefasfese.4pu.com/9739730732732738/A-User-s-Guide-to-the-Millennium-Essays-and-Reviews-by-J-G-Ballard.pdf
    • http://cefasfese.4pu.com/9730730739734738/The-User-s-Guide-to-Spiritual-Teachers-by-Scott-Edelstein.pdf
    • http://cefasfese.4pu.com/3739734739731733/Men-Love-amp-Sex-The-Complete-User-s-Guide-for-Women-by-David-Zinczenko.pdf
    • http://cefasfese.4pu.com/1731733739737733739/A-Practical-Guide-to-Strategic-User-Experience-by-Leisa-Reichelt.pdf
    • http://cefasfese.4pu.com/6733737730731732/Dust-and-Fume-Control-A-User-Guide-by-Gulf-Publishing-Co.pdf
    • http://cefasfese.4pu.com/8732737731730733/Earth-User-s-Guide-to-Teaching-Permaculture-by-Rosemary-Morrow.pdf
    • http://cefasfese.4pu.com/2735735738735739/Economics-The-User-s-Guide-A-Pelican-Introduction-by-Ha-Joon-Chang.pdf
    • http://cefasfese.4pu.com/3737735733731730/The-Kindle-Publishing-Bible-How