Malicious PDF — malware analysis report

Static analysis result for SHA-256 f3b7673acac76626…

MALICIOUS

PDF

18.2 KB Created: 2019-05-03 18:33:46 +01:00 Authoring application: mPDF 5.7
MD5: 85ce7ddd7bec19c8ce07daba610fc705 SHA-1: 76a6a8a4c6aff328d362416d2dca308dd759f1ca SHA-256: f3b7673acac766265d75e5ef58d43dcf39167d2e1b855efc34807e349bd3a34e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to external PDF files hosted on the same domain, suggesting a link farm or SEO poisoning attempt. While the document body is unreadable, the structure and heuristics indicate a malicious intent to distribute or redirect users through a large number of URLs.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8738732737738738/A-Job-For-An-Angel-Schulte-Elaine-L-Ginger-Series-by-Elaine-L-Schulte.pdf
    • http://cefasfese.4pu.com/8738732739737733/Dark-Shattering-The-Ella-Reynolds-Series-Book-4-by-Liz-Schulte.pdf
    • http://cefasfese.4pu.com/1730738734736735731/Eifelfieber-by-Andreas-J-Schulte.pdf
    • http://cefasfese.4pu.com/8733738738732/The-Best-of-Elaine-Raco-Chase-A-Dream-Come-True-No-Easy-Way-Out-2-Books-in-1-by-Elaine-Raco-Chase.pdf
    • http://cefasfese.4pu.com/1731737730735734732/Gottes-10-Gebote-by-Anton-Schulte.pdf
    • http://cefasfese.4pu.com/3738734731734734/Secrets-The-Guardian-Trilogy-1-by-Liz-Schulte.pdf
    • http://cefasfese.4pu.com/3731739738734733/Strangers-Have-the-Best-Candy-by-Margaret-Meps-Schulte.pdf
    • http://cefasfese.4pu.com/8738732737738735/The-Love-Club-by-Donna-Faulkner-Schulte.pdf
    • http://cefasfese.4pu.com/8738732739737730/Discover-Germany-by-Andrea-Schulte-Peevers.pdf
    • http://cefasfese.4pu.com/1731734737732737736/Mendener-K-pfe-Stadtgeschichte-In-Kurzbiographien-by-Anton-Schulte.pdf
    • http://cefasfese.4pu.com/9735731732738738/Verm-gen-retten-In-Silber-investieren-by-Thorsten-Schulte.pdf
    • http://cefasfese.4pu.com/8738732739738732/Los-Angeles-amp-Southern-California-by-Andrea-Schulte-Peevers.pdf
    • http://cefasfese.4pu.com/1730738734738730733/Gest-ndnis-Ich-t-te-weiter-Gregor-Schulte-2-by-Moe-Teratos.pdf
    • http://cefasfese.4pu.com/8738732736735739/The-Ultimate-Whole-Foods-Instant-Pot-Cookbook-by-Julia-Schulte.pdf
    • http://cefasfese.4pu.com/8738732735735734/Legends-of-Kenpo-Rainer-Schulte-by-Michael-Miller.pdf
    • http://cefasfese.4pu.com/2730736731730732/Weltmacht-durch-die-Hintert-r-Deutsche-Nationalgeschichte-in-der-Diskussion-by-Bernd-F-Schulte.pdf
    • http://cefasfese.4pu.com/8738732737739731/Good-Tidings-The-Guardian-Trilogy-Christmas-Short-Story-Book-6-by-Liz-Schulte.pdf
    • http://cefasfese.4pu.com/8738732737739733/Tantric-Sex-for-Women-A-Guide-for-Lesbian-Bi-Hetero-and-Solo-Lovers-by-Christa-Schulte.pdf
    • http://cefasfese.4pu.com/2730735732736731/Deutsche-Policy-of-Pretention-Der-Abstieg-eines-Kriegerstaates-1871-1914-by-Bernd-F-Schulte.pdf
    • http://cefasfese.4pu.com/8738732735735739/Ollie-Ollie-Hex-n-Free-Easy-Bake-Coven-Book-5-by-Liz-Schulte.pdf
    • http://cefasfese.4pu.com/1731734737732737736/Mendener-K-pfe-Stadtgeschichte