Malicious PDF — malware analysis report

Static analysis result for SHA-256 f5b7e92a178dc6a5…

MALICIOUS

PDF

16.1 KB Created: 2019-11-08 01:18:18 +00:00 Authoring application: mPDF 5.7
MD5: 54764d4b60390f199608467e1463ff5d SHA-1: 129f87937f590043b00fa42bde490903dc8b7d76 SHA-256: f5b7e92a178dc6a52d3f71473cd61f9302c37babc470bcbe491c1f1567ec9809
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a significant number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While most of these links point to benign content, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO poisoning or to distribute malware. The document body is heavily obfuscated and unreadable, providing no further clues. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3737730733737733/Cold-In-The-Earth-DI-Marjory-Fleming-1-by-Aline-Templeton.pdf
    • http://cefasfese.4pu.com/1730733737736739733/Nasse-Fesseln-Erotische-Stories-by-Aline-Aline.pdf
    • http://cefasfese.4pu.com/1737736735735730/Tales-from-the-23rd-Century-Children-of-Earth-by-Paul-J-Fleming.pdf
    • http://cefasfese.4pu.com/4735734735732731/Tales-from-the-23rd-Century-Children-of-Earth-by-Paul-J-Fleming.pdf
    • http://cefasfese.4pu.com/4739732736733736/Cold-Earth-Shetland-Island-7-by-Ann-Cleeves.pdf
    • http://cefasfese.4pu.com/7730730733738731/Escoffier-Master-Chef-by-Marjory-Bartlett-Sanger.pdf
    • http://cefasfese.4pu.com/8739739735734734/Spaceship-Number-Four-A-Thanksgiving-Story-by-Marjory-Wunsch.pdf
    • http://cefasfese.4pu.com/9739730736734/An-Everglades-Providence-Marjory-Stoneman-Douglas-and-the-American-Environmental-Century-by-Jack-E-Davis.pdf
    • http://cefasfese.4pu.com/1731735730733738/The-War-within-These-Walls-by-Aline-Sax.pdf
    • http://cefasfese.4pu.com/1738736739732/Sex-Smart-by-Aline-P-Zoldbrod.pdf
    • http://cefasfese.4pu.com/3738734735738730/The-Cold-Cold-Ground-Detective-Sean-Duffy-1-by-Adrian-McKinty.pdf
    • http://cefasfese.4pu.com/4738734737739738/The-Cold-Cold-Ground-Detective-Sean-Duffy-1-by-Adrian-McKinty.pdf
    • http://cefasfese.4pu.com/2739735731738731/Love-That-Bunch-by-Aline-Kominsky-Crumb.pdf
    • http://cefasfese.4pu.com/1738734734736734/Eternity-and-a-Day-Desires-of-the-Otherworld-1-by-Aline-Hunter.pdf
    • http://cefasfese.4pu.com/2734730737733736/There-Is-No-Lovely-End-by-Patty-Templeton.pdf
    • http://cefasfese.4pu.com/1732731739733738/Return-to-Me-by-Julia-Templeton.pdf
    • http://cefasfese.4pu.com/1731736732738738735/Jurassic-Earth-2-Prologue-The-Last-Woman-on-Earth-The-Jurassic-Earth-Saga-by-Logan-T-Stark.pdf
    • http://cefasfese.4pu.com/3731738739733734/Cold-Fear-Cold-Justice-4-by-Toni-Anderson.pdf
    • http://cefasfese.4pu.com/2739734735736738/Cold-Blooded-Cold-Justice-9-by-Toni-Anderson.pdf
    • http://cefasfese.4pu.com/4731735738737732/Cold-Blooded-Cold-Justice-9-by-Toni-Anderson.pdf
    • http://cefasfese.4pu.com/9739730736734/An-Everglades-Providence-Marjory-Stoneman-Douglas-and-the-American-Environmental-Century-by-Jack-