Malicious PDF — malware analysis report

Static analysis result for SHA-256 f5c0b59eee7f2b60…

MALICIOUS

PDF

15.3 KB Created: 2019-05-03 17:12:25 +01:00 Authoring application: mPDF 5.7
MD5: 45a34398ab6059dbc28cc1b76f662e0b SHA-1: 661144f7a5347a8b903a8f3803b3675eb98d81e6 SHA-256: f5c0b59eee7f2b607647ad45d48c5153964fe36770b90bf0448edeecdae49706
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a heuristic firing for PDF_SEO_LINK_FARM, indicating a large number of embedded links. The document body is heavily obfuscated and unreadable, but the embedded links point to various PDF files hosted on the same domain. This suggests the primary purpose is to generate traffic or manipulate search engine results, rather than delivering a direct payload.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2734736730734734/Simon-s-Lady-by-Julie-Tetel-Andresen.pdf
    • http://cefasfese.4pu.com/2734733732739739/The-Blue-Hour-Timeslip-1-by-Julie-Tetel-Andresen.pdf
    • http://cefasfese.4pu.com/1731732732738739732/Sweet-Sensations-by-Adrienne-Basso.pdf
    • http://cefasfese.4pu.com/1737731739735736/Sensations-Assignment-1-by-K-B-Gardener.pdf
    • http://cefasfese.4pu.com/1731732732738738735/Sensations-by-Tessie-Bradford.pdf
    • http://cefasfese.4pu.com/1731732732738738736/Sensations-by-Jessica-March.pdf
    • http://cefasfese.4pu.com/2738738733739737/Sarah-s-Needs-Sensations-2-by-Fiona-Thrust.pdf
    • http://cefasfese.4pu.com/2738738735731739/Forbidden-Affair-Sensations-4-by-Fiona-Thrust.pdf
    • http://cefasfese.4pu.com/3735736733731737/The-Sweetest-Scent-Senses-and-Sensations-4-by-Susan-Laine.pdf
    • http://cefasfese.4pu.com/2735737737739736/Germaine-Dulac-A-Cinema-of-Sensations-by-Tami-Williams.pdf
    • http://cefasfese.4pu.com/1731732732738730736/Super-Normal-Sensations-of-the-Ordinary-by-Naoto-Fukasawa.pdf
    • http://cefasfese.4pu.com/2737737737731730/Sounds-of-Love-Senses-and-Sensations-1-by-Susan-Laine.pdf
    • http://cefasfese.4pu.com/2732735730733734/Sweet-Cowboy-Christmas-Sweet-Texas-3-5-by-Candis-Terry.pdf
    • http://cefasfese.4pu.com/5731738733739/Summer-s-Sweet-Embrace-A-Sweet-Romance-Anthology-by-Kim-Strattford.pdf
    • http://cefasfese.4pu.com/1733735735737733/Meet-Julie-American-Girls-Julie-1-by-Megan-McDonald.pdf
    • http://cefasfese.4pu.com/1734732735737730/Julie-and-the-Eagles-American-Girls-Julie-4-by-Megan-McDonald.pdf
    • http://cefasfese.4pu.com/4733738736739730/Sweet-Encore-A-Road-Trip-from-Paris-to-Portugal-via-northern-Spain-Tout-Sweet-Book-4-by-Karen-Wheeler.pdf
    • http://cefasfese.4pu.com/3734735736739734/Sweet-Temptation-The-Sweet-Trilogy-4-by-Wendy-Higgins.pdf
    • http://cefasfese.4pu.com/3733738734731736/Sweet-Reckoning-The-Sweet-Trilogy-3-by-Wendy-Higgins.pdf
    • http://cefasfese.4pu.com/2731737732737730/Sweet-Tea-at-Sunrise-The-Sweet-Magnolias-6-by-Sherryl-Woods.pdf
    • http://cefasfese.4pu.com/2732735730733734/Sweet-Cowboy-Christmas-S