Malicious PDF — malware analysis report

Static analysis result for SHA-256 f703fdf63a54e738…

MALICIOUS

PDF

16.8 KB Created: 2019-08-02 07:38:08 +01:00 Authoring application: mPDF 5.7
MD5: 632455a5958dc41e762978640feb3a79 SHA-1: bda4e315b176fefe7c9ee7447be5754adb4d5276 SHA-256: f703fdf63a54e7385ac403abb03508dc1f261d4580422e37d2c3a5f039c4e216
120 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, all hosted on the same domain. This behavior is indicative of a link farm or SEO manipulation tactic, and the ClamAV detection as Pdf.Dropper.Agent-7178644-0 suggests it is used for malicious purposes, likely to distribute further malware or phishing content. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7178644-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7178644-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3730732732736734/Texas-Hold-Em-Hotter-In-Texas-3-by-Christie-Craig.pdf
    • http://cefasfese.4pu.com/1734735735737737/Blame-It-On-Texas-Hotter-In-Texas-2-by-Christie-Craig.pdf
    • http://cefasfese.4pu.com/2730736734736/Texas-Bluff-Texas-Hold-em-5-by-Linda-Warren.pdf
    • http://cefasfese.4pu.com/4733731736735733/Heart-of-Texas-Vol-2-Caroline-s-Child-Dr-Texas-Heart-of-Texas-3-4-by-Debbie-Macomber.pdf
    • http://cefasfese.4pu.com/2735735736733/Texas-Glory-Leigh-Brothers-Texas-Trilogy-2-by-Lorraine-Heath.pdf
    • http://cefasfese.4pu.com/1731733730737736737/Texas-Lucky-Texas-Tyler-Family-Saga-1-by-Sandra-Brown.pdf
    • http://cefasfese.4pu.com/4735739730739731/Texas-Bossa-Nova-Texas-Montgomery-Mavericks-5-by-Cynthia-D-39-Alba.pdf
    • http://cefasfese.4pu.com/4733732739739737/Texas-Destiny-Leigh-Brothers-Texas-Trilogy-1-by-Lorraine-Heath.pdf
    • http://cefasfese.4pu.com/4737738732737/Texas-Lucky-Texas-Tyler-Family-Saga-1-by-Sandra-Brown.pdf
    • http://cefasfese.4pu.com/3733731736731736/Weird-Texas-Your-travel-guide-to-Texas-s-Local-Legends-and-Best-Kept-Secrets-by-Wesley-Treat.pdf
    • http://cefasfese.4pu.com/1735730731738735/Escape-from-Texas-A-Novel-of-Slavery-and-the-Texas-War-of-Independence-by-James-W-Russell.pdf
    • http://cefasfese.4pu.com/1732737732738/Texas-Outlaw-Wild-Texas-Nights-1-by-Adrienne-deWolfe.pdf
    • http://cefasfese.4pu.com/3736734734736734/Texas-Fandango-Texas-Montgomery-Mavericks-3-by-Cynthia-D-39-Alba.pdf
    • http://cefasfese.4pu.com/1734737737731733/Flirting-with-Texas-Deep-in-the-Heart-of-Texas-5-by-Katie-Lane.pdf
    • http://cefasfese.4pu.com/2737738735730735/Texas-Twist-Texas-Soul-3-by-Sara-York.pdf
    • http://cefasfese.4pu.com/1731734735732734731/Texas-Free-The-Tylers-of-Texas-5-by-Janet-Dailey.pdf
    • http://cefasfese.4pu.com/4733733736738734/Texas-True-The-Tylers-of-Texas-1-by-Janet-Dailey.pdf
    • http://cefasfese.4pu.com/4736731736730730/Texas-Legacy-Texas-Soul-6-by-Sara-York.pdf
    • http://cefasfese.4pu.com/2737738735730734/Texas-Branded-Texas-Soul-4-by-Sara-York.pdf
    • http://cefasfese.4pu.com/4736731735737735/Texas-Desire-Texas-Soul-5-by-Sara-York.pdf
    • http://cefasfese.4pu.com/4737738732737/Texas-Lucky-T