Malicious PDF — malware analysis report

Static analysis result for SHA-256 fa50f34a0bd809f5…

MALICIOUS

PDF

17.0 KB Created: 2019-06-04 14:54:22 +01:00 Authoring application: mPDF 5.7
MD5: 3d0360198d7331f8e39b7b6f88bc60a4 SHA-1: 01b89b8aca84900b27584f47017f0fea83fd4059 SHA-256: fa50f34a0bd809f55e0739e5a51dc88be6ddaca482c0f508a14a37d677a9c860
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles, suggesting a potential SEO spam or content redirection scheme. While the URLs themselves are currently flagged as benign, the sheer volume and the nature of the heuristic indicate a malicious intent to drive traffic or host potentially harmful content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1737733731733732/Phoenix-Rising-Or-How-to-Survive-Your-Life-by-Cynthia-D-Grant.pdf
    • http://cefasfese.4pu.com/9738737732734736/Quiet-Phoenix-An-Introvert-s-Guide-to-Rising-in-Career-amp-Life-by-Prasenjeet-Kumar.pdf
    • http://cefasfese.4pu.com/2735738737736736/I-Will-Survive-Tips-and-Hints-to-Help-You-Survive-in-this-Zombie-Infested-World-Survive-1-by-Dana-Burkey.pdf
    • http://cefasfese.4pu.com/5737736736730/Phoenix-Rising-by-JoLynne-Valerie.pdf
    • http://cefasfese.4pu.com/4735735731733732/Phoenix-Rising-by-Theo-Fenraven.pdf
    • http://cefasfese.4pu.com/3732737737738739/Shatter-Phoenix-Rising-4-by-Joan-Swan.pdf
    • http://cefasfese.4pu.com/3731735738739731/Strongman-Phoenix-Rising-3-by-Denise-Rossetti.pdf
    • http://cefasfese.4pu.com/4737730737738739/Shatter-Phoenix-Rising-4-by-Joan-Swan.pdf
    • http://cefasfese.4pu.com/4739735735737738/Guilty-as-Sin-Phoenix-Rising-4-by-Denise-Rossetti.pdf
    • http://cefasfese.4pu.com/3737732732735731/Paragon-Rising-Curse-of-the-Phoenix-2-by-Dorothy-Dreyer.pdf
    • http://cefasfese.4pu.com/3733738737734738/Phoenix-Rising-A-novel-of-Anne-Boleyn-by-Hunter-S-Jones.pdf
    • http://cefasfese.4pu.com/2738735736737731/Keep-Laughing-by-Cynthia-D-Grant.pdf
    • http://cefasfese.4pu.com/1732731730732736/Big-Time-by-Cynthia-D-Grant.pdf
    • http://cefasfese.4pu.com/2735730736735734/Incendiary-Phoenix-Rising-Rock-Band-2-by-Kathryn-C-Kelly.pdf
    • http://cefasfese.4pu.com/2738735733736738/Joshua-Fortune-by-Cynthia-D-Grant.pdf
    • http://cefasfese.4pu.com/3734734738738732/The-Obsidian-Temple-A-Desert-Rising-Novel-by-Kelley-Grant.pdf
    • http://cefasfese.4pu.com/2732730735730733/Ride-the-Rising-Tide-The-Maxwell-Saga-2-by-Peter-Grant.pdf
    • http://cefasfese.4pu.com/6739738737735731/The-Nearly-Wed-Handbook-How-To-Survive-The-Happiest-Day-Of-Your-Life-by-Dan-Zevin.pdf
    • http://cefasfese.4pu.com/7737734739731739/The-Gaslight-Effect-How-to-Spot-and-Survive-the-Hidden-Manipulation-Others-Use-to-Control-Your-Life-by-Robin-Stern.pdf
    • http://cefasfese.4pu.com/4730731734738733/Phoenix-The-Life-of-Norman-Bethune-by-Sharon-Stewart.pdf
    • http://cefasfese.4pu.com/37377327