Malicious PDF — malware analysis report

Static analysis result for SHA-256 fdc06c6aba64c54d…

MALICIOUS

PDF

17.7 KB Created: 2019-05-03 17:54:45 +01:00 Authoring application: mPDF 5.7
MD5: 86eecfde048f5c161faa2be522cd18a2 SHA-1: 611b1a3f19223fe431056e46467dd164bf79f6a2 SHA-256: fdc06c6aba64c54d339c6d25f294e1642bced9ac163dd37c2ebd440bcad6dd7f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links pointing to external resources, a technique often used for SEO manipulation or to redirect users to malicious sites. While the extracted URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent to distribute or promote content through deceptive means. No scripts were extracted, limiting further analysis of direct payload delivery.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2731739736733733/The-Equals-The-Ones-2-by-Daniel-Sweren-Becker.pdf
    • http://cefasfese.4pu.com/4739733737734732/This-Mean-Disease-Growing-Up-in-the-Shadow-of-My-Mother-s-Anorexia-Nervosa-by-Daniel-Becker.pdf
    • http://cefasfese.4pu.com/2739735734735738/Faust-Among-Equals-by-Tom-Holt.pdf
    • http://cefasfese.4pu.com/4732734739739733/Alliance-of-Equals-by-Sharon-Lee.pdf
    • http://cefasfese.4pu.com/2730735737730735/Geek---Boy-Equals-by-Kish-Knight.pdf
    • http://cefasfese.4pu.com/7732737730733737/Ten-Minus-Nine-Equals-Joanie-by-Clarice-Pont.pdf
    • http://cefasfese.4pu.com/3734734735732730/Alliance-of-Equals-Liaden-Universe-19-by-Sharon-Lee.pdf
    • http://cefasfese.4pu.com/9736734735731730/Dead-Funny-Flying-Dutch-and-Faust-Among-Equals-by-Tom-Holt.pdf
    • http://cefasfese.4pu.com/9730733737736734/The-Ernest-Becker-Reader-by-Ernest-Becker.pdf
    • http://cefasfese.4pu.com/1731733737736734730/Algorithms-Plus-Data-Structures-Equals-Programs-Prentice-Hall-series-in-automatic-computation-by-Niklaus-Wirth.pdf
    • http://cefasfese.4pu.com/9731735736737731/Collected-Plays-Two-Man-equals-Man-The-Elephant-Calf-The-Threepenny-Opera-The-Rise-and-Fall-of-the-City-of-Mahagonny-and-The-Seven-Deadly-Sins-by-Bertolt-Brecht.pdf
    • http://cefasfese.4pu.com/6738731730738739/Posthumous-memoirs-and-pedagogic-philosophical-confessions-by-Daniel-A-o-by-Daniel-A-o.pdf
    • http://cefasfese.4pu.com/2739735734738739/Daniel-and-the-Six-Element-Dragons-Daniel-and-the-Mysteries-2-by-Tamuna-Tsertsvadze.pdf
    • http://cefasfese.4pu.com/1730739731739739/Ecliptica-by-T-G-W-Becker.pdf
    • http://cefasfese.4pu.com/8739732736734736/The-Boxer-by-Jurek-Becker.pdf
    • http://cefasfese.4pu.com/1731736732732732735/Linked-by-Taran-Becker.pdf
    • http://cefasfese.4pu.com/4739736734730735/Outsiders-by-Howard-S-Becker.pdf
    • http://cefasfese.4pu.com/8734739732738739/Scented-Geraniums-by-Jim-Becker.pdf
    • http://cefasfese.4pu.com/3732738738734734/The-Star-Thief-by-Lindsey-Becker.pdf
    • http://cefasfese.4pu.com/3738735733736737/Seven-Little-Rabbits-by-John-Leonard-Becker.pdf