Malicious PDF — malware analysis report

Static analysis result for SHA-256 29bbf838edb0e0de…

MALICIOUS

PDF

25.1 KB Created: 2019-05-02 17:25:01 +01:00 Authoring application: mPDF 5.7
MD5: 5f43f549852cbfe239e87bb608244e5e SHA-1: b98597a13ad827852e63163b22636d90873c405a SHA-256: 29bbf838edb0e0de7d973058c526b8d5b2943589ef28642f8abcf0ebff5ee3f5
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing indicating a link farm, with numerous embedded URLs pointing to external PDF documents. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent to distribute or redirect users. The attack pattern is consistent with SEO poisoning or traffic redirection schemes.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2737731738737732/Theology-of-the-Body-for-Beginners-A-Basic-Introduction-to-Pope-John-Paul-II-s-Sexual-Revolution-by-Christopher-West.pdf
    • http://cefasfese.4pu.com/5730736732736738/Adventures-in-the-Orgasmatron-How-the-Sexual-Revolution-Came-to-America-by-Christopher-Turner.pdf
    • http://cefasfese.4pu.com/1730732735736731734/The-Character-of-Theology-An-Introduction-to-Its-Nature-Task-and-Purpose-by-John-R-Franke.pdf
    • http://cefasfese.4pu.com/3736738734734739/Salvation-Belongs-to-the-Lord-An-Introduction-to-Systematic-Theology-by-John-M-Frame.pdf
    • http://cefasfese.4pu.com/4732733735738737/In-God-s-Name-An-Investigation-into-the-Murder-of-Pope-John-Paul-I-by-David-A-Yallop.pdf
    • http://cefasfese.4pu.com/1731734734736735731/Pope-John-Paul-II-A-Festive-Profile-by-Ludv-k-N-mec.pdf
    • http://cefasfese.4pu.com/1735738737734732/In-God-s-Name-An-Investigation-Into-the-Murder-of-Pope-John-Paul-I-by-David-A-Yallop.pdf
    • http://cefasfese.4pu.com/3733730739733733/Witness-to-Hope-The-Biography-of-Pope-John-Paul-II-by-George-Weigel.pdf
    • http://cefasfese.4pu.com/4739732739735734/Sex-Sexual-Revolution-Discover-Sex-God-Goddess-In-You-Buried-Sex-Secrets-Revealed-For-Your-Personal-Use-Discover-the-Power-of-Sex-sex-secrets-God-Goddess-Sexual-Revolution-Power-of-sex-by-Michelle-M-Denarro.pdf
    • http://cefasfese.4pu.com/7732731739731733/Pope-John-Paul-IIs-Theological-Journey-to-the-Prayer-Meeting-of-Religions-in-Assisi-Part-2-3-by-Johannes-D-rmann.pdf
    • http://cefasfese.4pu.com/1731733739736739738/Basic-Beadwork-for-Beginners-by-Mitsuko-Muto.pdf
    • http://cefasfese.4pu.com/7739738736739737/Mozambique-Memoirs-of-a-Revolution-by-John-Paul.pdf
    • http://cefasfese.4pu.com/7735732734739737/The-First-and-Second-Missionary-Journey-of-Pope-John-Paul-II-to-Nigeria-The-Beatification-of-Father-Cyprian-Michael-Iwene-Tansi-March-22-1998-by-S-Iniobong-Udoidem.pdf
    • http://cefasfese.4pu.com/6732733736731737/Christian-Theology-An-Introduction-by-Alister-E-McGrath.pdf
    • http://cefasfese.4pu.com/6732738731739734/Radical-Love-An-Introduction-to-Queer-Theology-by-Patrick-S-Cheng.pdf
    • http://cefasfese.4pu.com/1731734731732737733/Introduction-to-the-Theology-of-Karl-Barth-by-Geoffrey-William-Bromiley.pdf
    • http://cefasfese.4pu.com/5735735734734739/Kinship-An-Introduction-to-the-Basic-Concepts-by-Robert-Parkin.pdf
    • http://cefasfese.4pu.com/1730737738734735731/The-Practice-of-Communicative-Theology-An-Introduction-to-a-New-Theological-Culture-by-Matthias-Scharer.pdf
    • http://cefasfese.4pu.com/8739733735738735/The-Great-Passion-An-Introduction-to-Karl-Barth-s-Theology-by-Eberhard-Busch.pdf
    • http://cefasfese.4pu.com/6731738734738/Basic-Writings-Ten-Key-Essays-plus-the-Introduction-to-Being-and-Time-by-Martin-Heidegger.pdf
    • http://cefasfese.4pu.com/1731734734736735731/Pope-John-Paul-II-A-Festive-Profile-by-Lud