Malicious PDF — malware analysis report

Static analysis result for SHA-256 540c3ac39b59dc3d…

MALICIOUS

PDF

22.6 KB Created: 2019-05-04 10:24:11 +01:00 Authoring application: mPDF 5.7
MD5: 5f286562bb45ce37b0378e8f4b8c78b1 SHA-1: 5037ffa65aedb717dcad0bfe990dd372af8127bf SHA-256: 540c3ac39b59dc3d57bc9d786a94346dfc137cf7511831202d99465c4f56ac3f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links, identified as a link farm. The primary heuristic indicates this is a critical finding, suggesting the document's purpose is to direct users to a multitude of external resources. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the specific lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4730738737730733/Why-Were-They-Built-Six-Man-Made-Wonders-of-the-World-by-Scott-Hayden.pdf
    • http://cefasfese.4pu.com/2731738732733733/The-Man-Who-Built-the-World-by-Chris-Ward.pdf
    • http://cefasfese.4pu.com/9732730735739/Wonders-of-a-Godless-World-by-Andrew-McGahan.pdf
    • http://cefasfese.4pu.com/3738733731736731/Wonders-of-the-Invisible-World-by-Christopher-Barzak.pdf
    • http://cefasfese.4pu.com/7732730735739/Nothing-Like-It-in-the-World-The-Men-Who-Built-the-Transcontinental-Railroad-1863-69-by-Stephen-E-Ambrose.pdf
    • http://cefasfese.4pu.com/9731730739737/World-of-Wonders-The-Deptford-Trilogy-3-by-Robertson-Davies.pdf
    • http://cefasfese.4pu.com/2737738736733739/American-Ghosts-amp-Old-World-Wonders-by-Angela-Carter.pdf
    • http://cefasfese.4pu.com/9739738735733731/Age-of-Wonders-Exploring-the-World-of-Science-Fiction-by-David-G-Hartwell.pdf
    • http://cefasfese.4pu.com/3733730735731735/Good-Profit-How-Creating-Value-for-Others-Built-One-of-the-World-s-Most-Successful-Companies-by-Charles-G-Koch.pdf
    • http://cefasfese.4pu.com/1730733731732731/The-Box-How-the-Shipping-Container-Made-the-World-Smaller-and-the-World-Economy-Bigger-by-Marc-Levinson.pdf
    • http://cefasfese.4pu.com/2733738735731733/The-Box-How-the-Shipping-Container-Made-the-World-Smaller-and-the-World-Economy-Bigger-by-Marc-Levinson.pdf
    • http://cefasfese.4pu.com/2733738733737732/Sheep-The-Remarkable-Story-Of-The-Humble-Animal-That-Built-The-Modern-World-by-Alan-Butler.pdf
    • http://cefasfese.4pu.com/4730734730/Atlas-Obscura-An-Explorer-s-Guide-to-the-World-s-Hidden-Wonders-by-Joshua-Foer.pdf
    • http://cefasfese.4pu.com/8735732739738731/Small-Wonders-Jean-Henri-Fabre-and-His-World-of-Insects-by-Matthew-Clark-Smith.pdf
    • http://cefasfese.4pu.com/1731731739730738734/The-Wonders-of-the-Ancient-World-Antiquity-s-Greatest-Feats-of-Design-and-Engineering-by-Justin-Pollard.pdf
    • http://cefasfese.4pu.com/4731736737731735/The-Gun-Runner-Mafia-Made-1-by-Scott-Hildreth.pdf
    • http://cefasfese.4pu.com/3739733734739731/The-Book-of-Caddyshack-Everything-You-Ever-Wanted-to-Know-about-the-Greatest-Movie-Ever-Made-by-Scott-Martin.pdf
    • http://cefasfese.4pu.com/4736730735731731/Harry-s-Last-Stand-How-the-World-My-Generation-Built-is-Falling-Down-and-What-We-Can-Do-to-Save-It-by-Harry-Leslie-Smith.pdf
    • http://cefasfese.4pu.com/1733739733735730/The-World-Jones-Made-by-Philip-K-Dick.pdf
    • http://cefasfese.4pu.com/3731737731739737/A-World-Made-of-Fire-by-Mark-Childress.pdf
    • http://cefasfese.4pu.com/3733730735731735/Good-Profit-How-Creating-Value-for-Others-Built-One-of-the-World-s-Most-Successful-Companies