Malicious PDF — malware analysis report

Static analysis result for SHA-256 79f90cd502022195…

MALICIOUS

PDF

18.5 KB Created: 2019-05-03 05:05:12 +01:00 Authoring application: mPDF 5.7
MD5: 59685167f7fba636de3a1c7417ca026c SHA-1: ce60f5271c44120a6308ae347dd888a17e395827 SHA-256: 79f90cd50202219522eba334f39bb3eb153ae316f41aa555ebff254f055b891e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, primarily hosted on the domain 'cefasfese.4pu.com'. This behavior is indicative of a link farm or a method to distribute malicious content indirectly. While the document body itself is unreadable due to encoding issues, the heuristic 'PDF_SEO_LINK_FARM' strongly suggests a malicious intent to redirect users to potentially harmful content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730739734733738734/White-Plume-Mountain-Greyhawk-Classics-2-by-Paul-Kidd.pdf
    • http://cefasfese.4pu.com/1730739734734738738/Queen-of-the-Demonweb-Pits-Greyhawk-Classics-5-by-Paul-Kidd.pdf
    • http://cefasfese.4pu.com/1733739736735735/White-Plume-Mountain-by-Lawrence-Schick.pdf
    • http://cefasfese.4pu.com/1730731739732736730/Lilith-by-Paul-Kidd.pdf
    • http://cefasfese.4pu.com/2730735737733738/Effectuators-Horrors-of-the-Night-by-Paul-Kidd.pdf
    • http://cefasfese.4pu.com/3735738737738739/Go-A-Kidd-s-Guide-to-Graphic-Design-by-Chip-Kidd.pdf
    • http://cefasfese.4pu.com/5738738731731738/The-Woman-in-White-The-Original-Classics---Illustrated-by-Wilkie-Collins.pdf
    • http://cefasfese.4pu.com/2739737739730737/Classics-62-Great-Books-from-the-Iliad-to-Midnight-s-Children-by-Jane-Gleeson-White.pdf
    • http://cefasfese.4pu.com/1732730730736732/White-Mountain-by-Sophie-E-Tallis.pdf
    • http://cefasfese.4pu.com/2730734732732736/White-Water-Passion-Montana-Mountain-1-by-Dawn-Luedecke.pdf
    • http://cefasfese.4pu.com/1731734735731737/Tales-from-Gold-Mountain-by-Paul-Yee.pdf
    • http://cefasfese.4pu.com/5730738739731735/Don-t-Let-the-Sun-Step-Over-You-A-White-Mountain-Apache-Family-Life-1860-1975-by-Eva-Tulene-Watt.pdf
    • http://cefasfese.4pu.com/1732731731732731/Siege-at-Hawthorn-Lake-Murder-on-the-Mountain-by-Paul-G-Buckner.pdf
    • http://cefasfese.4pu.com/1736733738734736/Halfway-to-Heaven-My-White-knuckled--and-Knuckleheaded--Quest-for-the-Rocky-Mountain-High-by-Mark-Obmascik.pdf
    • http://cefasfese.4pu.com/1731730734733731732/A-Study-Guide-for-William-Strunk-Jr-E-B-White-s-quot-Elements-of-Style-quot-Nonfiction-Classics-for-Students-by-Cengage-Learning-Gale.pdf
    • http://cefasfese.4pu.com/2738736735732736/Mountain-Mystery-Silver-River-Mystery-1-by-Carr-White.pdf
    • http://cefasfese.4pu.com/3736738734738732/Dispatches-from-the-Fort-Apache-Scout-White-Mountain-and-Cibecue-Apache-History-Through-1881-by-Lori-Davisson.pdf
    • http://cefasfese.4pu.com/7733736733738731/The-Abduction-of-Rupert-Deville-by-Paul-White.pdf
    • http://cefasfese.4pu.com/3733739735737738/The-White-Rose-Murders-Sir-Roger-Shallot-1-by-Paul-Doherty.pdf
    • http://cefasfese.4pu.com/7738738735733731/-poil-et-plume-by-Michel-Larivi-re.pdf
    • http://cefasfese.4pu.com/2730734732732736/White-Water-Passion-Montana-Mountain-1-