Malicious PDF — malware analysis report

Static analysis result for SHA-256 8451a2b9cdff3ecc…

MALICIOUS

PDF

17.9 KB Created: 2019-05-03 05:09:18 +01:00 Authoring application: mPDF 5.7
MD5: 7ed3f5f3652aaed2ed346df803144fc1 SHA-1: 51262641ddb6679971f368426bb28f18581e7e70 SHA-256: 8451a2b9cdff3ecc9c44f1386faa6e24e579e13051cc30cbe6d6199f36b858cb
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of links to external PDF documents, all hosted on the domain 'cefasfese.4pu.com'. This pattern is indicative of a link farm or a lure to download further malicious content. While no scripts were extracted, the heuristic 'PDF_SEO_LINK_FARM' strongly suggests a malicious intent to redirect users to potentially harmful resources. The document body itself is heavily corrupted, but the embedded URLs are clearly visible.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5735735737737732/The-Odyssey-of-Homer-Done-Into-English-Verse-by-Homer.pdf
    • http://cefasfese.4pu.com/6733734736731738/The-Odyssey-By-Homer-Illustrated-by-Homer.pdf
    • http://cefasfese.4pu.com/6730737738735732/The-Odyssey-of-Homer-by-Homer.pdf
    • http://cefasfese.4pu.com/1730734730730735732/The-Odyssey-Book-1-12-by-Homer.pdf
    • http://cefasfese.4pu.com/4738730731737737/The-Iliad-amp-The-Odyssey-by-Homer.pdf
    • http://cefasfese.4pu.com/6733736734734739/The-Odyssey-with-Reader-s-Guide-by-Homer.pdf
    • http://cefasfese.4pu.com/6734738735732731/Odyssey-The-Story-of-Odysseus-by-Homer.pdf
    • http://cefasfese.4pu.com/7733738737730733/The-Odyssey-The-Harvard-Classics-22-by-Homer.pdf
    • http://cefasfese.4pu.com/4739736737735737/Ithaca-A-Novel-of-Homer-s-Odyssey-by-Patrick-Dillon.pdf
    • http://cefasfese.4pu.com/5734732737732738/Odyssey-The-Toils-and-Travels-of-Odysseus-by-Homer.pdf
    • http://cefasfese.4pu.com/1732733732737736/Homer-s-Odyssey-A-Fearless-Feline-Tale-or-How-I-Learned-about-Love-and-Life-with-a-Blind-Wonder-Cat-by-Gwen-Cooper.pdf
    • http://cefasfese.4pu.com/1731736739738732734/The-Parallel-English-Greek-Odyssey-With-Dictionary-Definitions-for-Every-Greek-Word-by-Homer.pdf
    • http://cefasfese.4pu.com/6739739734737734/The-Odyssey-or-The-ten-years-wandering-of-Odusseus-after-the-ten-years-siege-of-Troy-Reproduced-in-dramatic-bland-verse-by-Homer.pdf
    • http://cefasfese.4pu.com/3732734738735732/Homer-s-the-quot-Iliad-quot-and-the-quot-Odyssey-quot-A-Biography-A-Book-That-Shook-the-World-by-Alberto-Manguel.pdf
    • http://cefasfese.4pu.com/9732732733730738/Homer-the-Iliad-Or-Achilles-Wrath-at-the-Siege-of-Ilion-1864-by-Homer.pdf
    • http://cefasfese.4pu.com/5735734734731730/The-Iliad-of-Homer-In-English-Hexameter-Verse-by-Homer.pdf
    • http://cefasfese.4pu.com/5737734731739730/The-Iliad-of-Homer---The-Original-Classic-Edition-by-Homer.pdf
    • http://cefasfese.4pu.com/8733738732731732/The-Iliad-of-Homer-Interlinear-Translation-by-Homer.pdf
    • http://cefasfese.4pu.com/7733736732739/The-Iliad-of-Homer-Vols-1-2-Books-1-24-by-Homer.pdf
    • http://cefasfese.4pu.com/3733739736737732/3001-The-Final-Odyssey-Space-Odyssey-4-by-Arthur-C-Clarke.pdf
    • http://cefasfese.4pu.com/1732733732737736/Homer-s-Odyssey-A-Fearless-Feline-Tale-or-How-I-Learned-about-Love-and-Li