Malicious PDF — malware analysis report

Static analysis result for SHA-256 97cd6ffbe4215db8…

MALICIOUS

PDF

30.8 KB Created: 2019-05-02 06:10:17 +01:00 Authoring application: mPDF 5.7
MD5: 509ea5125aadb6fd745a63bf8be0bd1e SHA-1: 0125ba75dace5bb227984e4c4c45fc565dc37802 SHA-256: 97cd6ffbe4215db87e20102e162246805812adae52212780d0d15963ad285b40
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. While the document body itself is heavily obfuscated, the presence of numerous links suggests a tactic to drive traffic to external resources, potentially for SEO manipulation or to host malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1733738736739736/The-Church-of-Apostles-and-Martyrs-History-of-the-Church-of-Christ-1-by-Henri-Daniel-Rops.pdf
    • http://cefasfese.4pu.com/3736739737738735/The-Primitive-Church-The-Church-in-the-Days-of-the-Apostles-by-D-I-Lanslots.pdf
    • http://cefasfese.4pu.com/1730733737734732732/Teachings-of-Presidents-of-the-Church-Spencer-W-Kimball-by-The-Church-of-Jesus-Christ-of-Latter-day-Saints.pdf
    • http://cefasfese.4pu.com/6730737736731736/The-Church-of-England-Its-Own-Witness-an-Argument-to-Prove-the-Identity-of-the-Church-of-England-with-the-Ancient-British-and-Apostolic-Church-by-Britannicus.pdf
    • http://cefasfese.4pu.com/1730734733731737/A-Collection-of-Sacred-Hymns-for-The-Church-of-Jesus-Christ-of-Latter-day-Saints-by-Community-of-Christ.pdf
    • http://cefasfese.4pu.com/5738731737730738/O-Sing-Unto-the-Lord-A-History-of-English-Church-Music-A-History-of-English-Church-Music-by-Andrew-Gant.pdf
    • http://cefasfese.4pu.com/7730739738733736/The-Manifesto-Church-Records-of-the-Church-in-Brattle-Square-Boston-with-Lists-of-Communicants-Baptisms-Marriages-and-Funerals-1699-1872-by-Church-in-Brattle-Square.pdf
    • http://cefasfese.4pu.com/3736737731733732/The-Splendor-of-the-Church-by-Henri-de-Lubac.pdf
    • http://cefasfese.4pu.com/7730739738734731/The-Manifesto-Church-Records-of-the-Church-in-Brattle-Square-Boston-With-Lists-of-Communicants-Baptisms-Marriages-and-Funerals-1699-1872-by-Church-in-Brattle-Square-Boston.pdf
    • http://cefasfese.4pu.com/9737730736738733/The-Blueprint-of-Christ-s-Church-by-Tad-R-Callister.pdf
    • http://cefasfese.4pu.com/8731739737737732/The-Church-of-Jesus-Christ-On-The-Move-by-Archange-Malonga.pdf
    • http://cefasfese.4pu.com/8730731734738/Children-s-Songbook-by-The-Church-of-Jesus-Christ-of-Latter-day-Saints.pdf
    • http://cefasfese.4pu.com/1734730731735739/Gospel-Principles-by-The-Church-of-Jesus-Christ-of-Latter-day-Saints.pdf
    • http://cefasfese.4pu.com/8735734738738732/Pursuit-of-Excellence-by-The-Church-of-Jesus-Christ-of-Latter-day-Saints.pdf
    • http://cefasfese.4pu.com/3736739735730738/Confessions-of-a-Mega-Church-Pastor-How-I-Discovered-the-Hidden-Treasures-of-the-Catholic-Church-by-Allen-R-Hunt.pdf
    • http://cefasfese.4pu.com/7730739738732735/History-of-the-First-Presbyterian-Church-of-Fort-Scott-Kansas-Together-with-a-Complete-List-of-Communicants-by-K-First-Presbyterian-Church-Fort-Scott.pdf
    • http://cefasfese.4pu.com/3734737735730734/Cult-to-Christ-The-Church-With-No-Name-and-the-Legacy-of-the-Living-Witness-Doctrine-by-Elizabeth-Joy-Coleman.pdf
    • http://cefasfese.4pu.com/3736733739736735/How-the-Body-of-Christ-Talks-Recovering-the-Practice-of-Conversation-in-the-Church-by-C-Christopher-Smith.pdf
    • http://cefasfese.4pu.com/4732731737736/Book-of-Mormon-Doctrine-and-Covenants-Pearl-of-Great-Price-by-The-Church-of-Jesus-Christ-of-Latter-day-Saints.pdf
    • http://cefasfese.4pu.com/8734733732730734/Sermons-on-the-Manifestation-of-the-Son-of-God-With-a-Preface-Addressed-to-Laymen-on-the-Present-Position-of-the-Clergy-of-the-Church-of-England-and-an-Appendix-on-the-Testimony-of-Scripture-and-the-Church-as-to-the-Possibility-of-Paon-in-the-Future-by-J-Llewelyn-Davies.pdf