Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d29e7400bc4b089…

MALICIOUS

PDF

15.8 KB Created: 2019-05-02 18:52:13 +01:00 Authoring application: mPDF 5.7
MD5: 479104c30c7e8506439bca2027c66ff6 SHA-1: 4d03f1fdee925acc562e09cfa120077368c4252a SHA-256: 9d29e7400bc4b089ada22dab3fcb6abd6ec77620aa9373c617db35f80d61a596
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are marked as benign, the sheer volume and structure suggest a link farm or a method to distribute potentially malicious content disguised as legitimate documents. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the direct intent.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6733732732739736/Rose-Point-Her-Instruments-2-by-M-C-A-Hogarth.pdf
    • http://cefasfese.4pu.com/6731736735734730/The-Arcane-Eye-of-Hogarth-by-Burne-Hogarth.pdf
    • http://cefasfese.4pu.com/5739733731735735/The-Mortal-Instruments-Mortal-Instruments-1-3-by-Cassandra-Clare.pdf
    • http://cefasfese.4pu.com/1737732732739736/Reckless-Point-Cross-Point-Village-1-by-Cora-Brent.pdf
    • http://cefasfese.4pu.com/2733734730734732/Counter-Point-Heath-s-Point-Suspense-1-by-Marji-Laine.pdf
    • http://cefasfese.4pu.com/2731734732735733/The-Worth-of-a-Shell-by-M-C-A-Hogarth.pdf
    • http://cefasfese.4pu.com/5737736737739/Point-of-No-Return-Turning-Point-1-by-N-R-Walker.pdf
    • http://cefasfese.4pu.com/3739733738730734/Point-of-No-Return-Turning-Point-1-by-N-R-Walker.pdf
    • http://cefasfese.4pu.com/2735733739730739/Mr-Hogarth-s-Will-by-Catherine-Helen-Spence.pdf
    • http://cefasfese.4pu.com/2732736735730733/Educating-Intuition-by-Robin-M-Hogarth.pdf
    • http://cefasfese.4pu.com/5731733739734734/The-Other-Hogarth-Aesthetics-of-Difference-by-Bernadette-Fort.pdf
    • http://cefasfese.4pu.com/6737736737731731/Le-portrait-sans-peine-by-Burne-Hogarth.pdf
    • http://cefasfese.4pu.com/2730739739735738/Drawing-Dynamic-Hands-by-Burne-Hogarth.pdf
    • http://cefasfese.4pu.com/1730735738733731/Cantor-for-Pearls-Twin-Kingdoms-Romances-2-by-M-C-A-Hogarth.pdf
    • http://cefasfese.4pu.com/5735735738738738/Wrecked-Under-the-Green-Point-Light-The-Background-to-the-Green-and-Mouille-Point-Lights-and-Stories-of-Six-Shipwrecks-in-the-Area-by-John-T-Dimond.pdf
    • http://cefasfese.4pu.com/1730735737732738735/Insights-in-Decision-Making-A-Tribute-to-Hillel-J-Einhorn-by-Robin-M-Hogarth.pdf
    • http://cefasfese.4pu.com/2734732733730/The-Origins-of-Comics-From-William-Hogarth-to-Winsor-McCay-by-Thierry-Smolderen.pdf
    • http://cefasfese.4pu.com/1732736737731730/Extinction-Point-Extinction-Point-1-by-Paul-Antony-Jones.pdf
    • http://cefasfese.4pu.com/1731733736737/Snowfall-on-Haven-Point-Haven-Point-5-by-RaeAnne-Thayne.pdf
    • http://cefasfese.4pu.com/5732732735730737/The-People-Instruments-by-Amy-King.pdf
    • http://cefasfese.4pu.com/2730739739735738/Drawing-Dynamic-Hands-by-Burne-