Malicious PDF — malware analysis report

Static analysis result for SHA-256 a600a9a4033dd808…

MALICIOUS

PDF

12.5 KB Created: 2019-11-07 16:31:26 +00:00 Authoring application: mPDF 5.7
MD5: 86f630946f90b686a4a748288de378dd SHA-1: 679052bb022857613de654b0426a616459d9ba1f SHA-256: a600a9a4033dd808ae24a11b141f6512f4e3df4799826888fbe25336b8fd4d8d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various book titles hosted on the same domain, suggesting a potential SEO manipulation scheme or a distribution point for further malicious content. No scripts were extracted from this sample, and the document body was heavily corrupted, limiting further analysis of the specific lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4
    • http://cefasfese.4pu.com/8731738739732/Nanny-Ogg-s-Cookbook-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/4736735731738732/Terry-Pratchett-s-Mort-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/1737737738730732/The-Unadulterated-Cat-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/5730735734734732/Nation-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/9738736733736/Dodger-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/4731737732733/Where-s-My-Cow-Discworld-34-5-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/1731738732732739731/Sourcery-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/3732730731736/Nation-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/1731738732731730739/Mort-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/8739735738738/The-Dark-Side-of-the-Sun-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/1735737736736736/The-Fifth-Elephant-Discworld-24-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/8734730732735/Maskerade-Discworld-Novel-18-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/7736736737733735/Buenos-presagios-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/5735737735737/Discworld-Companion-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/1734732733734732/The-Wit-and-Wisdom-of-Discworld-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/4735732731731735/A-Hat-Full-of-Sky-Discworld-32-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/4736735737736733/The-Dark-Side-of-the-Sun-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/5736733736732732/Going-Postal-Discworld-33-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/4737734731734732/Monstrous-Regiment-by-Terry-Pratchett.pdf
    • http://cefasfese.4pu.com/2731735739738733/Mort-Discworld-4-by-Terry-Pratchett.pdf