Malicious PDF — malware analysis report

Static analysis result for SHA-256 55299b01c1d25c3f…

MALICIOUS

PDF

18.9 KB Created: 2019-04-30 07:46:33 +01:00 Authoring application: mPDF 5.7
MD5: 8a5aca9f367b5b661f03f20b1e3634dd SHA-1: ff11c797981509caa059b4ab17b46c1d095084c5 SHA-256: 55299b01c1d25c3f9bd8eeb5c2feae48d3e4fcd4b86adb1fbca4aea200899ee4
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While most of the extracted URLs are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample, limiting the ability to determine a specific payload or delivery mechanism.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8731738732734735/Audubon-Life-List-Journal-by-National-Audubon-Society.pdf
    • http://cefasfese.4pu.com/8731737739736733/National-Audubon-Society-Field-Guide-to-the-Night-Sky-by-National-Audubon-Society.pdf
    • http://cefasfese.4pu.com/8731738732735735/Audubon-s-Western-Journal-by-John-Woodhouse-Audubon.pdf
    • http://cefasfese.4pu.com/8731738732730736/National-Audubon-Society-Guide-to-Nature-Photography-by-Tim-Fitzharris.pdf
    • http://cefasfese.4pu.com/8731738732734732/National-Audubon-Society-Birder-s-Handbook-by-Stephen-W-Kress.pdf
    • http://cefasfese.4pu.com/8731738731730730/National-Audubon-Society-First-Field-Guide-Insects-by-Christina-Wilsdon.pdf
    • http://cefasfese.4pu.com/8731738731730732/National-Audubon-Society-First-Field-Guide-Mammals-by-John-Grassy.pdf
    • http://cefasfese.4pu.com/8731738732735732/National-Audubon-Society-First-Field-Guide-Reptiles-by-John-L-Behler.pdf
    • http://cefasfese.4pu.com/8731738732734737/National-Audubon-Society-Pocket-Guide-to-Constellations-of-the-Northern-Skies-by-Mark-R-Chartrand.pdf
    • http://cefasfese.4pu.com/8731738730733736/National-Audubon-Society-Field-Guide-to-Weather-North-America-by-David-McWilliams-Ludlum.pdf
    • http://cefasfese.4pu.com/8731732732737738/National-Audubon-Society-Field-Guide-to-North-American-Trees-Eastern-Region-by-Elbert-L-Little.pdf
    • http://cefasfese.4pu.com/8731732734731738/National-Audubon-Society-Field-Guide-to-North-American-Birds-Western-Region-by-Miklos-D-F-Udvardy.pdf
    • http://cefasfese.4pu.com/8731738732735730/National-Audubon-Guide-to-Nature-Photography-by-Tim-Fitzharris.pdf
    • http://cefasfese.4pu.com/8731738732730734/The-Audubon-Society-Field-Guide-to-North-American-Mammals-by-John-O-Whitaker.pdf
    • http://cefasfese.4pu.com/8731732734732738/The-Audubon-Society-Field-Guide-to-North-American-Wildflowers-Eastern-Region-by-William-A-Niering.pdf
    • http://cefasfese.4pu.com/8731738730733730/John-James-Audubon-Writings-and-Drawings-by-John-James-Audubon.pdf
    • http://cefasfese.4pu.com/2739731733733/This-Strange-Wilderness-The-Life-and-Art-of-John-James-Audubon-by-Nancy-Plain.pdf
    • http://cefasfese.4pu.com/8731738730738739/The-Audubon-Quartet-by-Ray-Sipherd.pdf
    • http://cefasfese.4pu.com/8731738732734734/Lucy-Audubon-A-Biography-by-Carolyn-E-Delatte.pdf
    • http://cefasfese.4pu.com/8731738730733731/Birds-of-America-by-John-James-Audubon.pdf