Malicious PDF — malware analysis report

Static analysis result for SHA-256 a15d157c6be0edb1…

MALICIOUS

PDF

20.0 KB Created: 2019-11-28 22:26:03 +00:00 Authoring application: mPDF 5.7
MD5: 3c066d70afd2db707103a3794b20c913 SHA-1: 5df161665e576790a51335e1c7da2163d017d080 SHA-256: a15d157c6be0edb1ad20160fd8a5e0f708b49ddbdaebc617be587edb13d4bf85
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was identified as malicious due to a critical heuristic firing for a PDF SEO link farm. It contains numerous external links, with the first one being http://cefasfese.4pu.com/1731736736737735731/Het-scherp-van-de-snede-de-Nederlandse-literatuur-in-meer-dan-100-polemieken-by-Pierre-Vinken.pdf. This suggests the document's primary purpose is to lure users into clicking these links, potentially leading to further compromise.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731736736737735731/Het-scherp-van-de-snede-de-Nederlandse-literatuur-in-meer-dan-100-polemieken-by-Pierre-Vinken.pdf
    • http://cefasfese.4pu.com/1731736736738739733/Neurobehavioural-Disorders-by-Pierre-Vinken.pdf
    • http://cefasfese.4pu.com/1731736736738738732/Vascular-Diseases-by-Pierre-Vinken.pdf
    • http://cefasfese.4pu.com/1731736736738733739/Injuries-Of-The-Brain-And-Skull-by-Pierre-Vinken.pdf
    • http://cefasfese.4pu.com/1731736736737735739/Handbook-of-Clinical-Neurology-by-Pierre-Vinken.pdf
    • http://cefasfese.4pu.com/1731736736737736739/Systemic-Diseases-Part-I-by-Pierre-Vinken.pdf
    • http://cefasfese.4pu.com/1731736736738738736/Tumours-Of-The-Brain-And-Skull-by-Pierre-Vinken.pdf
    • http://cefasfese.4pu.com/1731736736738732735/System-Disorders-and-Atrophies-by-Pierre-Vinken.pdf
    • http://cefasfese.4pu.com/6733731733736734/Hadnbook-of-Clin-Neurology-by-Pierre-Vinken.pdf
    • http://cefasfese.4pu.com/1731736736738733738/Spinal-Cord-Trauma-by-Pierre-Vinken.pdf
    • http://cefasfese.4pu.com/1731736736738739730/Microbial-Disease-Handbook-of-Clinical-Neurology-Series-by-Pierre-Vinken.pdf
    • http://cefasfese.4pu.com/1731736736737736734/Neuro-Oncology-Part-2-Gliomas-and-Other-Primary-Tumors-of-the-Brain-and-Spinal-Cord-by-Pierre-Vinken.pdf
    • http://cefasfese.4pu.com/1731736736738739736/Cumulative-Subject-Index-of-Volumes-1-75-Including-Revised-Series-Volumes-1-31-Part-1-A-E-by-Pierre-Vinken.pdf
    • http://cefasfese.4pu.com/9734739737732731/Saalfelden-Saalfelden-Am-Steinernen-Meer-Steinernes-Meer-Liste-Der-Denkmalgeschutzten-Objekte-in-Saalfelden-Am-Steinernen-Meer-by-Quelle-Wikipedia.pdf
    • http://cefasfese.4pu.com/9735738735731731/Huid-over-sex-klasse-en-literatuur-by-Dorothy-Allison.pdf
    • http://cefasfese.4pu.com/7731731739736739/Nederlandse-Histori-n-In-Het-Kort-by-P-C-Hooft.pdf
    • http://cefasfese.4pu.com/6731733738730/De-Nederlandse-kinderpo-zie-in-1000-en-enige-gedichten-by-Gerrit-Komrij.pdf
    • http://cefasfese.4pu.com/8736738739731734/Hollandsch-Hollywood-de-Nederlandse-speelfilm-in-de-jaren-dertig-by-Ineke-Setz.pdf
    • http://cefasfese.4pu.com/9735738736735736/De-Russische-leeslijst-Essays-over-de-klassieke-Russische-literatuur-by-Alexander-Genis.pdf
    • http://cefasfese.4pu.com/4731733737732732/De-Nederlandse-po-zie-van-de-19de-en-de-20ste-eeuw-in-1000-en-enige-gedichten-by-Gerrit-Komrij.pdf
    • http://cefasfese.4pu.com/67337