Malicious PDF — malware analysis report

Static analysis result for SHA-256 a7317ddf2136976d…

MALICIOUS

PDF

18.5 KB Created: 2019-11-07 21:18:17 +00:00 Authoring application: mPDF 5.7
MD5: 61fa99be4e0ee84cfccf1f5adab1f4ed SHA-1: 22ad478709923dcb04927d1b9832cbc90232611a SHA-256: a7317ddf2136976d7be706fa7533dad4e92179f38666c8851de2afa1f81c9638
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample, limiting the ability to determine specific payload delivery mechanisms.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8733733730732730/Horace-s-Hope-What-Works-for-the-American-High-School-by-Theodore-R-Sizer.pdf
    • http://cefasfese.4pu.com/5730734732738732/The-Red-Pencil-Convictions-from-Experience-in-Education-by-Theodore-R-Sizer.pdf
    • http://cefasfese.4pu.com/5730735739733733/I-Have-the-Right-To-A-High-School-Survivor-s-Story-of-Sexual-Assault-Justice-and-Hope-by-Chessy-Prout.pdf
    • http://cefasfese.4pu.com/8733732738738737/The-Works-of-Horace-by-Horace.pdf
    • http://cefasfese.4pu.com/7737730736732736/High-School-Debut-Vol-09-High-School-Debut-9-by-Kazune-Kawahara.pdf
    • http://cefasfese.4pu.com/7737730736732737/High-School-Debut-Vol-10-High-School-Debut-10-by-Kazune-Kawahara.pdf
    • http://cefasfese.4pu.com/2738734737730737/Ouran-High-School-Host-Club-Vol-2-Ouran-High-School-Host-Club-2-by-Bisco-Hatori.pdf
    • http://cefasfese.4pu.com/4731734734735733/Ouran-High-School-Host-Club-Vol-12-Ouran-High-School-Host-Club-12-by-Bisco-Hatori.pdf
    • http://cefasfese.4pu.com/8734736730730733/The-Second-Angela-Brazil-s-Collected-Works-The-Princess-of-the-School-A-Fortunate-Term-and-More-12-Works-The-Schoolgirl-s-Sories-by-Angela-Brazil.pdf
    • http://cefasfese.4pu.com/1730738739738735734/Warwolves-of-the-Iron-Cross-The-Hyenas-of-High-Finance-The-International-Relationships-of-French-and-American-High-Finance-Wehrwolf-Book-3-by-V-K-Clark.pdf
    • http://cefasfese.4pu.com/8733732739738735/Horace-Odes-And-Epodes-by-Horace.pdf
    • http://cefasfese.4pu.com/8733733730731738/Selected-Poems-of-Horace-by-Horace.pdf
    • http://cefasfese.4pu.com/2735739736736730/An-American-Tragedy-by-Theodore-Dreiser.pdf
    • http://cefasfese.4pu.com/2737732735739734/An-American-Tragedy-by-Theodore-Dreiser.pdf
    • http://cefasfese.4pu.com/9734732732732733/Sunday-School-That-Really-Works-by-Jessie-Schut.pdf
    • http://cefasfese.4pu.com/1732737738739733/Surviving-High-School-by-M-Doty.pdf
    • http://cefasfese.4pu.com/1730737732736730/Hip-Hop-High-School-by-Alan-Sitomer.pdf
    • http://cefasfese.4pu.com/1739735735736735/How-to-Win-at-High-School-by-Owen-Matthews.pdf
    • http://cefasfese.4pu.com/7732735734736735/American-Statesmen-Gouverneur-Morris-by-Theodore-Roosevelt.pdf
    • http://cefasfese.4pu.com/1738730736731736/The-Bobbsey-Twins-at-School-by-Laura-Lee-Hope.pdf