Malicious PDF — malware analysis report

Static analysis result for SHA-256 a8d7e3c397ad7ee2…

MALICIOUS

PDF

20.0 KB Created: 2019-05-02 06:46:46 +01:00 Authoring application: mPDF 5.7
MD5: 8260443ea6ab906a2efc15a6f5086490 SHA-1: 2d3b3a7b61ad03ee361f5691c08d5fd67fca5557 SHA-256: a8d7e3c397ad7ee25cc4362866ca10b23671bdda3abc470f30fd85362404be53
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, as indicated by the PDF_SEO_LINK_FARM heuristic. These URLs likely serve as a lure to direct users to malicious websites. No scripts were extracted from this sample, and the document body was heavily obfuscated, preventing a deeper analysis of the specific content's intent. The primary attack pattern observed is the mass distribution of external links.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730735733733738734/-Beyond-Band-of-Brothers-The-War-Memoirs-of-Major-Dick-Winters-BEYOND-BAND-OF-BROTHERS-THE-WAR-MEMOIRS-OF-MAJOR-DICK-WINTERS-By-Winters-Dick-Author-May-01-2008-Paperback-by-Dick-Winters.pdf
    • http://cefasfese.4pu.com/1739732730738734/Biggest-Brother-The-Life-of-Major-Dick-Winters-the-Man-Who-Led-the-Band-of-Brothers-by-Larry-Alexander.pdf
    • http://cefasfese.4pu.com/5730733730731/2000-Years-of-Dick-Fiction-by-Dick-Ward.pdf
    • http://cefasfese.4pu.com/7732734737736739/Memoirs-of-Dick-The-Little-Poney-by-Anonymous.pdf
    • http://cefasfese.4pu.com/7732734737735733/Memoirs-of-Dick-The-Little-Poney-by-Benjamin-Tabart.pdf
    • http://cefasfese.4pu.com/4730732736736735/The-Collected-Stories-of-Philip-K-Dick-Volume-4-Minority-Report-by-Philip-K-Dick.pdf
    • http://cefasfese.4pu.com/3738731737738739/The-Collected-Stories-of-Philip-K-Dick-Volume-3-The-Father-Thing-by-Philip-K-Dick.pdf
    • http://cefasfese.4pu.com/1730731730733732739/Blade-Runner-Ubik-Marsianischer-Zeitsturz-3-Romane-in-einem-Band-by-Philip-K-Dick.pdf
    • http://cefasfese.4pu.com/7732730734736731/Dick-Francis-Omnibus-Forfeit-Risk-and-Reflex-by-Dick-Francis.pdf
    • http://cefasfese.4pu.com/1733738737735735/The-Collected-Stories-of-Philip-K-Dick-2-We-Can-Remember-it-for-You-Wholesale-by-Philip-K-Dick.pdf
    • http://cefasfese.4pu.com/5731736734739731/The-Most-Defining-Moments-in-Black-History-According-to-Dick-Gregory-by-Dick-Gregory.pdf
    • http://cefasfese.4pu.com/4737732734735/The-Collected-Stories-of-Philip-K-Dick-4-The-Minority-Report-by-Philip-K-Dick.pdf
    • http://cefasfese.4pu.com/5736737739731733/Philip-K-Dick-s-Electric-Dreams-by-Philip-K-Dick.pdf
    • http://cefasfese.4pu.com/4736735735733738/Dick-Francis-4-Comp-Nov-Jkt-by-Dick-Francis.pdf
    • http://cefasfese.4pu.com/1730733736737733/The-Wish-The-Wish-1-by-Eden-Winters.pdf
    • http://cefasfese.4pu.com/4733734733736733/The-Wish-The-Wish-1-by-Eden-Winters.pdf
    • http://cefasfese.4pu.com/3737733730738/In-the-Shadow-of-Blackbirds-by-Cat-Winters.pdf
    • http://cefasfese.4pu.com/9739734730737/I-Am-a-Truck-by-Michelle-Winters.pdf
    • http://cefasfese.4pu.com/4735739738735730/Starting-Over-by-Sara-Winters.pdf
    • http://cefasfese.4pu.com/2737732739732736/Destroyed-by-Pepper-Winters.pdf