Malicious PDF — malware analysis report

Static analysis result for SHA-256 adb3ae4ce11ea9d9…

MALICIOUS

PDF

15.7 KB Created: 2019-05-03 17:54:10 +01:00 Authoring application: mPDF 5.7
MD5: 5c1f42b6e8cb340f280caedb7b221df7 SHA-1: 028ee5e29d1b3ebfe5c2137cf98ee63923620db7 SHA-256: adb3ae4ce11ea9d948822a58923c36ea4f66541a568dd12e8306f55425b7f4f1
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign book titles, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a landing page for further malicious activity. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4737733736739739/The-Famous-Stanley-Kidnapping-Case-Stanley-Family-2-by-Zilpha-Keatley-Snyder.pdf
    • http://cefasfese.4pu.com/2733737739732735/Stanley-Bagshaw-and-the-Short-Sighted-Football-Trainer-Stanley-Bagshaw-Series-by-Bob-Wilson.pdf
    • http://cefasfese.4pu.com/5733730733731738/The-Millennial-Critic-Stanley-Kauffmann-on-Film-1999-2009-by-Stanley-Kauffmann.pdf
    • http://cefasfese.4pu.com/5733730733733733/Forward-Observer-Stanley-Kauffmann-at-the-Cinema-1999-2013-by-Stanley-Kauffmann.pdf
    • http://cefasfese.4pu.com/5733730733730731/The-World-Screened-Stanley-Kauffmann-on-the-Cinema-by-Stanley-Kauffmann.pdf
    • http://cefasfese.4pu.com/2731735733730734/Stanley-Kubrick-s-Clockwork-Orange-by-Stanley-Kubrick.pdf
    • http://cefasfese.4pu.com/7733736730735736/The-Nazi-Conscience-by-Claudia-Koonz.pdf
    • http://cefasfese.4pu.com/7730734735734730/The-Nazi-Hunters-by-Damien-Lewis.pdf
    • http://cefasfese.4pu.com/1731737732732738/Nazi-Goreng-by-Marco-Ferrarese.pdf
    • http://cefasfese.4pu.com/1731735737730731732/Nazi-Propaganda-by-Zbyn-k-A-B-Zeman.pdf
    • http://cefasfese.4pu.com/1738735739736732/Nazi-Cinema-by-Erwin-Leiser.pdf
    • http://cefasfese.4pu.com/4738737730734731/Becoming-Hitler-The-Making-of-a-Nazi-by-Thomas-Weber.pdf
    • http://cefasfese.4pu.com/2739731731732737/Nazi-Literature-in-the-Americas-by-Roberto-Bola-o.pdf
    • http://cefasfese.4pu.com/1731734731734737736/Don-t-Let-Them-See-You-Cry-Overcoming-a-Nazi-Childhood-by-Irmgard-Powell.pdf
    • http://cefasfese.4pu.com/1731735730735732733/Achtung-Nazi-Zombies-by-Shantnu-Tiwari.pdf
    • http://cefasfese.4pu.com/7734734735735732/Quest-Searching-for-Germany-s-Nazi-Past-by-Ib-Melchior.pdf
    • http://cefasfese.4pu.com/1731732735730731735/Secrets-of-the-Last-Nazi-Myles-Munro-1-by-Iain-King.pdf
    • http://cefasfese.4pu.com/4731731730734734/The-Nazi-Invasion-1944-I-Survived-9-by-Lauren-Tarshis.pdf
    • http://cefasfese.4pu.com/6732735739736730/The-Social-Policy-of-Nazi-Germany-by-Claude-W-Guillebaud.pdf
    • http://cefasfese.4pu.com/1735737731733737/Occult-Nazi-Go-Go-Girls-Storm-Tibet-by-A-K-Forest.pdf