Malicious PDF — malware analysis report

Static analysis result for SHA-256 b3834722f92222ad…

MALICIOUS

PDF

31.2 KB Created: 2019-05-03 20:06:29 +01:00 Authoring application: mPDF 5.7
MD5: 739500147440022805527b24683a3911 SHA-1: 3212a32d8f359ce9e1add9db505d319353a7aef9 SHA-256: b3834722f92222adbe141ec8536512b153293afbff9d80640744d9a736ed358c
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document was flagged for containing a large number of external links, a common technique for SEO poisoning or directing users to malicious sites. While no scripts were extracted, the heuristic 'PDF_SEO_LINK_FARM' strongly suggests a malicious intent to lure users through a link farm. The embedded URLs, although marked as benign in isolation, are part of this larger suspicious structure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5738731735731732/Corpus-Based-Approaches-to-Contrastive-Linguistics-and-Translation-Studies-by-Sylviane-Granger.pdf
    • http://cefasfese.4pu.com/9731731731734735/Schiller-s-quot-On-Grace-and-Dignity-quot-in-Its-Cultural-Context-Essays-and-a-New-Translation-Studies-in-German-Literature-Linguistics-and-Culture-by-Christophe-Fricker.pdf
    • http://cefasfese.4pu.com/6736738739738737/Perspectives-on-Teaching-and-Researching-Translation-Case-studies-in-Translation-and-Translation-Pedagogy-by-Antar-Abdellah.pdf
    • http://cefasfese.4pu.com/5738731735731730/Electronic-Lexicography-by-Sylviane-Granger.pdf
    • http://cefasfese.4pu.com/5738731736730734/eLexicography-in-the-21st-century-New-challenges-new-applications-by-Sylviane-Granger.pdf
    • http://cefasfese.4pu.com/5738731734737734/Taste-for-Corpora-A-in-Honour-of-Sylviane-Granger-by-Fanny-Meunier.pdf
    • http://cefasfese.4pu.com/9739735735733738/Corpus-Linguistics-by-Tony-McEnery.pdf
    • http://cefasfese.4pu.com/9739735737739731/An-Introduction-to-Corpus-Linguistics-by-Graeme-D-Kennedy.pdf
    • http://cefasfese.4pu.com/9739735737732735/English-Corpus-Linguistics-An-Introduction-by-Charles-F-Meyer.pdf
    • http://cefasfese.4pu.com/1730733734739734731/Theological-Encounters-at-a-Crossroads-An-Edition-and-Translation-of-Judah-Hadassi-s-Eshkol-Ha-Kofer-First-Commandment-and-Studies-of-the-Book-s-Judaeo-Arabic-and-Byzantine-Contexts-Karaite-Texts-and-Studies-Volume-11-by-Daniel-Lasker.pdf
    • http://cefasfese.4pu.com/1731733738733730736/Expressionist-Film----New-Perspectives-Studies-in-German-Literature-Linguistics-and-Culture-by-Dietrich-Scheunemann.pdf
    • http://cefasfese.4pu.com/6731736733733731/Polysemy-Flexible-Patterns-of-Meaning-in-Mind-and-Language-Trends-in-Linguistics-Studies-and-Monographs-TiLSM-by-Brigitte-Nerlich.pdf
    • http://cefasfese.4pu.com/9730732731730734/Hector-Und-Achill-Die-Rezeption-Des-Trojastoffes-Im-Deutschen-Mittelalter-Personenbild-Und-Struktureller-Wandel-Utah-Studies-In-Literature-And-Linguistics-by-Gerhard-Peter-Knapp.pdf
    • http://cefasfese.4pu.com/5737737730734732/The-Trial-A-New-Translation-Based-on-the-Restored-Text-by-Franz-Kafka.pdf
    • http://cefasfese.4pu.com/9739735736731739/Corpus-Corpus-John-Bogdanovic-3-by-H-Paul-Jeffers.pdf
    • http://cefasfese.4pu.com/4730732730730732/Tales-From-The-Vienna-Woods-And-Other-Plays-Studies-In-Austrian-Literature-Culture-And-Thought-Translation-Series-by-d-n-von-Horv-th.pdf
    • http://cefasfese.4pu.com/6735736733733731/Current-Progress-in-Historical-Linguistics-Proceedings-of-the-Second-International-Conference-on-Historical-Linguistics-Tucson-Arizona-12-16-Janua-by-William-M-Christie.pdf
    • http://cefasfese.4pu.com/8730736734738736/Critique-for-What-Cultural-Studies-American-Studies-Left-Studies-by-Joel-Pfister.pdf
    • http://cefasfese.4pu.com/7734732735739732/Case-Studies-in-the-Use-of-Land-Based-Aerial-Forces-in-Maritime-Operations-1939-1990---Battle-of-the-Atlantic-Arctic-Convoys-Dunkirk-Pacific-Repulse-Sinking-Falklands-War-Cold-War-Tanker-War-by-U-S-Government.pdf
    • http://cefasfese.4pu.com/8734731732732738/Decolonizing-Translation-Francophone-African-Novels-in-English-Translation-by-Kathryn-Batchelor.pdf
    • http://cefasfese.4pu.com/5738731736730734/eLexicography-in-the-21st-century-New-challenges-new-applications-by-Sylvia