Malicious PDF — malware analysis report

Static analysis result for SHA-256 d5d865ef0c1df7ae…

MALICIOUS

PDF

21.0 KB Created: 2019-09-27 13:33:56 +01:00 Authoring application: mPDF 5.7
MD5: 73999a7b11dcea55c0c28446f6363b30 SHA-1: bafde74647faba1ef787c400be4892f65d962e01 SHA-256: d5d865ef0c1df7aef1bb8f4106ca641237630b6b2a04d1de380d307183aeea3f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified as a PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent to manipulate search engine results or direct users to potentially harmful content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7737733737738738/Savage-Anamoly-The-Power-of-Spinoza-s-Metaphysics-and-Politics-by-Antonio-Negri.pdf
    • http://cefasfese.4pu.com/6736735732734731/Art-and-Multitude-Nine-Letters-on-Art-Followed-by-Metamorphoses-Art-and-Immaterial-Labour-by-Antonio-Negri.pdf
    • http://cefasfese.4pu.com/5731738737737/Looking-for-Spinoza-Joy-Sorrow-and-the-Feeling-Brain-by-Ant-nio-R-Dam-sio.pdf
    • http://cefasfese.4pu.com/8731732738736737/Nietzsche-Volumes-3-amp-4-The-Will-to-Power-as-Knowledge-and-as-Metaphysics-amp-Nihilism-by-Martin-Heidegger.pdf
    • http://cefasfese.4pu.com/9735734739739733/The-Savage-Series-Books-1-3-The-Pearl-Savage-The-Savage-Blood-and-The-Savage-Principle-by-Tamara-Rose-Blodgett.pdf
    • http://cefasfese.4pu.com/5735733736733734/SPINOZA-OEUVRES-COMPL-TES---16-OUVRAGES-ET-ANNEXES-BIOGRAPHIQUES-amp-TH-ORIQUES-annot-by-Baruch-Spinoza.pdf
    • http://cefasfese.4pu.com/7737733737733739/The-Essential-Spinoza-Ethics-and-Related-Writings-by-Baruch-Spinoza.pdf
    • http://cefasfese.4pu.com/7737733737738732/Spinoza-s-Short-Treatise-on-God-Man-and-His-Well-Being-by-Baruch-Spinoza.pdf
    • http://cefasfese.4pu.com/9734733730731732/Spinoza-in-der-europ-ischen-Geistesgeschichte-by-Baruch-Spinoza.pdf
    • http://cefasfese.4pu.com/3735738735730735/Antonio-s-Grace-An-Island-s-Plea-for-a-Native-Son-The-Antonio-s-Series-Book-2-by-Yasmin-Tirado-Chiodini.pdf
    • http://cefasfese.4pu.com/2735736732734736/Ritual-Politics-and-Power-by-David-I-Kertzer.pdf
    • http://cefasfese.4pu.com/3734734737732731/Black-Power-The-Politics-of-Liberation-by-Stokely-Carmichael.pdf
    • http://cefasfese.4pu.com/8732732731735739/The-Politics-and-Power-of-Tourism-in-Palestine-by-Rami-Isaac.pdf
    • http://cefasfese.4pu.com/9737738739736739/Politics-and-Guilt-The-Destructive-Power-of-Silence-by-Gesine-Schwan.pdf
    • http://cefasfese.4pu.com/8734730733736735/The-Congressional-Energy-Conspiracy-Money-Power-and-Politics-by-Dan-Rondeau.pdf
    • http://cefasfese.4pu.com/1734733738739730/Soft-Power-The-Means-to-Success-in-World-Politics-by-Joseph-S-Nye-Jr-.pdf
    • http://cefasfese.4pu.com/4739737735730/Portland-People-Politics-and-Power-1851-2001-by-Jewel-Lansing.pdf
    • http://cefasfese.4pu.com/5731739730730730/A-World-of-Homeowners-American-Power-and-the-Politics-of-Housing-Aid-by-Nancy-H-Kwak.pdf
    • http://cefasfese.4pu.com/7739739730735734/Peace-Power-Politics-How-New-Zealand-Became-Nuclear-Free-by-Maire-Leadbeater.pdf
    • http://cefasfese.4pu.com/5730738735733733/Empires-in-World-History-Power-and-the-Politics-of-Difference-by-Jane-Burbank.pdf
    • http://cefasfese.4pu.com/5735733736733734/SPINO