Malicious PDF — malware analysis report

Static analysis result for SHA-256 f598cd44913ae355…

MALICIOUS

PDF

17.8 KB Created: 2019-05-02 07:29:40 +01:00 Authoring application: mPDF 5.7
MD5: 5a1adc4b358a5c7e0f5566de69c67f33 SHA-1: b76cb9ce1cc942ebea0f0ce3e67df00bf2c82b6b SHA-256: f598cd44913ae355115047f50e05bf3b7c94ee5e23550ab82232337b6e3104a9
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO spam or to distribute further malicious content. No scripts were extracted from this sample, limiting the ability to determine a more specific attack pattern or family.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730737739737736730/M-rderferien-Das-Krimi-Paket-f-r-die-Ferien-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/9734735738736730/Mords-Ostern-Krimi-Paket-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/1731735731739736736/Die-schlesische-Zeitmaschine-Kurz-Krimi-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/1731735733732735731/M-rderisch-Ein-Krimi-Trio-Cassiopeiapress-Thriller-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/8737739733732735/Die-Unsichtbaren-Das-Juwel-der-Elben---Zweites-Buch-Alfred-Bekker-s-Elben-Saga---Neuausgabe-8-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/1730733731737735735/Treffpunkt-H-lle-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/9739736732731739/Ein-Gesch-pf-namens-Oou---Episode-38-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/1731735738737731739/Der-Todesengel-D-monenj-ger-Murphy-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/1731734737736731732/Drachenschiffe-Zwei-Wikinger-Abenteuer-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/8737733737736738/Schwerter-und-G-tter-Die-Saga-von-Edro-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/9739730737731737/Barbaren-Zwei-Fantasy-Abenteuer-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/1730736736734731731/Ragnar-der-Wikinger-4-Das-zerbrochene-Schwert-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/1731735733732735737/Gnadenlos-und-m-rderisch-Vier-Krimis-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/1731730736731734739/M-nsterland-M-rderland-Monsterland-Drei-Krimis-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/8737739732738738/Patricia-Vanhelsing---Das-Juwel-des-D-mons-Cassiopeiapress-Fantasy-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/1731736739737730733/Dreimal-gemordet-Drei-Krimis-Cassiopeiapress-Spannung-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/1731737736737734732/Galaktische-Zuflucht-Mega-Killer-3-German-Edition-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/8737733737736736/John-Sinclair---Folge-1995-D-mon-der-Schwerter-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/1731734734738733735/Zwergenkinder-1-bis-4-Sammelband-mit-vier-Fantasy-Abenteuern-aus-dem-Zwischenland-der-Elben-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/1731730736732730736/MORDrhein-Westfalen-Vier-Krimis-mit-Tatorten-in-NRW---M-nsterland-Sauerland-Niederrhein-by-Alfred-Bekker.pdf
    • http://cefasfese.4pu.com/1731734737736731732/Drachenschiff