Malicious PDF — malware analysis report

Static analysis result for SHA-256 fa7afe2ae9cee9ff…

MALICIOUS

PDF

18.1 KB Created: 2019-08-02 07:36:30 +01:00 Authoring application: mPDF 5.7
MD5: 5353cf81414e2d05f4c26c23a2772ca1 SHA-1: f02aa0f74a99e1ead8c201f4b82b3cd9b2d24dcb SHA-256: fa7afe2ae9cee9ff455348a97766719d00d9133054839ba121297c97511be79f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated, the presence of numerous links suggests a malicious intent, possibly for SEO manipulation or to distribute further malware. The links themselves point to various historical documents, but their sheer volume and the heuristic firing indicate a non-standard use of the PDF format. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9733739739736736/Roosevelt-and-Hitler-Prelude-to-War-by-Robert-Edwin-Herzstein.pdf
    • http://cefasfese.4pu.com/9733739739737730/Adolf-Hitler-and-the-German-Trauma-1913-1945-An-Interpretation-of-the-Nazi-Phenomenon-by-Robert-Edwin-Herzstein.pdf
    • http://cefasfese.4pu.com/9733739739736733/Herzstein-Im-Wester-Civilization-by-Herzstein.pdf
    • http://cefasfese.4pu.com/3739738730733733/Saving-Italy-The-Race-to-Rescue-a-Nation-s-Treasures-from-the-Nazis-by-Robert-M-Edsel.pdf
    • http://cefasfese.4pu.com/9733739739736732/Der-Herzstein-Band-1-by-Kathi-Wallace.pdf
    • http://cefasfese.4pu.com/4735739731734739/Selected-Poems-of-Edwin-Arlington-Robinson-by-Edwin-Arlington-Robinson.pdf
    • http://cefasfese.4pu.com/1731738735737733733/Nazis-and-the-Cinema-by-Susan-Tegel.pdf
    • http://cefasfese.4pu.com/1730737733733731738/Braunbuch-DDR-Nazis-in-der-DDR-by-Olaf-Kappelt.pdf
    • http://cefasfese.4pu.com/5736730736732739/Siegfried-The-Nazis-Last-Stand-by-Charles-Whiting.pdf
    • http://cefasfese.4pu.com/2735735734730738/The-Nazis-A-Warning-from-History-by-Laurence-Rees.pdf
    • http://cefasfese.4pu.com/1732735734731739/Witnesses-of-War-Children-s-Lives-Under-the-Nazis-by-Nicholas-Stargardt.pdf
    • http://cefasfese.4pu.com/5736733736733736/La-Tristesse-De-Saint-Louis-Swing-Under-The-Nazis-by-Michael-Zwerin.pdf
    • http://cefasfese.4pu.com/9736735734736733/Im-Feuerofen-der-Nazis-Jehovas-Zeugen-in-Heilbronn-by-Michael-Hetzner.pdf
    • http://cefasfese.4pu.com/1730739733735732737/The-Lion-of-M-nster-The-Bishop-Who-Roared-Against-The-Nazis-by-Daniel-Utrecht.pdf
    • http://cefasfese.4pu.com/6730732734737739/Andr-e-s-War-How-One-Young-Woman-Outwitted-the-Nazis-by-Francelle-Bradford-White.pdf
    • http://cefasfese.4pu.com/1730730739736736735/Defying-the-Nazis-The-Story-of-Captain-Wilm-Hosenfeld-by-Herman-Vinke.pdf
    • http://cefasfese.4pu.com/2736737735734735/World-War-II-Behind-Closed-Doors-Stalin-the-Nazis-and-the-West-by-Laurence-Rees.pdf
    • http://cefasfese.4pu.com/1730736737732736739/Nazis-Islamists-and-the-Making-of-the-Modern-Middle-East-by-Barry-Rubin.pdf
    • http://cefasfese.4pu.com/4738736736736735/The-Orpheus-Clock-The-Search-for-My-Family-s-Art-Treasures-Stolen-by-the-Nazis-by-Simon-Goodman.pdf
    • http://cefasfese.4pu.com/1730731733734734730/Einmal-Kreuzberg-Neuruppin-Kindheit-in-Berlin-unter-den-Nazis-by-Christine-Von-Raussendorff.pdf
    • http://cefasfese.4pu.com/2735735734730738/The-Nazi