Malicious PDF — malware analysis report

Static analysis result for SHA-256 fac122cb8e05a8b6…

MALICIOUS

PDF

19.1 KB Created: 2019-05-02 07:02:40 +01:00 Authoring application: mPDF 5.7
MD5: 7ce75e7570f9ed706a45e54e1685cadf SHA-1: 9a049453eec8f22c751ed3a43a3f674dac72dc69 SHA-256: fac122cb8e05a8b644e287b6249ac140de0557ffd226ff2b9c40d6ae343e4307
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDFs, a technique often used for SEO manipulation or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links, with the first URL pointing to a suspicious domain. While no scripts were extracted, the sheer volume of links suggests an attempt to drive traffic or distribute further payloads, making it a likely part of a larger malicious campaign.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731734739739738730/Der-Friede-in-Europa-Eine-Volkerrechtlich-Politische-Studie-by-Eugen-Schlief.pdf
    • http://cefasfese.4pu.com/9739739739734739/Europa-Europa-1-3-by-Joseph-Robert-Lewis.pdf
    • http://cefasfese.4pu.com/1730731739731731735/Jahr-der-Wandlung-by-Friede-H-Kraze.pdf
    • http://cefasfese.4pu.com/1731735730730733736/Hotel-Sacher-in-deinen-Betten-schlief-sterreich-by-Ernst-Hagen.pdf
    • http://cefasfese.4pu.com/1731734739739737735/The-Fairytale-Life-of-Aulden-Schlief-Part-2-The-Anima-by-John-William-Kulm.pdf
    • http://cefasfese.4pu.com/1731739738737738735/The-Implication-of-Prevention-of-Conflicts-for-Justice-and-Peace-In-the-Light-of-the-Pastoral-Letter--Gerechter-Friede-by-Asega-Primus.pdf
    • http://cefasfese.4pu.com/8739738738735736/Franziskas-Erwachen-by-Eugen-Bea.pdf
    • http://cefasfese.4pu.com/3730734730738730/Zen-in-the-Art-of-Archery-by-Eugen-Herrigel.pdf
    • http://cefasfese.4pu.com/9733735734734730/Quantum-Mechanics-by-Eugen-Merzbacher.pdf
    • http://cefasfese.4pu.com/1730736734732737736/The-Eisenberg-Constant-by-Eugen-Egner.pdf
    • http://cefasfese.4pu.com/9730736737733731/Zen-in-der-Kunst-des-Bogenschie-ens-by-Eugen-Herrigel.pdf
    • http://cefasfese.4pu.com/1730735739730734732/Die-Merowinger-Und-Das-Imperium-by-Eugen-Ewig.pdf
    • http://cefasfese.4pu.com/1731735730732736734/Prinz-Eugen-von-Savoyen-by-Alfred-Arneth.pdf
    • http://cefasfese.4pu.com/9734730732733/Theory-and-practice-of-hell-by-Eugen-Kogon.pdf
    • http://cefasfese.4pu.com/9730731733737735/-sterreichs-Spuren-in-Venedig-by-Eugen-Semrau.pdf
    • http://cefasfese.4pu.com/2736734733739732/In-Times-of-Fading-Light-by-Eugen-Ruge.pdf
    • http://cefasfese.4pu.com/1731739731735735737/Der-Deutschenspiegel-in-seinem-sprachlichstilistischen-Verh-by-Freiherr-von-Eugen-M.pdf
    • http://cefasfese.4pu.com/9738735732733739/Ber-hmte-Deutsche-Vork-mpfer-F-r-Fortschritt-Freiheit-Und-Friede-in-Nord-Amerika-Von-1626-Bis-1888-Einhundert-Und-F-nfzig-Biographien-Mit-Sechzehn-Portraits-by-Herman-Julius-Ruetenik.pdf
    • http://cefasfese.4pu.com/9735731730734736/Sonja---Gebraucht-Missbraucht-Verbraucht-Verkauft-FINAL-EDITION-by-Eugen-Bea.pdf
    • http://cefasfese.4pu.com/1738736730730733/The-Theory-and-Practice-of-Hell-The-German-Concentration-Camps-and-the-System-Behind-Them-by-Eugen-Kogon.pdf
    • http://cefasfese.4pu.com/9733735