Malicious PDF — malware analysis report

Static analysis result for SHA-256 38050a0666c970ad…

MALICIOUS

PDF

20.7 KB Created: 2019-05-02 05:14:21 +01:00 Authoring application: mPDF 5.7
MD5: 841f6316547ec117d655125ecc62af0c SHA-1: 61fed20a328056dc2322b966b61221b136cd4cd4 SHA-256: 38050a0666c970ad9313955891389f2d78347093c9ccdc87904d637787bff9a7
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to seemingly benign content, but the sheer volume and the heuristic firing suggest a malicious intent, likely SEO poisoning or a distribution network. No scripts were extracted from this sample. The attack pattern is inferred from the link farm heuristic.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5739735731737734/Chow-Chow-Dogs-For-Pets-The-New-Pet-Owner-amp-x2019-s-Complete-Handbook-On-Chow-Chow-Diet-Chow-Chow-Health-How-To-Train-Chow-Chow-Puppy-Chow-Chows-How-To-Buy-A-Chow-Chow-And-All-The-Important-Chow-Chow-Facts-You-Need-To-Care-For-Your-Chow-Chow-Pet-by-Jose-K-Nichols.pdf
    • http://cefasfese.4pu.com/5739735733735737/Chow-Chow-Dog-Guide-for-Owners-of-Chow-Chows-amp-Those-Thinking-of-Getting-One-The-Chow-Chow-dog-breed-definitive-guide-Everything-about-Chow-Chows-Chows-healthy-and-everything-in-between-by-C-J-Walker.pdf
    • http://cefasfese.4pu.com/5739735733731737/Chow-Chow-An-Owner-s-Guide-to-a-Happy-Healthy-Pet-by-Paulett-Braun.pdf
    • http://cefasfese.4pu.com/5739735733734733/Guide-to-Owning-a-Chow-Chow-by-Anna-Katherine-Nicholas.pdf
    • http://cefasfese.4pu.com/5739735733734736/The-Story-of-Chester-the-Chow-Chow-by-Dennis-Babeaux.pdf
    • http://cefasfese.4pu.com/5739735733735731/The-New-Complete-Chow-Chow-by-Howell-Book-House.pdf
    • http://cefasfese.4pu.com/5739735731737732/The-Chow-Chow-by-Anna-Katherine-Nicholas.pdf
    • http://cefasfese.4pu.com/5739735731738737/Proper-Care-of-Chow-Chow-by-Bob-Banghart.pdf
    • http://cefasfese.4pu.com/5739735731737739/The-Chow-Chow-by-Constance-Emily-Collett.pdf
    • http://cefasfese.4pu.com/5739735731733738/The-Complete-Chow-Chow-by-L-J-Kip-Kopatch.pdf
    • http://cefasfese.4pu.com/5739735731737731/Chow-Chow-by-Samuel-Draper.pdf
    • http://cefasfese.4pu.com/5739735732736735/The-Chow-Chow-by-Lady-Dunbar.pdf
    • http://cefasfese.4pu.com/5739735731737730/Chow-by-Victoria-A-Hudson.pdf
    • http://cefasfese.4pu.com/5739735733734731/The-Fourth-Player-by-Marie-Chow.pdf
    • http://cefasfese.4pu.com/5739735731732739/Chow-Chows-by-Beverly-Pisano.pdf
    • http://cefasfese.4pu.com/5739735733734730/Cheap-Chow-Chicago-by-A-LaBan.pdf
    • http://cefasfese.4pu.com/5739735732737735/Apocalypse-Chow-How-to-Eat-Well-When-the-Power-Goes-Out-by-Jon-Robertson.pdf
    • http://cefasfese.4pu.com/5739735733734734/Chow-Chows-for-Beginners-by-Elliot-Adams.pdf
    • http://cefasfese.4pu.com/6732739737732732/The-New-Commune-ist-Manifesto-by-Ernesto-Raj-Peshkov-Chow.pdf
    • http://cefasfese.4pu.com/5739735731738730/Plant-Your-Feet-Firmly-by-Marie-Chow.pdf
    • http://cefasfese.4pu.com/5739735733735737/Chow-Chow-Dog-Guide-for-Owners-of-Chow-Chows-amp-Those-Thinki