Malicious PDF — malware analysis report

Static analysis result for SHA-256 b0f1be3a8ade4010…

MALICIOUS

PDF

21.0 KB Created: 2019-05-02 05:48:52 +01:00 Authoring application: mPDF 5.7
MD5: 5c7c189376121367a80a2091e3599aa9 SHA-1: b264824d103ec877f1b99a0f408560afe793789a SHA-256: b0f1be3a8ade4010bafdd4ee83c8babeb931fc70cad0199376120532405d09a7
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample. The attack pattern is inferred from the link farm heuristic.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/8735739735737733/Police-by-Robert-W-Chambers.pdf
    • http://cefasfese.4pu.com/1731738731738731732/Chambers-s-Edinburgh-Journal-No-458-by-Robert-Chambers.pdf
    • http://cefasfese.4pu.com/1730735734731739735/Chambers-s-Edinburgh-Journal-No-455-by-Robert-Chambers.pdf
    • http://cefasfese.4pu.com/6739735739736737/The-Barker-s-Dozen---Reminiscences-of-an-Early-Police-Dog-by-Robert-Warr.pdf
    • http://cefasfese.4pu.com/3738738735732730/The-King-in-Yellow-by-Robert-W-Chambers.pdf
    • http://cefasfese.4pu.com/1736731734730732/The-King-in-Yellow-by-Robert-W-Chambers.pdf
    • http://cefasfese.4pu.com/1736739731739737/Police-Aesthetics-Literature-Film-and-the-Secret-Police-in-Soviet-Times-by-Cristina-Vatulescu.pdf
    • http://cefasfese.4pu.com/1731733733732733/Code-of-Silence-How-one-honest-police-officer-took-on-Australia-s-most-corrupt-police-force-by-Colin-Dillon.pdf
    • http://cefasfese.4pu.com/3732737730730730/The-Yellow-Sign-amp-Other-Stories-by-Robert-W-Chambers.pdf
    • http://cefasfese.4pu.com/3738732738737/The-King-in-Yellow-and-Other-Horror-Stories-by-Robert-W-Chambers.pdf
    • http://cefasfese.4pu.com/8735739735737738/Police-The-Police-Trilogy-1-by-Alexis-Shore.pdf
    • http://cefasfese.4pu.com/1731733731730730/Angry-White-Pyjamas-A-Scrawny-Oxford-Poet-Takes-Lessons-from-the-Tokyo-Riot-Police-by-Robert-Twigger.pdf
    • http://cefasfese.4pu.com/8739733736736737/Police-Officer-s-Language-Translator-Polt-2004-Edition---Asian-Languages-by-Police-Language-Resources-Inc-.pdf
    • http://cefasfese.4pu.com/1731737730730738731/Chambers-Crossword-Lists---New-Edition-by-Chambers-Dictionaries.pdf
    • http://cefasfese.4pu.com/4734730735733736/-oku-The-Inner-Chambers-Volume-5-oku-The-Inner-Chambers-5-by-Fumi-Yoshinaga.pdf
    • http://cefasfese.4pu.com/4734730735733735/-oku-The-Inner-Chambers-Volume-4-oku-The-Inner-Chambers-4-by-Fumi-Yoshinaga.pdf
    • http://cefasfese.4pu.com/1730735738730739/-oku-The-Inner-Chambers-Volume-1-oku-The-Inner-Chambers-1-by-Fumi-Yoshinaga.pdf
    • http://cefasfese.4pu.com/5738736735737739/Chameleon-II---True-Stories-of-a-Texas-Undercover-Police-Officer-Chameleon---True-Stories-of-a-Texas-Undercover-Police-Officer-Book-2-by-Ty-Cran.pdf
    • http://cefasfese.4pu.com/2737739734735736/Police-Don-t-Move-well-sometimes-we-do-by-N-E-Wood.pdf
    • http://cefasfese.4pu.com/1732737738738737/The-Morality-Police-3-by-J-Cafesin.pdf