Malicious PDF — malware analysis report

Static analysis result for SHA-256 e167f0ab35edaf2a…

MALICIOUS

PDF

21.9 KB Created: 2019-06-04 09:54:50 +01:00 Authoring application: mPDF 5.7
MD5: 70f10631856701cce2d2003e4bda3af3 SHA-1: e69b83aaee5eebc0177875699b10491c6ebaf4fe SHA-256: e167f0ab35edaf2a7691910ca9fa4722e2c207bf77bcc429c23db2b29dfb111c
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are marked as benign, the sheer volume and structure suggest an attempt to manipulate search engine results or to serve as a distribution point for malicious content. The attack pattern is likely related to SEO poisoning or a phishing lure, aiming to direct users to potentially harmful sites. No scripts were extracted, limiting further analysis of direct malicious actions.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730739734731734/Waiting-for-the-Past-Poems-by-Les-Murray.pdf
    • http://cefasfese.4pu.com/4735732730731730/Waiting-on-God-by-Andrew-Murray.pdf
    • http://cefasfese.4pu.com/3733731735735730/Knowledge-of-Sins-Past-Murray-of-Letho-2-by-Lexie-Conyngham.pdf
    • http://cefasfese.4pu.com/4735739738738732/New-Collected-Poems-by-Les-Murray.pdf
    • http://cefasfese.4pu.com/1730739732735734/Subhuman-Redneck-Poems-by-Les-Murray.pdf
    • http://cefasfese.4pu.com/1737738739733733/Waiting-for-Saint-Brendan-and-Other-Poems-by-David-McLoghlin.pdf
    • http://cefasfese.4pu.com/4734731732737735/Waiting-for-the-Dark-Waiting-for-the-Light-by-Ivan-Kl-ma.pdf
    • http://cefasfese.4pu.com/1730738730738737737/An-Atheist-Epic-Bill-Murray-the-Bible-and-the-Baltimore-Board-of-Education-by-Madalyn-Murray-O-39-Hair.pdf
    • http://cefasfese.4pu.com/3739739738731737/Legends-of-the-Black-Orchid-by-Murray-Ian-Murray.pdf
    • http://cefasfese.4pu.com/3731735731733731/Waiting-for-You-Waiting-for-You-1-by-Shey-Stahl.pdf
    • http://cefasfese.4pu.com/8732735739738733/Remembrance-of-Things-Past-Volume-II---The-Guermantes-Way-Cities-of-the-Plain-The-Sweet-Cheat-Gone-The-Past-Recaptured-by-Marcel-Proust.pdf
    • http://cefasfese.4pu.com/4733737732731737/Pauli-Murray-The-Autobiography-of-a-Black-Activist-Feminist-Lawyer-Priest-and-Poet-by-Pauli-Murray.pdf
    • http://cefasfese.4pu.com/1738732731739/Claire-Murray-Nantucket-Inspirations-Designs-Charts-amp-Folklore-by-Claire-Murray.pdf
    • http://cefasfese.4pu.com/7731738738735735/Past-Life-Regression-Remember-Past-Lives-and-Reincarnation-with-Hypnosis-via-Beach-Hypnosis-and-Meditation-by-Gelina-Ray.pdf
    • http://cefasfese.4pu.com/3736733734734738/Past-Life-Regression-A-Manual-for-Hypnotherapists-to-Conduct-Effective-Past-Life-Regression-Sessions-by-Kemila-Zsange.pdf
    • http://cefasfese.4pu.com/1730737739734730733/Liberating-the-Future-from-the-Past-Liberating-the-Past-from-the-Future-A-Short-Listed-Essay-by-Erika-Schelby.pdf
    • http://cefasfese.4pu.com/3735732732738731/Past-Imperfect-Past-Imperfect-1-by-Fletcher-DeLancey.pdf
    • http://cefasfese.4pu.com/7739730736732731/Four-Poems-from-Zion-s-Flowers-Or-Christian-Poems-for-Spiritual-Edification-by-Zacharie-Boyd.pdf
    • http://cefasfese.4pu.com/6735735739735735/Messages-to-Lelia-Haiku-Short-Poems-and-Longer-Poems-by-Billy-Reed.pdf
    • http://cefasfese.4pu.com/7739730737734737/Four-Poems-from-Zion-s-Flowers-Or-Christian-Poems-for-Spiritual-Edification-by-Mr-Zacharie-Boyd.pdf
    • http://cefasfese.4pu.com/8732735739738733/Remembrance-of-Things-Past-Volume-II---The-Guermantes-Way-Cities-