Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1e4b5e1bbb5b599…

MALICIOUS

PDF

28.9 KB Created: 2019-05-05 05:01:45 +01:00 Authoring application: mPDF 5.7
MD5: 5a15d9aac2d54df47876ac0d890cded3 SHA-1: cb1ed92fafac10e334dc624dfc3e6a443dffbf91 SHA-256: f1e4b5e1bbb5b59908cc169d6e8d6cb9735f70a6b079f8823899057192b151b4
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to what appear to be book download pages, suggesting a lure to encourage users to click through and potentially download further malicious content. No scripts were extracted from this sample. The primary attack pattern involves a link farm disguised as legitimate content.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1732738732735738/Becoming-Holmes-The-Boy-Sherlock-Holmes-His-Final-Case-The-Boy-Sherlock-Holmes-6-by-Shane-Peacock.pdf
    • http://cefasfese.4pu.com/8734738730737734/The-Complete-Sherlock-Holmes-Treasury-Including-The-Complete-Adventures-and-Memoirs-of-Sherlock-Holmes-The-Return-of-Sherlock-Holmes-The-Hound-of-the-Baskervilles-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/8736734731733730/Die-Memoiren-des-Sherlock-Holmes-Holmes-erstes-Abenteuer-und-andere-Detektivgeschichten-The-Memoirs-of-Sherlock-Holmes-The-Gloria-Scott-and-Other-Gesicht-und-vieles-mehr-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/2731735730739733/The-Case-Book-of-Sherlock-Holmes-Sherlock-Holmes-9-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/1730730737731737737/The-Adventures-of-Sherlock-Holmes-Die-Abenteuer-von-Sherlock-Holmes---zweisprachig-Englisch-Deutsch-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/1730735736739735730/A-Study-in-Scarlet-Introducing-Sherlock-Holmes-The-Sherlock-Holmes-Collection-Volume-1-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/2735733731731732/Sherlock-Holmes-Volume-1-A-Study-in-Scarlet-amp-Other-Sherlock-Holmes-Stories-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/7737733733730734/The-Adventures-of-Sherlock-Holmes-Sherlock-Holmes-The-Definitive-Collection-3-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/8736734731739739/Die-R-ckkehr-des-Sherlock-Holmes-Im-leeren-Hause-und-andere-Detektivgeschichten-The-Return-of-Sherlock-Holmes-The-Empty-House-and-Other-Stories---Zweisprachige-einsame-Radfahrerin-etc-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/5735736731739732/The-Return-of-Sherlock-Holmes-Die-Wiederkehr-von-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/6739735738732737/His-Last-Bow-Some-Reminiscences-of-Sherlock-Holmes-Sherlock-Holmes-8-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/3730734731731735/The-Adventures-of-Sherlock-Holmes-Sherlock-Holmes-3-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/8738733739732731/The-Adventures-of-Sherlock-Holmes-Sherlock-Holmes-3-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/2736738732732/In-the-Company-of-Sherlock-Holmes-Stories-Inspired-by-the-Holmes-Canon-by-Laurie-R-King.pdf
    • http://cefasfese.4pu.com/3738737733731733/The-Case-Book-of-Sherlock-Holmes-9-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/9734730737734731/The-Memoirs-of-Sherlock-Holmes-Las-Meorias-de-Sherlock-Holles-by-Arthur-Conan-Doyle.pdf
    • http://cefasfese.4pu.com/7733737737730734/The-Case-Of-The-Grave-Accusation-A-Sherlock-Holmes-Adventure-by-Dicky-Neely.pdf
    • http://cefasfese.4pu.com/1736733736730/The-Scientific-Sherlock-Holmes-Cracking-the-Case-with-Science-and-Forensics-by-James-F-O-39-Brien.pdf
    • http://cefasfese.4pu.com/7730733739731734/Sherlock-Holmes-Was-Wrong-Reopening-the-Case-of-The-Hound-of-the-Baskervilles-by-Pierre-Bayard.pdf
    • http://cefasfese.4pu.com/4731731735732732/Sherlock-Holmes-time-detective-by-Adrian-Sherlock.pdf
    • http://cefasfese.4pu.com/8736734731733730/Die-Memoiren-des-Sherlock-Holmes-Holmes-erstes-Abenteuer-und-andere-Detektivgeschichten-The-Me