Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b712013f6f7ddab…

MALICIOUS

PDF

17.7 KB Created: 2019-05-01 19:08:31 +01:00 Authoring application: mPDF 5.7
MD5: fa7fdb543867f6d4b3b63b6fb5c782c3 SHA-1: ed8afc307424b21fca7045204cbeb029393ce542 SHA-256: 4b712013f6f7ddab4b1413398a24003875c5f0744527924da2fe554cc131116e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. The ML classifier strongly suggests maliciousness. The primary attack pattern appears to be SEO manipulation or a content distribution scheme, leveraging the numerous links to external PDF files. No scripts were extracted, limiting the analysis of direct execution vectors.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/1da0da9da3da2da1da6/edogawa-ranpo-zennshuu-ichi-shounenntannteidann-katuyakusu-by-Rampo-Edogawa.pdf
    • http://seasasac.lflinkup.com/1da1da8da4da4da8da7/The-world-of-Shakespeare-Hamlet-and-Julius-Caesar-by-shogo-kisaragi.pdf
    • http://seasasac.lflinkup.com/1da1da8da4da4da9da0/Play-of-the-child-1-by-shogo-kisaragi.pdf
    • http://seasasac.lflinkup.com/1da1da8da4da4da8da8/Desire-for-exchange-1-by-shogo-kisaragi.pdf
    • http://seasasac.lflinkup.com/1da1da8da4da4da2da8/Romeo-and-Juliet-of-Shakespeare-by-shogo-kisaragi.pdf
    • http://seasasac.lflinkup.com/1da1da8da4da4da3da2/Desire-for-exchange-Full-version-by-shogo-kisaragi.pdf
    • http://seasasac.lflinkup.com/1da1da8da4da4da3da0/Book-of-Five-Rings-by-Musashi-Miyamoto-full-version-by-shogo-kisaragi.pdf
    • http://seasasac.lflinkup.com/1da1da8da4da4da2da3/haiku-of-Shiki-MASAOKA-and-Picture-of-Fuji-of-Hokusai-KATSUSHIKA-by-shogo-kisaragi.pdf
    • http://seasasac.lflinkup.com/1da0da9da3da2da1da9/Edogawa-Ranpo-Sho-amp-X304-To-Nihon-No-Misuteri-amp-X304-by-Ensei-Sekiguchi.pdf
    • http://seasasac.lflinkup.com/3da6da9da0da6da6/The-Black-Lizard-and-Beast-in-the-Shadows-by-Rampo-Edogawa.pdf
    • http://seasasac.lflinkup.com/1da0da9da2da9da6da3/Edogawa-Ranposakuhinnshuu-zennsannjuugosakuhinnwoshuuroku-by-Rampo-Edogawa.pdf
    • http://seasasac.lflinkup.com/1da0da9da3da0da3da9/The-Edgar-Allan-Poe-of-Japan---Some-Tales-by-Edogawa-Rampo---With-Some-Stories-Inspired-by-His-Writings-by-Rampo-Edogawa.pdf
    • http://seasasac.lflinkup.com/1da0da9da2da9da6da1/The-Short-Stories-of-Rampo-Edogawa-by-Rampo-Edogawa.pdf
    • http://seasasac.lflinkup.com/2da0da4da9da2da6/No-Lie-I-Acted-Like-a-Beast-The-Story-of-Beauty-and-the-Beast-as-Told-by-the-Beast-by-Nancy-Loewen.pdf
    • http://seasasac.lflinkup.com/3da6da9da0da7da3/The-Edogawa-Rampo-Reader-by-Rampo-Edogawa.pdf
    • http://seasasac.lflinkup.com/2da7da6da3da3da1/Kill-the-Beast-Beast-Hunters-1-by-Michele-Israel-Harper.pdf
    • http://seasasac.lflinkup.com/3da1da3da4da2da3/Tartok-The-Ice-Beast-Beast-Quest-5-by-Adam-Blade.pdf
    • http://seasasac.lflinkup.com/3da8da3da3da1da4/Freeing-the-Beast-Taming-the-Beast-1-by-Tina-Donahue.pdf
    • http://seasasac.lflinkup.com/2da6da0da5da8da8/Blindness-by-Jos-Saramago.pdf
    • http://seasasac.lflinkup.com/8da2da4da9da9da6/Blindness-Seeing-by-Jos-Saramago.pdf
    • http://seasasac.lflinkup.com/1da0da9da3da2da1da9/Edogawa-Ranpo-Sho-amp-X304-To-Nihon-