Malicious PDF — malware analysis report

Static analysis result for SHA-256 7ab03b5a6e77607a…

MALICIOUS

PDF

17.4 KB Created: 2019-05-05 08:45:01 +01:00 Authoring application: mPDF 5.7
MD5: 72e003e1a3198bb79964d8cba6c9edd7 SHA-1: dd4b6034955a099b9f77624400ea5f9050a13d50 SHA-256: 7ab03b5a6e77607a74b629c2d5bfa25779f33cf50a759066da86d8a903f3a8bf
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing indicating a link farm with 23 external PDF links, all pointing to the same domain 'cefasfese.4pu.com'. The document body confirms the presence of these numerous URLs, suggesting a tactic to distribute content or potentially lure users to malicious sites. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/2736738730736734/Dengeki-Daisy-Vol-06-Dengeki-Daisy-6-by-Kyousuke-Motomi.pdf
    • http://cefasfese.4pu.com/2732731738730730/Dengeki-Daisy-Vol-10-Dengeki-Daisy-10-by-Kyousuke-Motomi.pdf
    • http://cefasfese.4pu.com/2736738739737730/Dengeki-Daisy-Vol-16-Dengeki-Daisy-16-by-Kyousuke-Motomi.pdf
    • http://cefasfese.4pu.com/1737739737735735/Dengeki-Daisy-Vol-12-Dengeki-Daisy-12-by-Kyousuke-Motomi.pdf
    • http://cefasfese.4pu.com/1731736734732736730/Dengeki-Daisy-Vol-14-Dengeki-Daisy-14-by-Kyousuke-Motomi.pdf
    • http://cefasfese.4pu.com/2736738736735736/Dengeki-Daisy-Vol-13-Dengeki-Daisy-13-by-Kyousuke-Motomi.pdf
    • http://cefasfese.4pu.com/2730733735739733/Dengeki-Daisy-Vol-01-Dengeki-Daisy-1-by-Kyousuke-Motomi.pdf
    • http://cefasfese.4pu.com/2736738733732734/Dengeki-Daisy-Vol-8-by-Kyousuke-Motomi.pdf
    • http://cefasfese.4pu.com/1730738735736737737/Dengeki-Daisy-07-by-Kyosuke-Motomi.pdf
    • http://cefasfese.4pu.com/1730738735736732738/Dengeki-Daisy-09-by-Kyosuke-Motomi.pdf
    • http://cefasfese.4pu.com/1730738735736732737/Dengeki-Daisy-14-by-Kyosuke-Motomi.pdf
    • http://cefasfese.4pu.com/1730738735736737738/Dengeki-Daisy-12-by-Kyosuke-Motomi.pdf
    • http://cefasfese.4pu.com/1731736734733735738/Japanese-Monthly-Manga-Magazines-Dengeki-G-s-Magazine-Dengeki-Daioh-Gangan-Comics-Lala-Nakayoshi-Super-Jump-Sh-Nen-Sekai-Jump-Square-by-Books-LLC.pdf
    • http://cefasfese.4pu.com/1730730737734730736/Miss-Daisy-und-der-Tote-auf-dem-Eis-Miss-Daisy-ermittelt-1-by-Carola-Dunn.pdf
    • http://cefasfese.4pu.com/9733731738738734/Daisy-McDare-and-the-Deadly-Art-Affair-Daisy-McDare-1-by-K-M-Morgan.pdf
    • http://cefasfese.4pu.com/2730733736736737/The-Beads-Club-by-Kyousuke-Motomi.pdf
    • http://cefasfese.4pu.com/1730738735736737734/Queen-s-Quality-Vol-1-Preview-by-Kyousuke-Motomi.pdf
    • http://cefasfese.4pu.com/3731733733730735/Baby-Daisy-s-Good-Idea-La-Buena-Idea-De-Bebe-Daisy-Baby-s-First-Disney-Books-English-Spanish-by-Walt-Disney-Company.pdf
    • http://cefasfese.4pu.com/1731736734732736734/dengeki-surounin-kanketuhen-by-watanabe-denki.pdf
    • http://cefasfese.4pu.com/1731736734734730738/Suite-line-lt-2-gt-audition-of-Preparation-Dengeki-Bunko-2009-ISBN-4048680722-Japanese-Import-by-Mamizu-Arisawa.pdf
    • http://cefasfese.4pu.com/1731736734733735738/Japanese-Monthly-Manga-Magazi