Malicious PDF — malware analysis report

Static analysis result for SHA-256 d91bb477dc8a97b0…

MALICIOUS

PDF

17.4 KB Created: 2019-05-02 05:43:01 +01:00 Authoring application: mPDF 5.7
MD5: 8a8b4c5209f292eda3a9160d3b5f0859 SHA-1: 8eed6ee0029b2e4e1e1a0535e892e55a4999afd0 SHA-256: d91bb477dc8a97b08a2b1c2d08b4abd994a9292a697602442df2efc8458403f8
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a heuristic firing for a PDF SEO link farm, indicating a large number of embedded links to external PDFs. The document body is heavily obfuscated, but the embedded URLs suggest a content-luring or redirection scheme. The primary IOC is the first URL in the link farm, which appears to be a benign coffee-related document, but the sheer volume of links suggests a malicious intent to drive traffic or distribute further content.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4737731736737732/Cool-Coffee-Creamer-Secrets---20-Homemade-Coffee-Creamer-Recipes-by-Jeen-van-der-Meer.pdf
    • http://cefasfese.4pu.com/4737731734738731/Critical-Reviews-of-Top-Rated-Coffee-Makers-by-Jeen-van-der-Meer.pdf
    • http://cefasfese.4pu.com/6739739733732738/A-Coffee-Lover-s-Guide-to-Coffee-All-the-Must---Know-Coffee-Methods-Techniques-Equipment-Ingredients-and-Secrets-by-Shlomo-Stern.pdf
    • http://cefasfese.4pu.com/6734739732730735/Ghost-in-the-Coffee-Machine-Coffee-and-Ghosts-Series-Starter-by-Charity-Tahmaseb.pdf
    • http://cefasfese.4pu.com/5736730732730737/Long-Distance-Coffee-Midnight-Coffee-1-by-Emma-Sterner-Radley.pdf
    • http://cefasfese.4pu.com/1731735734738730735/Coffee-Culture-and-Intellectual-Property-Lessons-for-Africa-from-the-Ethiopian-Fine-Coffee-Initiative-by-Heran-Sereke-Brhan.pdf
    • http://cefasfese.4pu.com/1736736736734733/Coffee-Czar-Coffee-Culture-1-by-J-Lorraine.pdf
    • http://cefasfese.4pu.com/4737736733734731/Coffee-Czar-Coffee-Culture-1-by-J-Lorraine.pdf
    • http://cefasfese.4pu.com/8732738730731733/The-Cop-and-the-Girl-from-the-Coffee-Shop-Coffee-Shop-Girls-1-by-Terry-Towers.pdf
    • http://cefasfese.4pu.com/4732737730730738/Baseball-in-41-a-Celebration-of-the-quot-Best-Baseball-Season-Ever-quot-by-Robert-W-Creamer.pdf
    • http://cefasfese.4pu.com/1731739732737739733/Espresso-Coffee-by-Ila-May.pdf
    • http://cefasfese.4pu.com/1739734735730734/First-We-Have-Coffee-by-Margaret-Jensen.pdf
    • http://cefasfese.4pu.com/2734732736731738/But-First-Coffee-by-Sarah-Darlington.pdf
    • http://cefasfese.4pu.com/1730734738735735735/All-Over-Coffee-by-Paul-Madonna.pdf
    • http://cefasfese.4pu.com/2738730738736/Drinking-Coffee-Elsewhere-by-Z-Z-Packer.pdf
    • http://cefasfese.4pu.com/3731739731734736/The-Cat-and-the-Coffee-Drinkers-by-Max-Steele.pdf
    • http://cefasfese.4pu.com/4734734732731732/Black-Coffee-by-Andrew-MacRae.pdf
    • http://cefasfese.4pu.com/1734731737730736/Coffee-with-Shakespeare-by-Stanley-Wells.pdf
    • http://cefasfese.4pu.com/4739737738732735/Coffee-s-for-Closers-by-Tony-Morris.pdf
    • http://cefasfese.4pu.com/1732737734730738/Fables-of-the-Flag-by-Ethan-Coffee.pdf