Malicious PDF — malware analysis report

Static analysis result for SHA-256 e4bf01c7695e74a9…

MALICIOUS

PDF

18.5 KB Created: 2019-05-03 19:49:28 +01:00 Authoring application: mPDF 5.7
MD5: 4cfa347c9a1e0de8aacb1eca497ee1a5 SHA-1: 38fbaa91d12d94aa3abb329201a4153f9914a89a SHA-256: e4bf01c7695e74a90244670875cfba3b85e16499c7df25d703ca4ad23be6e4c5
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDFs, a technique often used for SEO manipulation or to distribute malicious content. While the document body was not readable, the PDF structure and the heuristic firings strongly suggest a malicious intent to redirect users to potentially harmful content hosted on xiixmcuin.linkpc.net. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2201200209205200/Food-Wars-Vol-1-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/2204201203200202/Food-Wars-Vol-1-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/1201207204201201204/-27-Shokugeki-no-Souma-27-Food-Wars-Shokugeki-no-Soma-27-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/1201207203208207209/-12-Shokugeki-no-Souma-12-Food-Wars-Shokugeki-no-Soma-12-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/1201207203209207207/-24-Shokugeki-no-Souma-24-Food-Wars-Shokugeki-no-Soma-24-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/1201207204201201200/-26-Shokugeki-no-Souma-26-Food-Wars-Shokugeki-no-Soma-26-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/1201207203208209203/-19-Shokugeki-no-Souma-19-Food-Wars-Shokugeki-no-Soma-19-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/1201207203208208201/-13-Shokugeki-no-Souma-13-Food-Wars-Shokugeki-no-Soma-13-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/1201207203208207205/-9-Shokugeki-no-Souma-9-Food-Wars-Shokugeki-no-Soma-9-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/1201207203208201206/-6-Shokugeki-no-Souma-6-Food-Wars-Shokugeki-no-Soma-6-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/1201207204202200201/-30-Shokugeki-no-Souma-30-Food-Wars-Shokugeki-no-Soma-30-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/1201207203208202200/-10-Shokugeki-no-Souma-10-Food-Wars-Shokugeki-no-Soma-10-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/1201207203208201205/-5-Shokugeki-no-Souma-5-Food-Wars-Shokugeki-no-Soma-5-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/1201207203209208208/-23-Shokugeki-no-Souma-23-Food-Wars-Shokugeki-no-Soma-23-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/1201207204201201203/-1-Shokugeki-no-Souma-1-Food-Wars-Shokugeki-no-Soma-1-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/4207201206207206/Lunch-Wars-How-to-Start-a-School-Food-Revolution-and-Win-the-Battle-for-Our-Children-s-Health-by-Amy-Kalafa.pdf
    • http://xiixmcuin.linkpc.net/4204206204202202/The-Foie-Gras-Wars-How-a-5-000-Year-Old-Delicacy-Inspired-the-World-s-Fiercest-Food-Fight-by-Mark-Caro.pdf
    • http://xiixmcuin.linkpc.net/1200206207208208200/Fast-Food-Good-Food-More-Than-150-Quick-and-Easy-Ways-to-Put-Healthy-Delicious-Food-on-the-Table-by-Andrew-Weil.pdf
    • http://xiixmcuin.linkpc.net/7204206201204206/-L-toile----4-Shokugeki-no-Souma-L-toile-4-Food-Wars-Shokugeki-no-Soma-Etoile-4-by-Michiko-Itou.pdf
    • http://xiixmcuin.linkpc.net/7201207204200/The-Clone-Wars-Star-Wars-The-Clone-Wars-1-by-Karen-Traviss.pdf
    • http://xiixmcuin.linkpc.net/1201207203208207205/-9-Shokugeki-no-Souma-9-Food-Wars-Shokugeki-no-