Malicious PDF — malware analysis report

Static analysis result for SHA-256 f05629f7e572c5f5…

MALICIOUS

PDF

14.6 KB Created: 2019-04-30 07:44:52 +01:00 Authoring application: mPDF 5.7
MD5: 77efdc1a81effadc1646e19ecb2d10a4 SHA-1: b5ab11ba10a9930f9927cfeddf036b5147c70b87 SHA-256: f05629f7e572c5f57df701c7330cac0b5cf5dae2c4815924b440f84b56e7470d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external PDF link farm, with the first URL being http://cefasfese.4pu.com/9737739735732730/Ichi-the-killer-vol-9-by-Hideo-Yamamoto.pdf. While the extracted URLs are currently marked as benign, the sheer volume and the nature of the hosting domain suggest a malicious intent to redirect users. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/9737739735732730/Ichi-the-killer-vol-9-by-Hideo-Yamamoto.pdf
    • http://cefasfese.4pu.com/2738730731736732/The-Making-of-a-Serial-Killer-The-Real-Story-of-the-Gainesville-Student-Murders-in-the-Killer-s-Own-Words-by-Danny-Rolling.pdf
    • http://cefasfese.4pu.com/4731731738734738/The-Killer-Cat-s-Birthday-Bash-The-Killer-Cat-4-by-Anne-Fine.pdf
    • http://cefasfese.4pu.com/1731735738730736/Seventeen-by-Hideo-Yokoyama.pdf
    • http://cefasfese.4pu.com/8730733736739736/An-American-Breakfast-by-Hideo-Asano.pdf
    • http://cefasfese.4pu.com/2739732732732736/Killer-Decision-The-Killer-2-by-Jaci-Burton.pdf
    • http://cefasfese.4pu.com/6737736730734736/-Kage-no-kisetsu-by-Hideo-Yokoyama.pdf
    • http://cefasfese.4pu.com/9737739736734738/-Wagaya-no-mondai-by-Hideo-Okuda.pdf
    • http://cefasfese.4pu.com/6737735739731730/-Rupan-No-Sho-soku-by-Hideo-Yokoyama.pdf
    • http://cefasfese.4pu.com/9737739735737730/Encyclopedia-of-Japanese-Cuisine-by-Hideo-Dekura.pdf
    • http://cefasfese.4pu.com/9737739736735734/Classic-Bonsai-of-Japan-by-Hideo-Aragaki.pdf
    • http://cefasfese.4pu.com/9737739736735732/Essentially-Japanese-cooking-amp-cuisine-by-Hideo-Dekura.pdf
    • http://cefasfese.4pu.com/7731730737731735/Takato-Yamamoto-by-Takato-Yamamoto.pdf
    • http://cefasfese.4pu.com/1737732739739736/MM9-by-Hiroshi-Yamamoto.pdf
    • http://cefasfese.4pu.com/1736734733731732/Betty-San-by-Michiko-Yamamoto.pdf
    • http://cefasfese.4pu.com/5735738739732737/-6-by-Shin-39-ichi-Sakamoto.pdf
    • http://cefasfese.4pu.com/5735738739732738/-7-by-Shin-39-ichi-Sakamoto.pdf
    • http://cefasfese.4pu.com/1736737734737738/Gareki-no-naka-by-Ken-39-ichi-Yoshida.pdf
    • http://cefasfese.4pu.com/7731730737731733/Attack-on-Yamamoto-by-Carroll-V-Glines.pdf
    • http://cefasfese.4pu.com/7731730738735733/Riken-Yamamoto-by-Wilhelm-Klauser.pdf
    • http://cefasfese.4pu.com/9737739736735732/Essentially-Japanese-cooki