Malicious PDF — malware analysis report

Static analysis result for SHA-256 0e084462dfcb338b…

MALICIOUS

PDF

11.9 KB Created: 2015-07-15 16:26:07 +04:00 Authoring application: DOMPDF
MD5: 20f18880d542502b39b5be5a47f71382 SHA-1: c7f559e89a7fe03f0950e73bb3c83e21ce881ddc SHA-256: 0e084462dfcb338b83a22d5153423b63bd5200530dc8a70a62a763fbc642eff4
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to various domains, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged the document as malicious. The embedded URLs likely serve as a lure to external sites, potentially for SEO manipulation or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8959

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://chavagnes.com/index.php?article=2256.2&urwbo=2&pdf=2256
    • http://modart.com.tr/index.php?article=1684.1&ykgew=1&pdf=1684
    • http://ipestka.pl/index.php?article=445.1&qsxtx=1&pdf=445
    • http://chavagnes.com/index.php?article=193.2&urwbo=2&pdf=193
    • http://www.mantrabeautybar.ca/index.php?article=2018.1&rukbv=1&pdf=2018
    • http://chavagnes.com/index.php?article=2245.2&urwbo=2&pdf=2245
    • http://krummenacher-haustechnik.ch/index.php?article=1649.1&ptfan=1&pdf=1649
    • http://kontraportal.com/index.php?article=2107.1&szjdf=1&pdf=2107
    • http://alears.lv/index.php?article=1298.2&cqwcy=2&pdf=1298
    • http://chavagnes.com/index.php?article=2324.2&urwbo=2&pdf=2324
    • http://chavagnes.com/index.php?article=962.2&urwbo=2&pdf=962
    • http://chavagnes.com/index.php?article=1165.2&urwbo=2&pdf=1165
    • http://msobo.fr/index.php?article=2007.2&dfkro=2&pdf=2007
    • http://chavagnes.com/index.php?article=1053.2&urwbo=2&pdf=1053
    • http://photo-file.ru/index.php?article=2346.1&wehsa=1&pdf=2346
    • http://chavagnes.com/index.php?article=2242.2&urwbo=2&pdf=2242
    • http://egliseviechretienne.com/index.php?article=2458.5&fkyfd=5&pdf=2458