Malicious PDF — malware analysis report

Static analysis result for SHA-256 26d1d643900350ab…

MALICIOUS

PDF

4.3 KB Created: 2015-06-03 17:02:37 +03:00 Authoring application: DOMPDF
MD5: ee015f87509cd551afb9283fdd68a09c SHA-1: ec8a118f240eea502e7b66ae34ea96fab9dba58e SHA-256: 26d1d643900350ab3a9325fe711741b61d688000c5d32b7782272c223e345b31
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various domains and appear to be part of a link farm designed to manipulate search engine rankings or distribute malicious content. The ML classifier also flagged the PDF as malicious. No scripts were extracted, and the document body text is largely obfuscated, but the presence of numerous external links is the primary indicator of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5447

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.prequine.com/index.php?2015/torcida.pdf&fcldj=1&aspx=207
    • http://www.academiafutebolangola.com/index.php?2015/hmdeepfocus.pdf&audtr=1&aspx=2207
    • http://kash.info/index.php?2015/zmagic.pdf&eqhgc=1&aspx=239
    • http://kash.info/index.php?2015/zmagic.pdf&eqhgc=1&aspx=1245
    • http://www.academiafutebolangola.com/index.php?2015/hmdeepfocus.pdf&audtr=1&aspx=536
    • http://veranomusical.es/index.php?2015/booboodigital.pdf&ieycq=1&aspx=sitemap