Malicious PDF — malware analysis report

Static analysis result for SHA-256 305cdc567ce59744…

MALICIOUS

PDF

11.7 KB Created: 2015-07-15 16:24:55 +04:00 Authoring application: DOMPDF
MD5: c7cc26fb6e984e9c521ba3b8c5266e42 SHA-1: d20b3102603f93f8d88e4618c7edcabc1345e5c7 SHA-256: 305cdc567ce597448e83057dab3d5d12d87100612d5a79b75e78037d8de13bb5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs, identified by the 'PDF_SEO_LINK_FARM' heuristic, pointing to various websites. These links appear to be part of a link farm designed to manipulate search engine results or direct users to potentially malicious content. The ML classifier also flagged the PDF as malicious with a high probability. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8959

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://chavagnes.com/index.php?article=859.2&urwbo=2&pdf=859
    • http://wbus.nl/index.php?article=1928.7&exicf=7&pdf=1928
    • http://outletdepot.eu/index.php?article=1798.1&rjpfb=1&pdf=1798
    • http://chavagnes.com/index.php?article=2359.2&urwbo=2&pdf=2359
    • http://www.mantrabeautybar.ca/index.php?article=1750.1&rukbv=1&pdf=1750
    • http://chavagnes.com/index.php?article=1717.2&urwbo=2&pdf=1717
    • http://www.protop.co.il/index.php?article=1532.1&nraga=1&pdf=1532
    • http://sandystraitssizzlers.com/index.php?article=2170.1&kwbat=1&pdf=2170
    • http://zomodiet.com/index.php?article=514.1&tqubb=1&pdf=514
    • http://chavagnes.com/index.php?article=610.2&urwbo=2&pdf=610
    • http://chavagnes.com/index.php?article=1631.2&urwbo=2&pdf=1631
    • http://chavagnes.com/index.php?article=838.2&urwbo=2&pdf=838
    • http://www.ivanandpamela.com/index.php?article=544.1&tekgj=1&pdf=544
    • http://chavagnes.com/index.php?article=247.2&urwbo=2&pdf=247
    • http://top-rice-cooker.com/index.php?article=780.1&ratfe=1&pdf=780
    • http://chavagnes.com/index.php?article=2467.2&urwbo=2&pdf=2467
    • http://harmenhomes.ca/index.php?article=508.1&wcdhp=1&pdf=508