Malicious PDF — malware analysis report

Static analysis result for SHA-256 724fa0710c8efa22…

MALICIOUS

PDF

12.4 KB Created: 2015-07-15 16:25:45 +04:00 Authoring application: DOMPDF
MD5: e17189f7ac8807214f5358f46939b420 SHA-1: 0717d8943755b54cfa2ea6062bd58d37c3b63bee SHA-256: 724fa0710c8efa22379efc222a317c3c44604be5091735b8916aafb6629a43d1
132 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains a social engineering lure, instructing the user to install a browser extension or update to view content. This is a common tactic to trick users into downloading malware or providing credentials. The document also contains a large number of embedded URLs, many pointing to the same domains, suggesting a link farm or redirection mechanism to host malicious content. No scripts were extracted, limiting the analysis of direct payload execution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8883

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://chavagnes.com/index.php?article=1062.2&urwbo=2&pdf=1062
    • http://anaprieto.com/index.php?article=1775.2&yhxyj=2&pdf=1775
    • http://hotrodderclassifieds.com/index.php?article=979.1&hjjgr=1&pdf=979
    • http://chavagnes.com/index.php?article=1394.2&urwbo=2&pdf=1394
    • http://techaccesscorp.com/index.php?article=2000.2&dupth=2&pdf=2000
    • http://chavagnes.com/index.php?article=753.2&urwbo=2&pdf=753
    • http://www.ecoservice.co/index.php?article=1087.1&egezd=1&pdf=1087
    • http://marjangecevic.com/index.php?article=1062.1&vgslo=1&pdf=1062
    • http://www.myrlimo.com/index.php?article=784.1&sqfkb=1&pdf=784
    • http://chavagnes.com/index.php?article=1631.2&urwbo=2&pdf=1631
    • http://chavagnes.com/index.php?article=1374.2&urwbo=2&pdf=1374
    • http://chavagnes.com/index.php?article=1454.2&urwbo=2&pdf=1454
    • http://marche-espoir.org/index.php?article=157.6&xonvf=6&pdf=157
    • http://chavagnes.com/index.php?article=2317.2&urwbo=2&pdf=2317
    • http://urbanindoorgs.com/index.php?article=1447.1&lkbfl=1&pdf=1447
    • http://chavagnes.com/index.php?article=1094.2&urwbo=2&pdf=1094
    • http://www.mantrabeautybar.ca/index.php?article=1445.1&rukbv=1&pdf=1445