Malicious PDF — malware analysis report

Static analysis result for SHA-256 75fcf4c11fda709d…

MALICIOUS

PDF

4.4 KB Created: 2015-06-03 16:38:43 +03:00 Authoring application: DOMPDF
MD5: b6e05088cfc059d5f54ba7df65cc089f SHA-1: 2cc3cf3af98df16d948f52c4399924beeb06423c SHA-256: 75fcf4c11fda709d1c7da791a868c4f0569113abaa4f660f45b64809f963d83a
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, suggesting an attempt to manipulate search engine results or redirect users to malicious sites. While no scripts were explicitly extracted, the presence of embedded URLs within the document body, coupled with the ML_NYX_PDF_MALICIOUS classification, indicates a high likelihood of malicious intent. The primary attack pattern observed is the distribution of external links, potentially leading to further compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5320

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.kbb-gesellschaft.de/index.php?2015/ergoarena.pdf&urggv=1&aspx=2407
    • http://phcccolorado.org/index.php?2015/arabtera.pdf&effpp=1&aspx=1110
    • http://www.nibl.co.nz/index.php?2015/decision.pdf&angzv=1&aspx=1890
    • http://phcccolorado.org/index.php?2015/arabtera.pdf&effpp=1&aspx=1668
    • http://www.nibl.co.nz/index.php?2015/decision.pdf&angzv=1&aspx=284
    • http://dyrlaegecentret.dk/index.php?2015/typestitch.pdf&hjhle=1&aspx=sitemap