Malicious PDF — malware analysis report

Static analysis result for SHA-256 79ce43e40ee20e53…

MALICIOUS

PDF

5.4 KB Created: 2015-06-03 16:40:35 +03:00 Authoring application: DOMPDF
MD5: 09cbc5d0823d9502fb42966accd2355f SHA-1: a6f524efeabd66748bfc13cbcc0b5a7844f8796a SHA-256: 79ce43e40ee20e53d6b43c619047ec4bc74cda5cc79afa89fc6004f7472d02ba
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF file contains a significant number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. The document body, though truncated, also contains these URLs and text related to trading, suggesting a lure to click on these links. The primary attack pattern appears to be SEO manipulation or directing users to potentially malicious external sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier clean score 0.1561

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://phcccolorado.org/index.php?2015/arabtera.pdf&effpp=1&aspx=729
    • http://www.nibl.co.nz/index.php?2015/decision.pdf&angzv=1&aspx=649
    • http://phcccolorado.org/index.php?2015/arabtera.pdf&effpp=1&aspx=1892
    • http://www.academiafutebolangola.com/index.php?2015/hmdeepfocus.pdf&audtr=1&aspx=1193
    • http://www.academiafutebolangola.com/index.php?2015/hmdeepfocus.pdf&audtr=1&aspx=573
    • http://dyrlaegecentret.dk/index.php?2015/typestitch.pdf&hjhle=1&aspx=sitemap