Malicious PDF — malware analysis report

Static analysis result for SHA-256 a0bfbcba02473d08…

MALICIOUS

PDF

11.9 KB Created: 2015-07-15 14:41:54 +04:00 Authoring application: DOMPDF
MD5: 0a09806e21ccf07b37f4cbc86f6faa23 SHA-1: dd47c07123c094a0f63db4198e2046d411191c61 SHA-256: a0bfbcba02473d08d447f27b5c1af7b889c5b24ab6459c2f233f71ed3356bb15
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded URLs, indicating a link farm designed to redirect users. The heuristic 'PDF_SEO_LINK_FARM' specifically calls out the mass external PDF link farm. No scripts were extracted from this sample, but the sheer volume of URLs suggests a high likelihood of redirection to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8959

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://photo-file.ru/index.php?article=1098.1&wehsa=1&pdf=1098
    • http://weterynarz-gdynia.pl/index.php?article=2212.2&axpfr=2&pdf=2212
    • http://www.robinprime.com/index.php?article=976.1&bedxv=1&pdf=976
    • http://photo-file.ru/index.php?article=259.1&wehsa=1&pdf=259
    • http://kemerimalati.com/index.php?article=2288.3&rlrsj=3&pdf=2288
    • http://photo-file.ru/index.php?article=363.1&wehsa=1&pdf=363
    • http://egliseviechretienne.com/index.php?article=2077.5&fkyfd=5&pdf=2077
    • http://www.mantrabeautybar.ca/index.php?article=2189.1&rukbv=1&pdf=2189
    • http://konserborsasi.com/index.php?article=441.1&ntrdf=1&pdf=441
    • http://photo-file.ru/index.php?article=269.1&wehsa=1&pdf=269
    • http://photo-file.ru/index.php?article=190.1&wehsa=1&pdf=190
    • http://photo-file.ru/index.php?article=1212.1&wehsa=1&pdf=1212
    • http://urbanindoorgs.com/index.php?article=2247.1&lkbfl=1&pdf=2247
    • http://photo-file.ru/index.php?article=1014.1&wehsa=1&pdf=1014
    • http://power-team.cz/index.php?article=222.3&uwbuc=3&pdf=222
    • http://photo-file.ru/index.php?article=1130.1&wehsa=1&pdf=1130
    • http://archerwealth.com.au/index.php?article=1049.1&ldzws=1&pdf=1049