Malicious PDF — malware analysis report

Static analysis result for SHA-256 a5017b8dd2ae525b…

MALICIOUS

PDF

12.2 KB Created: 2015-07-15 14:36:53 +04:00 Authoring application: DOMPDF First seen: 2015-08-03
MD5: 4934d39ffd9763a7f4dde9974e8fa3ae SHA-1: dc2df82f55c75d73c78e3adadb91459ac5b2201d SHA-256: a5017b8dd2ae525b45bedfdb84dc08e3daf96aac89c7e327199e54fc9777f2b9
92 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.8883

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://photo-file.ru/index.php?article=1615.1&wehsa=1&pdf=1615 In PDF document text
    • http://healthcare2-concepts.com/index.php?article=1309.1&syyyl=1&pdf=1309In PDF document text
    • http://gradespay.com/index.php?article=1549.1&cibeh=1&pdf=1549In PDF document text
    • http://photo-file.ru/index.php?article=800.1&wehsa=1&pdf=800In PDF document text
    • http://pleasereadbible.com/index.php?article=1619.1&ofdkh=1&pdf=1619In PDF document text
    • http://photo-file.ru/index.php?article=2167.1&wehsa=1&pdf=2167In PDF document text
    • http://xserve-online.de/index.php?article=1906.1&yucuw=1&pdf=1906In PDF document text
    • http://quraniarbi.com/index.php?article=968.2&sbfeb=2&pdf=968In PDF document text
    • http://www.mantrabeautybar.ca/index.php?article=744.1&rukbv=1&pdf=744In PDF document text
    • http://photo-file.ru/index.php?article=75.1&wehsa=1&pdf=75In PDF document text
    • http://photo-file.ru/index.php?article=1984.1&wehsa=1&pdf=1984In PDF document text
    • http://photo-file.ru/index.php?article=1853.1&wehsa=1&pdf=1853In PDF document text
    • http://londonfilmandcomiccon.net/index.php?article=656.2&ybtwx=2&pdf=656In PDF document text
    • http://photo-file.ru/index.php?article=1566.1&wehsa=1&pdf=1566In PDF document text
    • http://ipestka.pl/index.php?article=719.1&qsxtx=1&pdf=719In PDF document text
    • http://photo-file.ru/index.php?article=2498.1&wehsa=1&pdf=2498In PDF document text
    • http://www.myrlimo.com/index.php?article=52.1&sqfkb=1&pdf=52In PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_000_off000002fd.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2FD 13212 bytes
SHA-256: f2d46a5cf83dab8ee66bbf5712d5e057bce096e788200362160a69e09b4c6f2d