Malicious PDF — malware analysis report

Static analysis result for SHA-256 cdb6b62bb473519e…

MALICIOUS

PDF

4.5 KB Created: 2015-06-03 16:40:16 +03:00 Authoring application: DOMPDF
MD5: 690a1864498599bf1c29ef56de69aee9 SHA-1: 29e7186d9e8c974978b12a6d4d35a79ad54d1dbc SHA-256: cdb6b62bb473519e08cb57fc7f1552dfcf736c794ae1ff2e13d4ce0dc33030a9
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was identified as malicious due to a critical heuristic firing for a PDF SEO link farm. The document body contains numerous embedded URLs, all of which are external links. These links appear to be part of a strategy to manipulate search engine results or redirect users to potentially harmful websites. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.kbb-gesellschaft.de/index.php?2015/ergoarena.pdf&urggv=1&aspx=133
    • http://www.nibl.co.nz/index.php?2015/decision.pdf&angzv=1&aspx=1443
    • http://www.prequine.com/index.php?2015/torcida.pdf&fcldj=1&aspx=588
    • http://www.prequine.com/index.php?2015/torcida.pdf&fcldj=1&aspx=1975
    • http://www.academiafutebolangola.com/index.php?2015/hmdeepfocus.pdf&audtr=1&aspx=967
    • http://dyrlaegecentret.dk/index.php?2015/typestitch.pdf&hjhle=1&aspx=sitemap