PDF static analysis report

Static analysis result for SHA-256 00a65db3d27b82bf…

SUSPICIOUS

PDF

123.6 KB Created: 2022-07-04 00:48:37 +00:00 Authoring application: hanfkar (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 11ee4eb7bf5876a157d21df49989add0 SHA-1: c862e129f41e163ff1faabd43ee9a91f4b643354 SHA-256: 00a65db3d27b82bf6c2dd167a7d52e20ec845d48fa1b1403238f08daccd8454c
34 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains heuristics indicating it advertises cracked software, with one heuristic specifically pointing to the URL http://www.kitesurfingkites.com/metalmouse-crack-full-product-key/. Additionally, an external URI was found pointing to http://seachtop.com/fellowman/footrests?ZG93bmxvYWR8RTJhTVdFMk5ueDhNVFkxTmpnNU1qTTFNbng4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA=shatters&distinctively=&VkFsYXJtVkF=procumbens, suggesting a lure to download malicious content. The document body is heavily obfuscated and does not provide further clues.

Machine Learning

  • Nyx PDF Classifier clean score 0.0006

Heuristics 3

  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seachtop.com/fellowman/footrests?ZG93bmxvYWR8RTJhTVdFMk5ueDhNVFkxTmpnNU1qTTFNbng4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA=shatters&distinctively=&VkFsYXJtVkF=procumbens PDF link annotation
    • https://www.careerfirst.lk/sites/default/files/webform/cv/SendToAny.pdfIn PDF document text
    • https://www.cameraitacina.com/en/system/files/webform/feedback/winhex.pdfIn PDF document text
    • https://homeoenergy.com/wp-content/uploads/2022/07/Complete_Program_Deleter.pdfIn PDF document text
    • https://www.imoc.cc/wp-content/uploads/2022/07/Black_Menu_for_Wikipedia_for_Opera.pdfIn PDF document text
    • https://guaraparadise.com/2022/07/03/magic-view-and-converter-license-code-keygen-free-download-2022/In PDF document text
    • https://shravasti.fastnews24x7.com/advert/kdt-soft-recover-product-key-crackIn PDF document text
    • https://enricmcatala.com/impressrunner-crack-with-product-key/In PDF document text
    • https://anthonybwashington.com/zoe-crack-serial-key/In PDF document text
    • https://entrelink.hk/interview/pasco-download-2022/In PDF document text
    • http://blnovels.net/?p=18457In PDF document text
    • https://cecj.be/lightscribe-windows-public-sdk-crack-license-keygen-2022/In PDF document text
    • https://rodillosciclismo.com/sin-categoria/dbforge-data-compare-for-oracle-standard-edition-torrent/In PDF document text
    • http://www.kitesurfingkites.com/metalmouse-crack-full-product-key/In PDF document text
    • https://harneys.blog/2022/07/04/nepali-radios-online-crack-with-keygen-pc-windows/In PDF document text
    • https://gjurmet.com/wp-content/uploads/2022/07/Management_of_Access_Control_in_the_Enterprise.pdfIn PDF document text
    • https://www.naethompsonpr.com/wp-content/uploads/2022/07/Karaoke_Mixer__Crack__Keygen_For_LifeTime_Free_Download_Updated_2022.pdfIn PDF document text
    • https://used-gensets.com/advert/fx-audio-editor-crack-license-code-keygen-free-mac-win/In PDF document text
    • https://www.paylessdvds.com/microsoft-platform-ready-test-tool-crack-with-keygen-for-windows/In PDF document text
    • https://guaraparadise.com/2022/07/03/magic-view-and-converter-license-code-keygen-free-In PDF document text
    • https://gjurmet.com/wp-In PDF document text
    • https://www.naethompsonpr.com/wp-content/uploads/2022/07/Karaoke_Mixer__Crack__Keygen_For_LIn PDF document text
    • http://mobume.yolasite.com/resources/Check-Yahoo-Status.pdfIn PDF document text
    • https://peohemoudupkind.wixsite.com/leigraphunin/post/autocompress-crack-for-pcIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text