Malicious PDF — malware analysis report

Static analysis result for SHA-256 1afe91eebf91b0da…

MALICIOUS

PDF

117.0 KB Created: 2022-07-04 08:02:35 +00:00 Authoring application: kerrglen (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 59c14867598ccef48bdba9562c2c48b0 SHA-1: 39b247fb7a94c727a61e29e07f551d213906e70b SHA-256: 1afe91eebf91b0da8451bd20614f62bc2a2a2f16389f819a6a0bff36c1be797e
74 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains multiple heuristics indicating it is a lure for cracked software and potentially a password-protected archive. It embeds numerous URLs, several of which are associated with software cracks and downloads. The presence of these lures suggests the document's primary purpose is to trick users into visiting malicious sites, likely to download further malicious payloads or compromise their systems.

Machine Learning

  • Nyx PDF Classifier clean score 0.0119

Heuristics 4

  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bestentrypoint.com/supplementaries&unanimous.lunge.madrasa.singlehandedly?TWF0cm9za2EgVW5wYWNrZXITWF=ZG93bmxvYWR8cWcxWW5Wb2RueDhNVFkxTmpnNU1qTTFNbng4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA PDF link annotation
    • http://www.tenutacostarossa.it/subtitles-converter-crack-free-download-for-pc-latest-2022/In PDF document text
    • https://nashvilleopportunity.com/enkrypto-for-windows-10-8-1-crack-with-registration-code/In PDF document text
    • https://newzspy.com/az-image-to-pdf-converter-5-4-0-0-crack-for-windows/In PDF document text
    • https://verrtise.com/advert/windows-movie-maker-and-windows-dvd-maker-sdk-crack-download/In PDF document text
    • https://pregnancyweekla.com/keyrocket-crack-download-mac-win-march-2022/In PDF document text
    • https://lacartadecervezas.com/queuemonitor-professional-1-0-0-crack-download-april-2022/In PDF document text
    • https://waoop.com/upload/files/2022/07/woySK6NCbo9RlI3svna5_04_1b5d76e069fea913dc65676e2a03d449_file.pdfIn PDF document text
    • https://chateaudelacazette.fr/?p=3695In PDF document text
    • http://shoplidaire.fr/?p=158122In PDF document text
    • https://technospace.co.in/upload/files/2022/07/SARGSRNHPzncUJRSLPEc_04_220f42220943f3ecb1bc87e65aa97520_file.pdfIn PDF document text
    • http://www.fiscalsponsor.net/wp-content/uploads/2022/07/cayfin.pdfIn PDF document text
    • https://marketstory360.com/news/46099/excel-xls-and-xlsx-to-dbf-converter-software-crack-full-product-key-free-download-win-mac-2022/In PDF document text
    • https://theludwigshafen.com/pixet-crack-win-mac/In PDF document text
    • https://firmateated.com/2022/07/04/ripmycds-crack-mac-win-2022-latest/In PDF document text
    • https://protected-inlet-72999.herokuapp.com/nadrgar.pdfIn PDF document text
    • https://epkrd.com/wp-content/uploads/2022/07/Cryptomator_.pdfIn PDF document text
    • http://getakart.com/wp-content/uploads/2022/07/amovalo.pdfIn PDF document text
    • https://www.7desideri.it/a-paper-crack-download-win-mac-2022/In PDF document text
    • https://young-tundra-14518.herokuapp.com/Tileset_Generator_Planet.pdfIn PDF document text
    • https://calibikemedia.s3.us-west-1.amazonaws.com/wp-content/uploads/2022/07/04010233/Freebyte_Zip_Crack___Updated_2022.pdfIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text