Malicious PDF — malware analysis report

Static analysis result for SHA-256 20037f2e32a36729…

MALICIOUS

PDF

124.4 KB Created: 2022-07-06 02:10:14 +00:00 Authoring application: wahhfur (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: ef4382e2573f5671774df71fc1b79100 SHA-1: ae7fb290e654bd702db2826a41b6a19ace041022 SHA-256: 20037f2e32a36729253a99f9b8fc82137b7ec61d8be4f1434f94192ef61284d8
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection strategy. One notable URL, http://hardlyfind.com/appy/TWFzdGVyY2FtIFg3IHYxNiAwIDUgNSAtMzJiaXQtNjRiaXQTWF/workload/ZG93bmxvYWR8cjhkTW5oelpYeDhNVFkxTnpBMk56RTFOSHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA=reeves.polystyrene, is directly embedded and likely serves as a download or redirect point. The presence of numerous links indicates an attempt to distribute malicious content or lead users to phishing sites.

Machine Learning

  • Nyx PDF Classifier clean score 0.0068

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://hardlyfind.com/appy/TWFzdGVyY2FtIFg3IHYxNiAwIDUgNSAtMzJiaXQtNjRiaXQTWF/workload/ZG93bmxvYWR8cjhkTW5oelpYeDhNVFkxTnpBMk56RTFOSHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA=reeves.polystyrene
    • https://papayu.co/download-pb-launcher-exe-epub-free/
    • https://workuccino.com/wp-content/uploads/2022/07/Software_Ht_Motorola_Ats_2500.pdf
    • http://www.flexcompany.com.br/flexbook/upload/files/2022/07/BZJ5yB8fsD4TMHmknw25_06_dac52853da24fd999d2957bfb671b35a_file.pdf
    • https://aghadeergroup.com/2022/07/06/tmpgenc-authoring-works-5-jp-keygen-link/
    • http://fixforpc.ru/circle-track-analyzer-3-6-updated/
    • https://citywharf.cn/ajay-yadav-anaesthesia-pdf-download-better/
    • http://www.mick0711.com/2022/07/05/full-crack-acdsee-pro-2-0-238-acdsee-photo-manager-10-0-238-serials/
    • http://freemall.jp/axasoft-cari-hesap-takip-3-0-6-crack-2021.html
    • https://bodhibliss.org/adobedimensioncc2018v1010crack-topcrack-topsnow64bit/
    • https://globaltechla.com/ziarah-iwan-simatupang-pdf-download-extra-quality/
    • http://iconnmedia.com/surah-al-baqarah-pdf/
    • https://aula.ciapse.edu.pe/blog/index.php?entryid=24271
    • https://playerclub.app/upload/files/2022/07/vOmUIdRr3MXzo76qALgD_06_dac52853da24fd999d2957bfb671b35a_file.pdf
    • https://ksycomputer.com/how-to-display-two-subtitles-simultaneously-in-vlc-on-windows-10/
    • https://ictlife.vn/upload/files/2022/07/O4f1h2AqqPrlEiQ1cPOg_06_dac52853da24fd999d2957bfb671b35a_file.pdf
    • https://iamjoburg.africa/wp-content/uploads/2022/07/Anti_Deep_REPACK_Freeze_06rar.pdf
    • http://fantasysportsolympics.com/wp-content/uploads/2022/07/GM_Forge__Virtual_Tabletop_Crack_Serial_Key.pdf
    • https://plumive.com/upload/files/2022/07/7WuWBzCZiFcHA81NzGrp_06_dac52853da24fd999d2957bfb671b35a_file.pdf
    • http://www.flexcompany.com.br/flexbook/upload/files/2022/07/BZJ5yB8fsD4TMHmknw25_06_dac528
    • http://www.mick0711.com/2022/07/05/full-crack-acdsee-pro-2-0-238-acdsee-photo-
    • https://playerclub.app/upload/files/2022/07/vOmUIdRr3MXzo76qALgD_06_dac52853da24fd999d2957
    • https://ictlife.vn/upload/files/2022/07/O4f1h2AqqPrlEiQ1cPOg_06_dac52853da24fd999d2957bfb671b
    • http://fantasysportsolympics.com/wp-
    • https://plumive.com/upload/files/2022/07/7WuWBzCZiFcHA81NzGrp_06_dac52853da24fd999d2957bf
    • https://trello.com/c/FsA2eqW5/56-zortam-mp3-media-studio-full-version-latest-crack-download-top
    • https://trello.com/c/UeAH1EHR/117-select-reading-intermediate-answer-key-pointeur-bootable-ho-exclusive
    • http://www.tcpdf.org
    • https://trello.com/c/UeAH1EHR/117-select-reading-intermediate-answer-key-pointeur-bootable-ho-
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/