PDF static analysis report

Static analysis result for SHA-256 28833e7541dff5e3…

SUSPICIOUS

PDF

153.0 KB Created: 2022-07-05 01:05:12 +00:00 Authoring application: valvawn (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 35f478a567617e57c46383cbb977ef00 SHA-1: 68a8c0b81318950bbfbae6bcd6a8153b38a4f4c6 SHA-256: 28833e7541dff5e3ce3e2e42ac8abcbcefefc57dde81151046fd8ab43304d5d5
34 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious Link

The PDF document contains multiple embedded URLs and heuristic firings indicating a lure for cracked software. Specifically, the PDF_CRACKED_SOFTWARE_LURE heuristic fired, along with several external URI findings, pointing to sites offering pirated software like Adobe Photoshop. The document body itself is heavily obfuscated and does not provide direct textual lures.

Machine Learning

  • Nyx PDF Classifier clean score 0.0086

Heuristics 3

  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://siteslocate.com/akers/QWRvYmUgUGhvdG9zaG9wIENDIDIwMTUgdmVyc2lvbiAxOAQWR/blackfooted/cruised/glenwood./mulberries/ZG93bmxvYWR8YVM1YW13NWZId3hOalUyT1RneE5UQTBmSHd5TlRjMGZId29UU2tnY21WaFpDMWliRzluSUZ0R1lYTjBJRWRGVGww/propio.coulson PDF link annotation
    • https://wmondemand.com/?p=17954In PDF document text
    • https://dev.izyflex.com/advert/adobe-photoshop-2022-crack-with-serial-number-download/In PDF document text
    • http://cirelliandco.com/?p=4109In PDF document text
    • https://digipal.ps/blog/index.php?entryid=5040In PDF document text
    • http://www.cpakamal.com/photoshop-2021-version-22-3-activation-keygen-for-lifetime-macwin-latest-2022/In PDF document text
    • https://poliestudios.org/campus2022/blog/index.php?entryid=2949In PDF document text
    • https://blooming-scrubland-14822.herokuapp.com/otewill.pdfIn PDF document text
    • https://www.cchb.fr/wp-content/uploads/Photoshop_2021_Version_222_keygen_only_.pdfIn PDF document text
    • https://propertynet.ng/adobe-photoshop-2021-version-22-0-0-free-latest-2022/In PDF document text
    • http://meowmeowcraft.com/2022/07/05/adobe-photoshop-2022-version-23-2-activation-key-for-windows-latest-2022/In PDF document text
    • https://libertinosdaalcova.com/adobe-photoshop-cc-2015-version-18-crack-license-code-keygen-free-download-updated-2022/In PDF document text
    • http://bookmanufacturers.org/wp-content/uploads/2022/07/Adobe_Photoshop_2022_Version_2302.pdfIn PDF document text
    • https://instafede.com/adobe-photoshop-2020-for-pc/In PDF document text
    • https://hochzeiten.de/wp-content/uploads/2022/07/Adobe_Photoshop_CC_2015_Version_17_With_Product_Key.pdfIn PDF document text
    • https://ystym.com/wp-content/uploads/2022/07/Adobe_Photoshop_CC_2015.pdfIn PDF document text
    • http://descargatelo.net/?p=28614In PDF document text
    • https://www.aulavirtual.icaf.cl/blog/index.php?entryid=3102In PDF document text
    • https://alluring-capitol-reef-54639.herokuapp.com/Adobe_Photoshop.pdfIn PDF document text
    • https://expressionpersonelle.com/adobe-photoshop-2021-version-22-2-crack-patch-product-key-full-pc-windows-latest/In PDF document text
    • https://hgpropertysourcing.com/photoshop-2021-version-22-3-serial-key-activation-code-with-keygen-download-for-pc-updated-2022/In PDF document text
    • https://certificacionbasicamedicina.com/blog/index.php?entryid=3041In PDF document text
    • https://www.mozideals.com/advert/photoshop-2021-version-22-1-0-crack-serial-number/In PDF document text
    • https://poker.new/blog/adobe-photoshop-2021-version-22-5-full-license-with-serial-key-download/In PDF document text
    • https://www.tmwltd.ca/sites/default/files/webform/darljon296.pdfIn PDF document text
    • http://www.cpakamal.com/photoshop-2021-version-22-3-activation-keygen-for-lifetime-macwin-In PDF document text
    • http://meowmeowcraft.com/2022/07/05/adobe-photoshop-2022-version-23-2-activation-key-for-In PDF document text
    • https://libertinosdaalcova.com/adobe-photoshop-cc-2015-version-18-crack-license-code-keygen-free-In PDF document text
    • https://hochzeiten.de/wp-In PDF document text
    • https://expressionpersonelle.com/adobe-photoshop-2021-version-22-2-crack-patch-product-key-full-In PDF document text
    • https://hgpropertysourcing.com/photoshop-2021-version-22-3-serial-key-activation-code-with-keygen-In PDF document text
    • http://comlemelt.yolasite.com/resources/Adobe-Photoshop-2021-Version-2201-Crack--Serial-Number-.pdfIn PDF document text
    • https://sigenciterdelimoga.wixsite.com/abidup/post/photoshop-2022-version-23-0-1-april-2022In PDF document text
    • https://landconsdigapo.wixsite.com/kingformthingha/post/photoshop-cc-keygen-crack-serial-key-x64In PDF document text
    • https://rennistpropwouma.wixsite.com/quidianimid/post/adobe-photoshop-cc-2018-with-license-key-lifetime-activation-code-32-64bit-latestIn PDF document text
    • http://frosenar.yolasite.com/resources/Photoshop-2021-Version-2251-Crack-Keygen--2022-New.pdfIn PDF document text
    • https://www.cakeresume.com/portfolios/adobe-photoshop-2021-nulled-download-updatedIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://comlemelt.yolasite.com/resources/Adobe-Photoshop-2021-Version-2201-Crack--Serial-In PDF document text
    • https://rennistpropwouma.wixsite.com/quidianimid/post/adobe-photoshop-cc-2018-with-license-key-In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text
    • http://comlemelt.yolasite.com/resources/adobe-photoshop-2021-version-2201-crack--serial-number-.pdfIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_022_off0001db98.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1DB98 119072 bytes
SHA-256: df221e87b81d1531cafdadb6c09a602e9f604d1baf0a17bbd350cbb83baa06f7