Malicious PDF — malware analysis report

Static analysis result for SHA-256 330161add7a3f1a0…

MALICIOUS

PDF

144.6 KB Created: 2022-07-05 16:19:21 +00:00 Authoring application: waltali (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 1c7873f47bd1132f2f098ec2874b2ec0 SHA-1: 80a549bce6d522a2649b20accf480ec925b01cee SHA-256: 330161add7a3f1a0ecb2160790cdd2bab7ad1ac4fb99a27e733606527e694a4a
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, many of which appear to be part of an SEO link farm. The primary heuristic indicates a mass of external PDF links, suggesting a tactic to drive traffic to potentially malicious or SEO-manipulated sites. The embedded URLs and the document's structure point towards a malicious intent to redirect users.

Machine Learning

  • Nyx PDF Classifier clean score 0.0047

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://widesearchengine.com/RmlmYSAyMgRml/misinterpretation.comprehensibility=constraint.ZG93bmxvYWR8OHE4ZG14d2ZId3hOalUzTURNMk1qSXpmSHd5TlRjMGZId29UU2tnY21WaFpDMWliRzluSUZ0R1lYTjBJRWRGVGww?seasickness=financingyourcar&mance=sedan
    • https://lordwillprovide.com/wp-content/uploads/2022/07/Fifa_22-1.pdf
    • http://saddlebrand.com/?p=43695
    • https://www.scet-tunisie.com/sites/default/files/webform/condidature_offre/_sid_/Fifa-22_0.pdf
    • http://uggla.academy/elearn/blog/index.php?entryid=3758
    • http://www.wellbeingactivity.com/2022/07/05/fifa-22-crack-keygen-product-key-full-free-win-mac/
    • https://yaapoo.com/upload/files/2022/07/vqzMd4xx9naAjQobkCQm_05_0fd49c7cefe079b3c8808d9e0ecbcf91_file.pdf
    • https://workerspros.com/wp-content/uploads/2022/07/lillquan.pdf
    • https://www.handmademarket.de/wp-content/uploads/2022/07/Fifa_22_Crack_File_Only__Serial_Key_Download_PCWindows.pdf
    • https://ventnortowers.com/wp-content/uploads/2022/07/elidarv.pdf
    • http://amlakzamanzadeh.com/wp-content/uploads/2022/07/Fifa_22_Incl_Product_Key.pdf
    • https://www.marshfield-ma.gov/sites/g/files/vyhlif3416/f/pages/final_fy23_budget_presentation_powerpoint.pdf
    • https://ideaboz.com/2022/07/05/fifa-22-torrent-activation-code-x64-latest-2022/
    • http://zakadiconsultant.com/?p=13540
    • http://youngindialeadership.com/?p=10485
    • https://www.idhealthagency.com/skin-care/fifa-22-download-mac-win-march-2022/
    • https://drogueriaconfia.com/fifa-22-free-download-x64/
    • https://www.northyarmouth.org/sites/g/files/vyhlif1006/f/uploads/curbside_pickup_schedule1.pdf
    • https://qeezi.com/advert/fifa-22-crack-mega/
    • https://yaapoo.com/upload/files/2022/07/vqzMd4xx9naAjQobkCQm_05_0fd49c7cefe079b3c8808d9e0
    • https://www.handmademarket.de/wp-
    • https://www.marshfield-
    • https://www.esma.europa.eu/sites/default/files/library/esma71-99-1971_fourth_esma_ccp_stress_test_results_press_release.pdf
    • https://7smabu2.s3.amazonaws.com/upload/files/2022/07/J3FGNFUTviLKQaalp6Ox_05_cd14aab910e0d9ba5daa073d79f7b086_file.pdf
    • http://www.tcpdf.org
    • https://www.esma.europa.eu/sites/default/files/library/esma71-99-1971_fourth_esma_ccp_stress_test
    • https://7smabu2.s3.amazonaws.com/upload/files/2022/07/J3FGNFUTviLKQaalp6Ox_05_cd14aab910e
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/