Malicious PDF — malware analysis report

Static analysis result for SHA-256 384ecd8c8af7f28e…

MALICIOUS

PDF

123.3 KB Created: 2022-07-06 22:16:03 +00:00 Authoring application: darsal (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: a6f16cc74ce5fb97cc8cdbd2695768c0 SHA-1: c9689df60539926a1afc1c0774f6bd2039ca2ab4 SHA-256: 384ecd8c8af7f28ebc22aa31f91032ccb9137e7de2d3405f7d569ca76fc83eb0
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, indicated by the PDF_SEO_LINK_FARM heuristic. One of the primary external URIs points to 'emailgoal.com', which is likely part of a malicious infrastructure. The document body is heavily obfuscated and does not provide clear textual lures, but the sheer volume of links suggests a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier clean score 0.0101

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://emailgoal.com/anarchy.delisted/morrall/Y2FkaW1hZ2V0b29sc2ZvcmFyY2hpY2FkMTIxNAY2F.ZG93bmxvYWR8dDY3YjNWblpueDhNVFkxTnpBMk56RTFOSHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA/coppola?francophone
    • https://plumive.com/upload/files/2022/07/DqGORTvIL11k9CbIsMbe_06_ae2fc36423b19a18a1acf7dd7cc73ad7_file.pdf
    • https://www.yflyer.org/advert/full-microsoft-visual-basic-6-0-full-multilenguaje-msdn-library-better/
    • http://mirrordancehair.com/?p=2723
    • http://latinon.com/?p=4807
    • http://sourceofhealth.net/2022/07/07/htc-hd2-ruu-leo-htc-wwe-1-48-405-14/
    • https://burmarauto.com/fifa-2006-full-rip-pc-exe-better/
    • http://galaxy7music.com/?p=51754
    • https://technospace.co.in/upload/files/2022/07/2WX5MHn8BlsEfxWg134T_06_ae2fc36423b19a18a1acf7dd7cc73ad7_file.pdf
    • https://workplace.vidcloud.io/social/upload/files/2022/07/RLFwMoZAmY1JMJnX7AbZ_06_ae2fc36423b19a18a1acf7dd7cc73ad7_file.pdf
    • https://palqe.com/upload/files/2022/07/y1BaSdBbdt12RuFWyyPv_06_ae2fc36423b19a18a1acf7dd7cc73ad7_file.pdf
    • https://bluesteel.ie/2022/07/06/paws-and-soul-t-rk-e-yama-download-better/
    • https://bodhibliss.org/satazius-free-download-full-version-repack/
    • https://lannews.net/advert/big-fish-games-crack-hot-keygen-20/
    • https://acsa2009.org/advert/youtube-movie-maker-platinum-16-21/
    • https://www.orion4u.nl/venice-deluxe-_best_-crack-full-version-download/
    • https://ebbsarrivals.com/2022/07/06/sh-d163b-sb01-kreon-v100-rar-2/
    • http://demoforextrading.com/?p=17982
    • https://cashonhomedelivery.com/mobiles/neoragex52aofficialhot-fullsetallromsneogeo188gamesrar/
    • https://plumive.com/upload/files/2022/07/DqGORTvIL11k9CbIsMbe_06_ae2fc36423b19a18a1acf7dd7
    • https://technospace.co.in/upload/files/2022/07/2WX5MHn8BlsEfxWg134T_06_ae2fc36423b19a18a1a
    • https://workplace.vidcloud.io/social/upload/files/2022/07/RLFwMoZAmY1JMJnX7AbZ_06_ae2fc36423b
    • https://palqe.com/upload/files/2022/07/y1BaSdBbdt12RuFWyyPv_06_ae2fc36423b19a18a1acf7dd7cc
    • https://bfacer.s3.amazonaws.com/upload/files/2022/07/yKrloIo3FerkEcdi2lpv_06_1b5e92d9e46c69a213fa8c8665556de3_file.pdf
    • https://wakelet.com/wake/MCj4FFMT9xipjxl2V9739
    • http://www.tcpdf.org
    • https://bfacer.s3.amazonaws.com/upload/files/2022/07/yKrloIo3FerkEcdi2lpv_06_1b5e92d9e46c69a2
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/