Malicious PDF — malware analysis report

Static analysis result for SHA-256 38fda94def1a62ac…

MALICIOUS

PDF

123.3 KB Created: 2022-07-08 04:02:30 +00:00 Authoring application: procata (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 33887198fd0d9cb6a809eea696a132f0 SHA-1: 3f60d98f1d19e693156f6a0be686954e76b677ad SHA-256: 38fda94def1a62ac2e0d1529d4e822ed774031d7439b664beb93e7cd7bbf658c
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which are obfuscated or lead to potentially untrusted domains. One notable URL, http://evacdir.com/campaigns/centralized.croco=ZG93bmxvYWR8YTFoWlhsemVYeDhNVFkxTnpFNE5qazFOWHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA?ravening=moneyball&U21ydCBDb3Zla2EgTmEgQmFsa2FudSAyMDEyIFRvcnJlbnQU21=sportscasting, appears to be a lure for downloading content. The heuristic PDF_SEO_LINK_FARM indicates a mass external link farm, suggesting a tactic to distribute malicious content or engage in SEO manipulation for malicious purposes.

Machine Learning

  • Nyx PDF Classifier clean score 0.0119

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://evacdir.com/campaigns/centralized.croco=ZG93bmxvYWR8YTFoWlhsemVYeDhNVFkxTnpFNE5qazFOWHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA?ravening=moneyball&U21ydCBDb3Zla2EgTmEgQmFsa2FudSAyMDEyIFRvcnJlbnQU21=sportscasting
    • https://dwfind.org/cbt-nuggets-wireshark-with-keith-barker-download-youtube-__link__/
    • https://aboutdance.com.ua/advert/actress-kajal-agarwal-sex-stories-in-exbii-top/
    • http://www.drbonesonline.com/?p=8179
    • https://promwad.com/sites/default/files/webform/tasks/patched-easeus-partition-master-v10-2-multilingual-incl-keygentsz.pdf
    • https://ghanarave.com/wp-content/uploads/2022/07/star_stable_4_nocd_crack_fs2004.pdf
    • https://cancuntoursbook.com/wp-content/uploads/2022/07/Jak_And_Daxter_Pc_Game_14_LINK.pdf
    • https://tueventoenvivo.com/xforce-keygen-32bits-or-64bits-version-vred-presenter-2016-keygen-verified/
    • https://karydesigns.com/wp-content/uploads/2022/07/Remove_WAT_V2252__Windows_7_Activation_Setup_REPACK_Freel.pdf
    • https://www.gift4kids.org/wp-content/uploads/2022/07/belytai.pdf
    • https://besttoolguide.com/2022/07/08/the-way-home-korean-movie-download-with-eng-sub-fixed/
    • https://warganesia.id/upload/files/2022/07/hBwmpOwdDxKqdf72aUB1_08_15fb6944503e04006a8a21b900b4be41_file.pdf
    • https://thedivahustle.com/wp-content/uploads/2022/07/vir2_instruments_acoustic_legends_keygen_crack.pdf
    • https://www.saint-gobain-abrasives.com/sga-common/files/webform/opensollicitatie/apache-air-assault-2010-yuplay-crack.pdf
    • https://arabamericanbusinesscommunity.org/wp-content/uploads/2022/07/ReFXVanguardVSTiv172AiR_crack.pdf
    • https://biancaitalia.it/2022/07/08/suicide-squad-english-subtitles-download-cracked/
    • https://efekt-metal.pl/witaj-swiecie/
    • http://isds.cesdev.ui.edu.ng/sites/default/files/webform/2019-remita-receipt/selreg357.pdf
    • https://hashtagiexist.com/wp-content/uploads/2022/07/Bajirao_Mastani_Movie_Download_Khatrimaza_Movies_NEW.pdf
    • http://shop.chatredanesh.ir/?p=57479
    • https://trello.com/c/TcNhLe01/97-genxsmartscan6001200dpidriversfreebest-download
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/