Malicious PDF — malware analysis report

Static analysis result for SHA-256 42dd75f8c4688700…

MALICIOUS

PDF

145.5 KB Created: 2022-07-03 13:59:46 +00:00 Authoring application: perrei (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 79c561f1ff7b72e7df98cb3b1317d030 SHA-1: d77b2900fbb5e60b6ec79f9a5c9d8d1cad78cb8f SHA-256: 42dd75f8c4688700691208cd0288847e5bca87f1114795475668c77e767cf731
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a significant number of external links, many of which are categorized as unknown reputation, suggesting a link farm or redirection scheme. One critical heuristic firing, PDF_SEO_LINK_FARM, indicates the PDF is designed to host numerous external links, likely for SEO poisoning or to distribute malware. The presence of a URL pointing to 'findthisall.com' further supports the malicious intent of directing users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier clean score 0.0043

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://findthisall.com/ZmlybXdhcmUgdXBkYXRlIGlubm92YSAzMTMwZml/slinky.ZG93bmxvYWR8MU12ZEhkdE5ueDhNVFkxTmpjM01UZ3hPSHg4TWpVNE4zeDhLRTBwSUVobGNtOXJkU0JiUm1GemRDQkhSVTVk/fitnessyou.hardpan?levy=eitan
    • https://damp-headland-81601.herokuapp.com/Driver_Samsung_Syncmaster_P2450_23.pdf
    • http://buyzionpark.com/?p=28561
    • https://www.cr-comores.org/wp-content/uploads/2022/07/ReLoader_Activator_V128_FINAL_Windows_Office_Activator.pdf
    • https://nashvilleopportunity.com/stonecoldrobertswindellsebookfreedownload-2021/
    • https://bodhirajabs.com/wp-content/uploads/2022/07/Aces_Of_The_Luftwaffe__Squadron_Extended_Edition_Full_Crack_.pdf
    • http://educationalliance.org/2022/07/kuch-khatti-kuch-meethi-video-720p-hd/
    • http://annarborholistic.com/wp-content/uploads/2022/07/cryflo.pdf
    • https://studiolegalefiorucci.it/2022/07/03/taiji-37-postures-martial-applications-downloadgolkes-_hot_/
    • https://homeimproveinc.com/wp-content/uploads/2022/07/tvs_msp_series_printer_driver_for_windows_7_free_download.pdf
    • https://selam.et/upload/files/2022/07/yW3db2pvsCLZkNDSwBQw_03_675ec8630d46b44ec5b6346c282c9ec4_file.pdf
    • http://www.vinergie.net/wp-content/uploads/2022/07/X_Force_Keygen_Fabrication_CAMduct_2014_Free_Download_Dmg.pdf
    • https://glacial-reaches-55148.herokuapp.com/padayappafullmovietamilhd1080p.pdf
    • http://elstar.ir/2022/07/03/descargar-crash-nitro-kart-para-psp-cso/
    • https://online-kassa.store/online-kassy/alien-shooter-revisited-full-link-crack-link-crack/
    • https://serene-retreat-29953.herokuapp.com/Serial_Number_Magix_Samplitude_Pro_X_Suite_120059.pdf
    • https://nicic.gov/system/files/webform/ta-request/elisabry672.pdf
    • https://allindiaherb.com/fm-2009-patch-9-3-1-upd-crack/
    • https://juliepetit.com/windows-server-2012-r2-language-pack-download-portable/
    • https://www.eventogo.com/boris-fx-sapphire-plug-ins-for-after-effects-ofx-2019-02/
    • http://awaazsachki.com/?p=40817
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/