Malicious PDF — malware analysis report

Static analysis result for SHA-256 4500ec41c77d40a7…

MALICIOUS

PDF

87.1 KB Created: 2022-06-10 05:33:12 +02:00 Authoring application: kalamoo (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 39187c7d08ed370ecdb59b88d0fd89a0 SHA-1: 903f644694ebe5aba9b9537f342ff85e267b55ae SHA-256: 4500ec41c77d40a7db6de45f4124d099d8f439debdde36af22db605a2ff41247
64 Risk Score

Malware Insights

MITRE ATT&CK
T1059 Command and Scripting Interpreter T1204 Malicious Link

The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection mechanism. One of these links, http://evacdir.com/alonzo/exaggerating/..., appears to be a direct download URL for a file, likely a payload. The presence of these links indicates an attempt to direct users to external resources for malicious purposes.

Machine Learning

  • Nyx PDF Classifier clean score 0.0092

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://evacdir.com/alonzo/exaggerating/RG93bmxvYWQgRnJlZSBSb3VsZXR0ZSBYdHJlbWUgS2V5Z2VuIEhhY2sRG9/ZG93bmxvYWR8Zkg4TnpBd00zeDhNVFkxTkRjNE1EZzNPWHg4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA?procrastinate=fruitier=oopm=saddening
    • https://social.arpaclick.com/upload/files/2022/06/EKRGzS52pvccT5Lzb7HP_10_cec8d3f1fd2788e07be08419f4e20b55_file.pdf
    • https://fokusparlemen.id/wp-content/uploads/2022/06/Lepton_Optimizer_Full_Crack_29.pdf
    • https://rackingpro.com/performance/6839/
    • https://overmarket.pl/wp-content/uploads/2022/06/midiculous_serial.pdf
    • https://solaceforwomen.com/free-download-wilcom-es-65-designer/
    • https://tcgworldwide.org/wp-content/uploads/2022/06/corkhr.pdf
    • https://allurefashion.net/wp-content/uploads/2022/06/Cars_2_The_Video_Game_PC_RELOADED_Serial_Numberrar.pdf
    • https://malekrealty.org/extremuedit-0-7-0-exe-2/
    • https://buymecoffee.co/wp-content/uploads/2022/06/autocom_20113_keygen.pdf
    • https://reset-therapy.com/wp-content/uploads/2022/06/Melodyne_2020_Activation_Key_With_Crack_Full_Download.pdf
    • https://thebakersavenue.com/wp-content/uploads/2022/06/The_Skywalker_Saga_Special_Extended_Edition_iso.pdf
    • https://startacting.ru/?p=10316
    • https://rollercoasterfriends.be/wp-content/uploads/2022/06/nanberw.pdf
    • https://biodashofficial.com/internet-explorer-8-windows-7-download-gezginler/
    • https://4uall.net/wp-content/uploads/2022/06/autosim_200_crack_serial_36.pdf
    • https://www.rentbd.net/nammalvar-books-in-tamil-67-pdf-hot/
    • https://robertasabbatini.com/multiscatter-v1-091-for-3ds-max-2014-to-2020-win-hot/
    • https://mercatoposto.com/wp-content/uploads/2022/06/Spat_609_Final_Version_Tool_For_Sysprep_Installation_FULL.pdf
    • https://social.arpaclick.com/upload/files/2022/06/EKRGzS52pvccT5Lzb7HP_10_cec8d3f1fd2788e0
    • https://allurefashion.net/wp-
    • https://reset-therapy.com/wp-
    • https://thebakersavenue.com/wp-
    • https://mercatoposto.com/wp-
    • https://stinger-live.s3.amazonaws.com/upload/files/2022/06/5g4HTDayHGKHSCm92E6J_10_044625fc7a98a8a74dfa3b55850030cf_file.pdf
    • https://secureservercdn.net/45.40.150.81/597.5ae.myftpupload.com/wp-content/uploads/2022/06/Native_Instruments_The_Grandeur_120_Keygen.pdf?time=1654831985
    • http://www.tcpdf.org
    • https://stinger-live.s3.amazonaws.com/upload/files/2022/06/5g4HTDayHGKHSCm92E6J_10_04462
    • https://secureservercdn.net/45.40.150.81/597.5ae.myftpupload.com/wp-
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00001cc2.bin
a217f12862e0ff75203bdd4136ca0d68471050be46bb09aed5306898926ffdd4
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1CC2 120140 bytes