Malicious PDF — malware analysis report

Static analysis result for SHA-256 5be8bda8bf451c69…

MALICIOUS

PDF

134.4 KB Created: 2022-07-02 12:36:44 +00:00 Authoring application: hajanej (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 50ac4bf1f21db203ecd215a3a465c070 SHA-1: 58fb2cb3604cdcd1971d32b14bfefbab58e4ffcb SHA-256: 5be8bda8bf451c69e57b82495bfbcb9e5f773c32a8909e69ae18f9791de7ee88
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of external links, identified as a link farm. The primary URL, http://findinform.com/..., is likely a gateway to malicious content or further phishing attempts. The presence of numerous PDF links suggests an attempt to manipulate search engine results or distribute additional malicious files.

Machine Learning

  • Nyx PDF Classifier clean score 0.0008

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://findinform.com/ZG93bmxvYWR8bGY4WnpGNE1IeDhNVFkxTmpjeE1qTXdOWHg4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA.Q2FydGkgS2luZGxlIEluIFJvbWFuYSBHcmF0aXMQ2F?bartram=/tati/invalidated/investigate.jaehrigen?frowned=lassies
    • https://matecumberesort.net/wp-content/uploads/2022/07/raider.pdf
    • https://kuudle.com/wp-content/uploads/2022/07/fenmar.pdf
    • https://jelenalistes.com/wp-content/uploads/2022/07/marbald.pdf
    • https://vivegeek.com/wp-content/uploads/2022/07/Paris_Nights_By_Gameloft_JAVA_GAME_FOR_MOBILEl.pdf
    • https://celticminkjewelry.com/wp-content/uploads/2022/07/Sigur_Ros_Von_Full_Album_Zip_FULL.pdf
    • https://vietnammototours.com/wp-content/uploads/2022/07/Golpitha_Namdeo_Dhasal_Pdf_Download.pdf
    • https://practicalislam.online/wp-content/uploads/2022/07/Eden_Bradley_The_Dark_Garden_Pdf_Download_High_Quality.pdf
    • https://bizzbless.com/wp-content/uploads/2022/07/hainiel.pdf
    • https://img.creativenovels.com/images/uploads/2022/07/phyhelp.pdf
    • https://cafevalentustienda.com/wp-content/uploads/2022/07/Namumuro_Kana_By_Lukas_Download_HOT.pdf
    • https://rakyatmaluku.id/upload/files/2022/07/KsktNulxDFe4MzYsBO9h_02_8b565f841c307ec42df570b7d29e79b3_file.pdf
    • https://adview.ru/wp-content/uploads/2022/07/loleile.pdf
    • https://hradkacov.cz/wp-content/uploads/2022/07/kaithi.pdf
    • https://wellnessblockchainalliance.com/wp-content/uploads/2022/07/Stop_Motion_Studio_Pro_Apk_Crackedl.pdf
    • https://ubipharma.pt/wp-content/uploads/2022/07/Rs_Aggarwal_Maths_Book_Class_8_Pdf_PORTABLE.pdf
    • https://www.giantgotrip.com/wp-content/uploads/2022/07/nadphe.pdf
    • https://www.sb20ireland.com/advert/shiv-tandav-hot-full-song-mp3-download-1/
    • https://rackingpro.com/wp-content/uploads/2022/07/MedCalcv14810x64CrackedEAT_Serial_Key_TOP.pdf
    • https://openld.de/wp-content/uploads/2022/07/kylyzak.pdf
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/