Malicious PDF — malware analysis report

Static analysis result for SHA-256 6128647e1c0e325c…

MALICIOUS

PDF

123.2 KB Created: 2022-07-04 03:54:19 +00:00 Authoring application: berbelt (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 06a6ba6710dcd6bc14fa5560cbd89e20 SHA-1: 5f8a8c1ca7df5b062627dd1a23c743c84dfae688 SHA-256: 6128647e1c0e325c58f6d55f21e7a803a98be57709d68d86821eed9ed6a012f3
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of external links, many of which are advertised as cracked software. One of the embedded URIs, http://awarefinance.com/newint/eczematous.Tm90ZXBhZC5Qcm8Tm9/lanceteo.ZG93bmxvYWR8TXM2Tlhaek5IeDhNVFkxTmpnNU1qTTFNbng4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA.loudness/schwabe.tympan, appears to be a downloader for a second-stage payload. The presence of numerous links and the nature of the advertised content strongly suggest a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier clean score 0.0073

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://awarefinance.com/newint/eczematous.Tm90ZXBhZC5Qcm8Tm9/lanceteo.ZG93bmxvYWR8TXM2Tlhaek5IeDhNVFkxTmpnNU1qTTFNbng4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA.loudness/schwabe.tympan
    • https://agile-taiga-68558.herokuapp.com/MidiMaster.pdf
    • http://manukau.biz/advert/sony-xperia-companion-crack-2022/
    • http://conbluetooth.net/?p=23908
    • https://nutacademia.com/wp-content/uploads/2022/07/Barberpole_Flanger__Crack_Activation_Key_MacWin-1.pdf
    • https://dig-tal.com/wp-content/uploads/2022/07/Simulation_Exams_for_CCNP642902_formerly_CCNP_BSCI_642801_Pr.pdf
    • https://www.kisugarshop.com/wp-content/uploads/2022/07/WGCalculator.pdf
    • https://l1.intimlobnja.ru/find-favorites-win-mac/
    • https://www.cameraitacina.com/en/system/files/webform/feedback/harecric514.pdf
    • https://desolate-dawn-56881.herokuapp.com/BoostDM.pdf
    • https://homedust.com/has-gps-activation-free-latest/
    • https://dry-refuge-53410.herokuapp.com/ClipShare.pdf
    • https://chatinzone.com/upload/files/2022/07/Cki4X7eSdOSoyMaTp6bt_04_7c69e9b6a1850603aa0336cf7edd7923_file.pdf
    • https://noobkit.com/file-checksum-calculator/
    • https://paddlealberta.org/wp-content/uploads/2022/07/horapavi.pdf
    • https://morning-cliffs-31920.herokuapp.com/Vector_Action01_Icons.pdf
    • https://taxi2b.social/upload/files/2022/07/Hby2qPRNXZaWpYoobuoi_04_307516f8d8e163d4630965e161a014b3_file.pdf
    • https://nutacademia.com/wp-content/uploads/2022/07/Barberpole_Flanger_
    • https://dig-tal.com/wp-content/uploads/2022/07/Simulation_Exams_for_CCN
    • https://www.kisugarshop.com/wp-
    • https://www.cameraitacina.com/en/system/files/webform/feedback/harecric
    • https://chatinzone.com/upload/files/2022/07/Cki4X7eSdOSoyMaTp6bt_04_7
    • https://taxi2b.social/upload/files/2022/07/Hby2qPRNXZaWpYoobuoi_04_307
    • https://wakelet.com/wake/rykejpLhke9Rnq1OKOuHy
    • http://witzlinglo.yolasite.com/resources/ELMAH-Log-Analyzer-Crack--Serial-Number-Full-Torrent-For-Windows-April2022.pdf
    • https://social111.s3.amazonaws.com/upload/files/2022/07/yLadTfuKW3pXeMbDZVNu_04_b2122944440cd0c277f615c4195740fc_file.pdf
    • https://wakelet.com/wake/-vi4V10edKr3nX3g81t3v
    • http://www.tcpdf.org
    • http://witzlinglo.yolasite.com/resources/ELMAH-Log-Analyzer-Crack--Serial-
    • https://social111.s3.amazonaws.com/upload/files/2022/07/yLadTfuKW3pXe
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/