Malicious PDF — malware analysis report

Static analysis result for SHA-256 62ee2602d05936ab…

MALICIOUS

PDF

128.6 KB Created: 2022-07-05 03:03:16 +00:00 Authoring application: palivon (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: a92015158dfe6f2b5c5bf433b8643000 SHA-1: ccda7564c511fea96eecb21e3abfb308cb84525a SHA-256: 62ee2602d05936ab16faca7969de20eee27319137f38de403e2e678e4115e357
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of external links, many of which advertise cracked or pirated software. The primary URL, http://awarefinance.com/canvas/..., appears to be a landing page for downloading such software. This suggests the document is designed to trick users into visiting malicious or untrustworthy sites under the guise of obtaining free software.

Machine Learning

  • Nyx PDF Classifier clean score 0.0087

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://awarefinance.com/canvas/QWRvYmUgUGhvdG9zaG9wIENDIDIwMTkQWR/millennium?honeymooner=ZG93bmxvYWR8b1cyTTNoa2NYeDhNVFkxTmprNE1UVXdOSHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA=hazcom=noses
    • https://aalcovid19.org/photoshop-2022-version-23-0-1-install-crack-full-version-free-download-pc-windows/
    • https://merryquant.com/photoshop-cc-2019-version-20-crack-activation-code-download-mac-win/
    • https://ssmecanics.com/adobe-photoshop-2021-version-22-4-2/
    • https://leidenalumni.id/wp-content/uploads/2022/07/Adobe_Photoshop_2022_Version_231_Key_Generator__With_Full_Keygen_X64.pdf
    • http://www.sparepartsdiesel.com/upload/files/2022/07/Kg1VP4LL5s6xWqmGIv7O_05_e0287ee3b2b59980d46df66a48a0d3d7_file.pdf
    • http://iled.in/wp-content/uploads/2022/07/ignamar.pdf
    • https://fmpconnect.com/wp-content/uploads/2022/07/tonialb.pdf
    • https://panda-app.de/upload/files/2022/07/RkdrjrszDVBVzjbcFBhC_05_a53fa0e955dbdc3f2a3a134def9954ae_file.pdf
    • https://www.blackhistoryinthebible.com/wp-content/uploads/2022/07/Photoshop_2021_Version_223_universal_keygen___Torrent_Download_PCWindows_Latest.pdf
    • https://artienz.com/upload/files/2022/07/hvXake77ryPWBYsGMEuc_05_a53fa0e955dbdc3f2a3a134def9954ae_file.pdf
    • http://montehogar.com/?p=29771
    • https://digibattri.com/photoshop-cs5-keygenerator-full-product-key-2022/
    • https://nashvilleopportunity.com/wp-content/uploads/2022/07/egymarc.pdf
    • https://everynon.com/adobe-photoshop-2021-version-22-2-crack-exe-file-torrent-activation-code-download-march-2022/
    • https://lobenicare.com/adobe-photoshop-express-crack-with-serial-number-activator-download-for-windows/
    • https://tuinfonavit.xyz/adobe-photoshop-2021-hack-patch-mac-win/
    • https://www.mil-spec-industries.com/system/files/webform/Adobe-Photoshop-2022-Version-231_13.pdf
    • https://expressionpersonelle.com/adobe-photoshop-2021-version-22-1-0-activation-download-3264bit-updated-2022/
    • https://storage.googleapis.com/paloodles/upload/files/2022/07/gpfObZyRXAtEh62LDphs_05_c0cc562631b52cbf0e81fa2224d0882d_file.pdf
    • https://blaquecat.com/community/upload/files/2022/07/siPE2jsAsGzXKy9HxW2h_05_e0287ee3b2b59980d46df66a48a0d3d7_file.pdf
    • https://ebbsarrivals.com/2022/07/05/photoshop-cc-2015-download/
    • http://texocommunications.com/adobe-photoshop-cc-crack-exe-file-with-product-key-for-windows-updated/
    • http://jameschangcpa.com/advert/photoshop-2022-version-23-4-1-crack-download-march-2022/
    • https://efekt-metal.pl/witaj-swiecie/
    • http://demo.funneldrivenroi.com/council/upload/files/2022/07/Eq365QFJY36ehA2dSbpc_05_a53fa0e955dbdc3f2a3a134def9954ae_file.pdf
    • https://j4miejohnston.com/photoshop-2021-version-22-4-1-keygen-exe-activation-key-for-windows/
    • https://frustratedgamers.com/upload/files/2022/07/3YvBf8fBLi5XQtWGMIUA_05_c0cc562631b52cbf0e81fa2224d0882d_file.pdf
    • http://www.ubom.com/upload/files/2022/07/TZMOc9iHrXhDxVIKJFiM_05_c0cc562631b52cbf0e81fa2224d0882d_file.pdf
    • https://aalcovid19.org/photoshop-2022-version-23-0-1-install-crack-full-version-free-download-pc-
    • https://leidenalumni.id/wp-content/uploads/2022/07/Adobe_Photoshop_2022_Version_231_Key_Gener
    • http://www.sparepartsdiesel.com/upload/files/2022/07/Kg1VP4LL5s6xWqmGIv7O_05_e0287ee3b2b5
    • https://panda-app.de/upload/files/2022/07/RkdrjrszDVBVzjbcFBhC_05_a53fa0e955dbdc3f2a3a134def
    • https://www.blackhistoryinthebible.com/wp-content/uploads/2022/07/Photoshop_2021_Version_223_
    • https://artienz.com/upload/files/2022/07/hvXake77ryPWBYsGMEuc_05_a53fa0e955dbdc3f2a3a134de
    • https://everynon.com/adobe-photoshop-2021-version-22-2-crack-exe-file-torrent-activation-code-
    • https://lobenicare.com/adobe-photoshop-express-crack-with-serial-number-activator-download-for-
    • https://www.mil-spec-industries.com/system/files/webform/Adobe-
    • https://expressionpersonelle.com/adobe-photoshop-2021-version-22-1-0-activation-
    • https://storage.googleapis.com/paloodles/upload/files/2022/07/gpfObZyRXAtEh62LDphs_05_c0cc562
    • https://blaquecat.com/community/upload/files/2022/07/siPE2jsAsGzXKy9HxW2h_05_e0287ee3b2b59
    • http://texocommunications.com/adobe-photoshop-cc-crack-exe-file-with-product-key-for-windows-
    • http://demo.funneldrivenroi.com/council/upload/files/2022/07/Eq365QFJY36ehA2dSbpc_05_a53fa0e9
    • https://frustratedgamers.com/upload/files/2022/07/3YvBf8fBLi5XQtWGMIUA_05_c0cc562631b52cbf0
    • http://www.ubom.com/upload/files/2022/07/TZMOc9iHrXhDxVIKJFiM_05_c0cc562631b52cbf0e81fa22
    • https://wakelet.com/wake/6hyXYhaRWvpsjBcOIrpV4
    • https://wakelet.com/wake/EVydcRoA_EROU68zgdfTi
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    +7 more URL(s)