Malicious PDF — malware analysis report

Static analysis result for SHA-256 68dd681d97481085…

MALICIOUS

PDF

138.2 KB Created: 2022-07-05 02:28:15 +00:00 Authoring application: sygnharl (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: d617a43452dd806bf630da1b1e659500 SHA-1: 79fe1cad4bf008f2757c8a7bab138fe5a005511a SHA-256: 68dd681d97481085a16b6ae9e0aa375b939db678bfca9a8e7132511021b1e12a
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains a large number of external links, many of which advertise cracked software, indicating a lure to download potentially malicious files. The primary URL http://sitesworlds.com/salvaging/... appears to be a direct download link for a payload. The document's structure and content suggest it is designed to trick users into visiting these sites and downloading malware disguised as software cracks.

Machine Learning

  • Nyx PDF Classifier clean score 0.0104

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://sitesworlds.com/salvaging/ZG93bmxvYWR8elcxTW5kbWFueDhNVFkxTmprNE1UVXdOSHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA/caribe/labovitch/magnolia/manipulator..QWRvYmUgUGhvdG9zaG9wIDIwMjAQWR.barred
    • http://igpsclub.ru/social/upload/files/2022/07/RpMuKmhOze2MH7YJMVvn_05_4483676510e12817c9aab06655cc1e47_file.pdf
    • https://www.mbca.org/sites/default/files/webform/ciatale41.pdf
    • https://www.tiempodejujuy.com.ar/advert/adobe-photoshop-2021-version-22-2-keygen-exe-keygen-for-lifetime-latest-2022/
    • https://entrelink.hk/event/adobe-photoshop-2022-version-23-1-1-crack-patch-keygen-full-version-free-download-pc-windows-2022-new/
    • https://netbizzz.com/wp-content/uploads/2022/07/Photoshop_2022_Version_2302.pdf
    • https://likesmeet.com/upload/files/2022/07/1UMs4hg5tmp1sBcymtHd_05_4483676510e12817c9aab06655cc1e47_file.pdf
    • https://swisshtechnologies.com/photoshop-2021-version-22-5-1-free-latest/
    • http://cyclades.in/en/?p=90514
    • https://innovacioncosmetica.com/adobe-photoshop-2021-version-22-1-1-crack-with-serial-number-free-download-mac-win/
    • http://tmcustomwebdesign.com/wp-content/uploads/2022/07/Adobe_Photoshop_CC_2018.pdf
    • http://pepsistars.com/photoshop-2022-version-23-2-keygenerator-lifetime-activation-code-download-mac-win-april-2022/
    • http://moonreaderman.com/adobe-photoshop-with-license-code-for-windows-march-2022/
    • https://netgork.com/upload/files/2022/07/LDpa3Cd4U57cwdUGfycp_05_4483676510e12817c9aab06655cc1e47_file.pdf
    • https://www.dejavekita.com/upload/files/2022/07/Nns3wP7veHLjm2Y4wgWa_05_db76a6ff85495e4730f24f77d6c600f3_file.pdf
    • https://workplace.vidcloud.io/social/upload/files/2022/07/wssnY6X8l7OmWMnPIp1J_05_4483676510e12817c9aab06655cc1e47_file.pdf
    • http://insenergias.org/?p=25162
    • http://www.studiofratini.com/adobe-photoshop-cs4-serial-number-free-download/
    • https://arcmaxarchitect.com/sites/default/files/webform/thropanc566.pdf
    • https://awazpost.com/wp-content/uploads/2022/07/obedhenr-1.pdf
    • https://4f46.com/adobe-photoshop-2021-version-22-1-0-crack-activator-win-mac-updated-2022-129311/
    • http://www.male-blog.com/2022/07/04/photoshop-2021-version-22-0-0-patch-with-serial-key-free-latest-2022/
    • https://travelfamilynetwork.com/wp-content/uploads/2022/07/Adobe_Photoshop_2022_Version_2311_universal_keygen__With_Product_Key_Download_3264bit.pdf
    • https://repliquetees.com/advert/adobe-photoshop-cc-universal-keygen-for-windows/
    • https://thetraditionaltoyboxcompany.com/wp-content/uploads/2022/07/Adobe_Photoshop_2021_Version_2200_Activation_Code_Updated.pdf
    • https://mandarinrecruitment.com/system/files/webform/photoshop-2021-version-224_9.pdf
    • http://www.essais-militaire.fr/en/system/files/webform/photoshop-2021-version-223.pdf
    • https://corporateegg.com/photoshop-2022-version-23-1-1-keygen-crack-setup-3264bit/
    • http://igpsclub.ru/social/upload/files/2022/07/RpMuKmhOze2MH7YJMVvn_05_4483676510e12817c9a
    • https://www.tiempodejujuy.com.ar/advert/adobe-photoshop-2021-version-22-2-keygen-exe-keygen-
    • https://entrelink.hk/event/adobe-photoshop-2022-version-23-1-1-crack-patch-keygen-full-version-free-
    • https://likesmeet.com/upload/files/2022/07/1UMs4hg5tmp1sBcymtHd_05_4483676510e12817c9aab0
    • https://innovacioncosmetica.com/adobe-photoshop-2021-version-22-1-1-crack-with-serial-number-
    • http://pepsistars.com/photoshop-2022-version-23-2-keygenerator-lifetime-activation-code-download-
    • https://netgork.com/upload/files/2022/07/LDpa3Cd4U57cwdUGfycp_05_4483676510e12817c9aab06
    • https://www.dejavekita.com/upload/files/2022/07/Nns3wP7veHLjm2Y4wgWa_05_db76a6ff85495e473
    • https://workplace.vidcloud.io/social/upload/files/2022/07/wssnY6X8l7OmWMnPIp1J_05_4483676510e
    • https://4f46.com/adobe-photoshop-2021-version-22-1-0-crack-activator-win-mac-
    • http://www.male-blog.com/2022/07/04/photoshop-2021-version-22-0-0-patch-with-serial-key-free-
    • https://travelfamilynetwork.com/wp-content/uploads/2022/07/Adobe_Photoshop_2022_Version_2311_
    • https://thetraditionaltoyboxcompany.com/wp-
    • https://wakelet.com/wake/az1hG0fLtEflF-D17r7BM
    • https://www.colorado.edu/biochemistry/system/files/webform/adobe-photoshop-2022-version-2301_0.pdf
    • https://patriabookspace.FRA1.digitaloceanspaces.com/upload/files/2022/07/RT2YitgtGA8QyazRxnWD_05_db76a6ff85495e4730f24f77d6c600f3_file.pdf
    • http://www.tcpdf.org
    • https://www.colorado.edu/biochemistry/system/files/webform/adobe-
    • https://patriabookspace.FRA1.digitaloceanspaces.com/upload/files/2022/07/RT2YitgtGA8QyazRxnWD
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    +6 more URL(s)