PDF static analysis report

Static analysis result for SHA-256 74d7235604319aa1…

SUSPICIOUS

PDF

121.6 KB Created: 2022-07-04 04:28:16 +00:00 Authoring application: zerzoli (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: c07539a990f92abead7945cde84fec80 SHA-1: 28bdfd75b8fa6b7092919c499cc589a984b96aa7 SHA-256: 74d7235604319aa160e4a49a5509158fe539300377217eba0348d942aac77daa
34 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains numerous embedded URLs that advertise cracked and pirated software, indicating a lure for users to download potentially malicious applications. One of the identified URLs, http://awarefinance.com/timme/censor/grades/SHRtUGFkSHR/rwyrhrw&ZG93bmxvYWR8QlQ2Tm04eWMzeDhNVFkxTmpnNU1qTTFNbng4TWpVNE4zeDhLRTBwSUVobGNtOXJkU0JiUm1GemRDQkhSVTVk.arteriograms, is particularly suspicious and likely serves as a download link for a second-stage payload. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier clean score 0.0149

Heuristics 3

  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://awarefinance.com/timme/censor/grades/SHRtUGFkSHR/rwyrhrw&ZG93bmxvYWR8QlQ2Tm04eWMzeDhNVFkxTmpnNU1qTTFNbng4TWpVNE4zeDhLRTBwSUVobGNtOXJkU0JiUm1GemRDQkhSVTVk.arteriograms PDF link annotation
    • https://sttropezrestaurant.com/ruleforge-crack-serial-key-updated-2022/In PDF document text
    • http://valentinesdaygiftguide.net/?p=34988In PDF document text
    • https://still-mesa-80812.herokuapp.com/fauhes.pdfIn PDF document text
    • http://findmallorca.com/anymp4-dvd-creator-crack-with-registration-code/In PDF document text
    • https://stark-citadel-86474.herokuapp.com/Future_City_3D_Screensaver.pdfIn PDF document text
    • http://freemall.jp/english-sentences-quiz-crack-license-key-free-download-for-windows.htmlIn PDF document text
    • https://agile-wildwood-63551.herokuapp.com/stanac.pdfIn PDF document text
    • https://blwes.com/wp-content/uploads/2022/07/SQL_MDF_Viewer__Crack___April2022.pdfIn PDF document text
    • https://clubnudista.com/upload/files/2022/07/ozXR5ct4dWyqcsVyuVXB_04_6020301b1722b5ae1aef46f33b482b36_file.pdfIn PDF document text
    • https://nanacomputer.com/nokia-video-converter-factory-pro-keygen-full-version-download-2022/In PDF document text
    • https://nisharma.com/pace-place-crack-free/In PDF document text
    • https://www.mil-spec-industries.com/system/files/webform/kaiouill51.pdfIn PDF document text
    • https://www.cityofmound.com/sites/g/files/vyhlif6191/f/uploads/migrate_the_2040_comprehensive_plan-compressed_1.pdfIn PDF document text
    • https://wheeoo.org/upload/files/2022/07/qgh3LJoymwLhtivVyKse_04_6020301b1722b5ae1aef46f33b482b36_file.pdfIn PDF document text
    • https://recreovirales.com/xformer-designer-april-2022/In PDF document text
    • http://www.barberlife.com/upload/files/2022/07/wnAIhbtpmm2TfU4iaFdq_04_6020301b1722b5ae1aef46f33b482b36_file.pdfIn PDF document text
    • http://topfleamarket.com/?p=28077In PDF document text
    • https://www.sartorishotel.it/zipdeploy-crack-download-2022-latest/In PDF document text
    • https://www.happy-energy.it/wp-content/uploads/2022/07/alljar.pdfIn PDF document text
    • https://greenearthcannaceuticals.com/chart-patterns-tutorial-for-forex-and-stock-market-crack-activation-free-download/In PDF document text
    • https://clubnudista.com/upload/files/2022/07/ozXR5ct4dWyqcsVyuVXB_04_6020301b1722b5ae1In PDF document text
    • https://nanacomputer.com/nokia-video-converter-factory-pro-keygen-full-version-In PDF document text
    • https://www.cityofmound.com/sites/g/files/vyhlif6191/f/uploads/migrate_the_2040_comprehensiIn PDF document text
    • https://wheeoo.org/upload/files/2022/07/qgh3LJoymwLhtivVyKse_04_6020301b1722b5ae1aef46In PDF document text
    • http://www.barberlife.com/upload/files/2022/07/wnAIhbtpmm2TfU4iaFdq_04_6020301b1722b5aIn PDF document text
    • https://greenearthcannaceuticals.com/chart-patterns-tutorial-for-forex-and-stock-market-crack-In PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003169.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3169 84648 bytes
SHA-256: 0b6c48f6a4e931a4572b13bb2af9ad514b0702ea3c747f8534c05d2c57946ed4
font_01_sfnt_off0000b9cc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB9CC 83036 bytes
SHA-256: 6d13e73e85a502a13969f6a5eaecd0b275a0868c045f80b7d64ed55d70678261