Malicious PDF — malware analysis report

Static analysis result for SHA-256 7beeb4d4b1c0547c…

MALICIOUS

PDF

127.3 KB Created: 2022-07-06 07:43:55 +00:00 Authoring application: alyssaro (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 24b179a6b8449ed1c13876a26799a580 SHA-1: 66c88bbabfa98c2549d8e91ec4749143a82daa11 SHA-256: 7beeb4d4b1c0547ccb380850c3d635ec91c8f44e33e6b57b6a61f2c9afb0314a
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a malicious intent to redirect users to potentially harmful content. The presence of multiple external URIs further supports this, indicating a likely downloader or redirector pattern. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier clean score 0.0089

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://findinform.com/ceasaria/roadblocks/fingertips/ZG93bmxvYWR8NGZCWTJZMllueDhNVFkxTnpBMk56RTFOSHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA/sharps.S2FodWx1Z2FuIEF0IEthaGFsYWdhaGFuIE5nIFBhZ2Jhc2EgUGRmIERvd25sb2FkS2F/
    • https://pra-namorar.paineldemonstrativo.com.br/upload/files/2022/07/E2pchkVzxacojXYtIo7X_06_e8ae17699a0a6779ce8499c26e0217e8_file.pdf
    • https://strine.co/wp-content/uploads/2022/07/haltdeat.pdf
    • https://www.girlkindproject.org/aaa-logo-business-edition-3-10-crack-link/
    • http://steelcurtain.club/wp-content/uploads/2022/07/viviverd.pdf
    • http://classacteventseurope.com/wp-content/uploads/2022/07/kachmak.pdf
    • http://atmecargo.com/?p=9601
    • https://noshamewithself.com/upload/files/2022/07/klqnCuJcmKjqH7pfF211_06_e8ae17699a0a6779ce8499c26e0217e8_file.pdf
    • https://webkhoacua.com/pdf-password-remover-v5-0-with-key-tordigger-setup-upd-free/
    • https://www.bnbpartners.be/fr-be/system/files/webform/visitor-uploads/fifa-20-crack-cpy-download-pc-torrent-2020.pdf
    • https://www.bigdawgusa.com/sarkar-raj-movie-download-utorrent-kickass-movies-exclusive/
    • https://slitetitle.com/baixarativadordowindows8probuild920012/
    • https://thefuturegoal.com/upload/files/2022/07/L9lZuTv77cR3fuLVaMhT_06_e12481e92927014564944b7a751fd731_file.pdf
    • https://ainocafe.com/upload/files/2022/07/fTcv3sVHOGmtISZSeHUj_06_e8ae17699a0a6779ce8499c26e0217e8_file.pdf
    • https://volyninfo.com/advert/the-singh-is-kinng-cracked-full-movie-in-hindi/
    • https://recreovirales.com/adobe-acrobat-7-0-professional-torrent-full-verified/
    • https://tattooshopreviews.com/wp-content/uploads/2022/07/fergury.pdf
    • https://www.sartorishotel.it/diablo-2-hero-editor-item-pack-1-13/
    • https://savosh.com/sikandar-hindi-dubbed-hd-mp4-movies-download-repack/
    • https://meuconhecimentomeutesouro.com/x-force-keygen-high-quality-invalid-request-code/
    • https://pra-namorar.paineldemonstrativo.com.br/upload/files/2022/07/E2pchkVzxacojXYtIo7X_06_e8a
    • https://noshamewithself.com/upload/files/2022/07/klqnCuJcmKjqH7pfF211_06_e8ae17699a0a6779ce
    • https://www.bnbpartners.be/fr-be/system/files/webform/visitor-uploads/fifa-20-crack-cpy-download-
    • https://thefuturegoal.com/upload/files/2022/07/L9lZuTv77cR3fuLVaMhT_06_e12481e9292701456494
    • https://ainocafe.com/upload/files/2022/07/fTcv3sVHOGmtISZSeHUj_06_e8ae17699a0a6779ce8499c2
    • https://trello.com/c/YazOqDh4/57-hd-online-player-cars-2-1080p-download-torrent-work
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/