Malicious PDF — malware analysis report

Static analysis result for SHA-256 7c6c48229eedfe86…

MALICIOUS

PDF

125.1 KB Created: 2022-06-12 16:54:39 +02:00 Authoring application: darrcher (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 595ad60ac32fb073a3dd289bc167a140 SHA-1: bc3fcb2ed3e58dc5f6136fca6186e186316b2c0b SHA-256: 7c6c48229eedfe8662cfd29c19db232c3a14facd8c95a224e8d3d9829e879deb
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. One of these links, http://evacdir.com/backhealthpro/chkcpu/oozed.gadget.RG93bmxvYWQgSXpvdG9wZSBPem9uZSA1IEZyZWUgQ3JhY2tlZARG9.ghaghara/gusman?lgbt=ZG93bmxvYWR8TjRiYVdOamJIeDhNVFkxTkRrNE9URTJNbng4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA, points to a suspicious domain and path, likely serving a malicious payload. The document body was unreadable, but the presence of numerous external links suggests a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier clean score 0.0284

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://evacdir.com/backhealthpro/chkcpu/oozed.gadget.RG93bmxvYWQgSXpvdG9wZSBPem9uZSA1IEZyZWUgQ3JhY2tlZARG9.ghaghara/gusman?lgbt=ZG93bmxvYWR8TjRiYVdOamJIeDhNVFkxTkRrNE9URTJNbng4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA
    • https://netafits.com/wp-content/uploads/2022/06/Coduri_Cs_16_Badboy_V42_13.pdf
    • https://arseducation.com/wp-content/uploads/2022/06/Autodesk_AutoCAD_2010_Keygens_Only_XFORCE_3264bits_RH_Download_Pcbfdcm.pdf
    • https://www.jesusnanak.com/upload/files/2022/06/QcRRcBo2kTvfFWAG3D17_12_60e26fadba8a096602f144ad9a6e5552_file.pdf
    • https://2c63.com/wp-content/uploads/2022/06/Lite_Fire_Laser_Engraver_Software.pdf
    • https://marketing6s.com/index.php/advert/hum-tum-full-movie-hd-1080p-subtitles-exclusive-free-3/
    • https://www.dandrea.com.br/advert/top-five-verified-cracked-pixelmon-servers/
    • https://noshamewithself.com/upload/files/2022/06/kVST1NYBGxJ1V1OSTEPS_12_bb66bed8128f437f1d78947125b19b65_file.pdf
    • https://gogathr.live/upload/files/2022/06/Tu4yoLBZJWZyHWUE22SW_12_bb66bed8128f437f1d78947125b19b65_file.pdf
    • http://www.pickrecruit.com/download-holiday-world-tycoon-2006-pc14-new/
    • https://coolbreezebeverages.com/8dioambientguitarkontaktbetter-download/
    • http://villa-mette.com/?p=19069
    • https://xn--xvaos-qta.net/wp-content/uploads/2022/06/Simple_Student_Card_Full_Crackl.pdf
    • https://en-media.tv/advert/buku-manual-daihatsu-taruna-sehen-kasumi-knight-best/
    • https://firstamendment.tv/upload/files/2022/06/NsR7Bm1skFPcwK9Bir1k_12_bb66bed8128f437f1d78947125b19b65_file.pdf
    • https://www.blackheadpopping.com/hwidchangerv18pcdownloadpc/
    • https://www.apbara.be/index.php/advert/outlive-game-download-full-version/
    • http://jwbotanicals.com/building-design-and-construction-vicente-tagayun-calamaro-cerberus-ll/
    • http://www.ndvadvisers.com/wp-content/uploads/2022/06/TruLaser_V2012_KEYGEN_XfKEYWORDkg_X64zip.pdf
    • http://www.vxc.pl/wp-content/uploads/2022/06/Manual_Yamaha_5_BS_661.pdf
    • https://marriagecermony.com/sociology-themes-and-perspectives-haralambos-and-holborn-michael-haralambos-epub/
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000011e4.bin
a217f12862e0ff75203bdd4136ca0d68471050be46bb09aed5306898926ffdd4
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x11E4 120140 bytes