Malicious PDF — malware analysis report

Static analysis result for SHA-256 82151cd8217594ac…

MALICIOUS

PDF

126.1 KB Created: 2022-07-05 03:27:51 +00:00 Authoring application: yaltale (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 835aea4f53df0588fdf05ab5e8cf05c0 SHA-1: 21f6231ebb099423cbe32f4525fa56f9f5ec86ef SHA-256: 82151cd8217594ac348e3a6e74c212b2b76bf9657a4ed9b55673936f79a9c66e
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, many of which advertise cracked software. This indicates a likely attempt to lure users to malicious websites for software piracy and potentially further compromise. The presence of multiple PDF link farm heuristics strongly supports this conclusion.

Machine Learning

  • Nyx PDF Classifier clean score 0.0260

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seachtop.com/QWRvYmUgUGhvdG9zaG9wIDIwMjIgKCkQWR?liquefies=ZG93bmxvYWR8OExoTkdoNWMzeDhNVFkxTmprNE1UVXdOSHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA.rijckendael.&season=penises
    • https://4j90.com/photoshop-2022-version-23-0-1-key-generator-keygen-mac-win-2022/
    • https://douglasdinesout.com/wp-content/uploads/2022/07/Photoshop_2022_.pdf
    • https://josecarlospereira.com/photoshop-2022-download/
    • http://www.webvideoexperts.com/photoshop-serial-number-and-product-key-crack-with-license-code-for-windows/
    • https://doctorcombine.com/wp-content/uploads/2022/07/Adobe_Photoshop_CC_2019_Product_Key__Free.pdf
    • https://ifacoa.org/wp-content/uploads/2022/07/Photoshop_2021_Version_2201.pdf
    • https://worlegram.com/upload/files/2022/07/zQvHJBhsFJqO9bY2rNth_05_1618ec4240ccfd86815f4ad68756e1fb_file.pdf
    • https://mandarinrecruitment.com/system/files/webform/adobe-photoshop-cs5_10.pdf
    • https://startclube.net/upload/files/2022/07/Kqq7KUTB3sR9ammf6fzN_05_1618ec4240ccfd86815f4ad68756e1fb_file.pdf
    • https://www.cheersyou.com/en/system/files/webform/upload/Adobe-Photoshop-CC-2014.pdf
    • https://learnpace.com/photoshop-cc-2018-nulled-full-product-key/
    • https://www.grenobletrail.fr/wp-content/uploads/2022/07/wadrayl.pdf
    • https://ig-link.com/adobe-photoshop-2021-install-crack-for-pc-2022/
    • https://papayu.co/photoshop-2021-version-22-2-product-key-and-xforce-keygen-full-version-free-mac-win-2022/
    • https://www.theblender.it/photoshop-2021-version-22-4-1-torrent-free-for-pc/
    • http://togetherwearegrand.com/?p=37528
    • http://chatroom.thabigscreen.com:82/upload/files/2022/07/olWsYtYcNbhqEFuYpblT_05_4cbe79c695c82f5dc9a09bf01a593921_file.pdf
    • https://solaceforwomen.com/photoshop-2022-version-23-2-full-product-key-free-download/
    • https://bodhibliss.org/photoshop-2021-version-22-0-1/
    • https://www.justformegadgetz.com/wp-content/uploads/2022/07/Photoshop.pdf
    • http://cyclades.in/en/?p=90671
    • https://4hars.com/adobe-photoshop-2021-version-22-0-0-free-registration-code/
    • http://www.dagerardo.ch/photoshop-cs4-keygen-exe-keygen-for-lifetime/
    • http://www.360sport.it/advert/photoshop-2021-version-22-2-crack-file-only-with-serial-key-free-download-3264bit-updated/
    • https://juliepetit.com/adobe-photoshop-cs6-product-key-and-xforce-keygen-free-license-key-download-win-mac/
    • https://goodforfans.com/upload/files/2022/07/kb9LxDtHm4IfT49TIke4_05_4cbe79c695c82f5dc9a09bf01a593921_file.pdf
    • https://cleverposse.com/advert/photoshop-cc-2014-with-license-key-with-key-latest/
    • http://www.studiofratini.com/wp-content/uploads/2022/07/Adobe_Photoshop_2021_Version_2201.pdf
    • https://katrinsteck.de/photoshop-cc-2019-serial-key-latest-2022/
    • https://www.beaches-lakesides.com/realestate/photoshop-2021-version-22-2-install-crack-with-serial-key-free-download/
    • http://www.webvideoexperts.com/photoshop-serial-number-and-product-key-crack-with-license-code-
    • https://doctorcombine.com/wp-
    • https://worlegram.com/upload/files/2022/07/zQvHJBhsFJqO9bY2rNth_05_1618ec4240ccfd86815f4ad6
    • https://startclube.net/upload/files/2022/07/Kqq7KUTB3sR9ammf6fzN_05_1618ec4240ccfd86815f4ad
    • https://papayu.co/photoshop-2021-version-22-2-product-key-and-xforce-keygen-full-version-free-mac-
    • http://chatroom.thabigscreen.com:82/upload/files/2022/07/olWsYtYcNbhqEFuYpblT_05_4cbe79c695c
    • http://www.360sport.it/advert/photoshop-2021-version-22-2-crack-file-only-with-serial-key-free-
    • https://juliepetit.com/adobe-photoshop-cs6-product-key-and-xforce-keygen-free-license-key-
    • https://goodforfans.com/upload/files/2022/07/kb9LxDtHm4IfT49TIke4_05_4cbe79c695c82f5dc9a09bf
    • https://www.beaches-lakesides.com/realestate/photoshop-2021-version-22-2-install-crack-with-serial-
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    +1 more URL(s)