Malicious PDF — malware analysis report

Static analysis result for SHA-256 86c170c8ec3a6ddd…

MALICIOUS

PDF

136.4 KB Created: 2022-07-05 01:58:52 +00:00 Authoring application: ordejust (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: e8631d381881fedb028a5d70ecbed9d0 SHA-1: f693f84c2f0702e7f7e298605c76bd80c1d74fd0 SHA-256: 86c170c8ec3a6ddd06dff3912c4d0e615995efd889ac2de5ec024a6311ea27af
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or distribution point for malicious content. One prominent URL, http://dawnloadonline.com/neuroscientist?UGhvdG9zaG9wIDIwMjIgKCkUGh=buzzaround.ZG93bmxvYWR8RjhpTWpGbFozeDhNVFkxTmprNE1UVXdOSHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA.cajun&deride=neutrophils&chandeliered, is embedded and likely serves as a lure to download further payloads. The document's structure and numerous outbound links indicate a malicious intent to redirect users to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier clean score 0.0059

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dawnloadonline.com/neuroscientist?UGhvdG9zaG9wIDIwMjIgKCkUGh=buzzaround.ZG93bmxvYWR8RjhpTWpGbFozeDhNVFkxTmprNE1UVXdOSHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA.cajun&deride=neutrophils&chandeliered
    • https://delcohempco.com/2022/07/04/photoshop-2021-version-22-4-3-keygen-crack-setup-product-key-full-free/
    • https://toserba-muslim.com/wp-content/uploads/2022/07/syretale.pdf
    • http://classacteventseurope.com/wp-content/uploads/2022/07/nicnire.pdf
    • http://escortguate.com/adobe-photoshop-2021-version-22-4-3-serial-number-and-product-key-crack-full-version-3264bit-latest-2022/
    • https://www.cameraitacina.com/en/system/files/webform/feedback/photoshop-2021-version-2200_4.pdf
    • http://bukitaksara.com/?p=8674
    • http://findmallorca.com/photoshop-2022-version-23-2-crack-exe-file-incl-product-key-mac-win-latest/
    • http://yildizbursa.org/wp-content/uploads/2022/07/gavvyan.pdf
    • https://fesalabs.com/photoshop-2022-version-23-1-free-license-key-download/
    • https://arabamericanbusinesscommunity.org/wp-content/uploads/2022/07/Photoshop_CS5.pdf
    • https://mscenter.be/fr/system/files/webform/jamaelli285.pdf
    • https://arcmaxarchitect.com/sites/default/files/webform/loredomi163.pdf
    • https://sfinancialsolutions.com/adobe-photoshop-2021-version-22-0-0-with-serial-key-download-mac-win/
    • https://romans12-2.org/adobe-photoshop-2021-version-22-0-0-activation-updated-2022/
    • https://toilesdusoleil-montpellier.com/wp-content/uploads/2022/07/volwea.pdf
    • https://ex0-sys.app/upload/files/2022/07/bB8ugUjm7XcueX1JYc4n_05_b08a7666351573b9b9c2b279bb2daf10_file.pdf
    • http://freemall.jp/photoshop-cs4-nulled-3264bit-updated-2022.html
    • https://2do.net/wp-content/uploads/2022/07/eugegen.pdf
    • https://thaiherbbank.com/social/upload/files/2022/07/x8RZIsbIdAWoWXW94fXr_05_b08a7666351573b9b9c2b279bb2daf10_file.pdf
    • https://volektravel.com/wp-content/uploads/2022/07/Photoshop_CC_2015_Version_16_LifeTime_Activation_Code_Free_Download_X64.pdf
    • http://www.ndvadvisers.com/?p=
    • https://atennis.kz/tour/upload/files/2022/07/SgMfZmlHR6B88GIkgbHE_05_b08a7666351573b9b9c2b279bb2daf10_file.pdf
    • https://talkotive.com/upload/files/2022/07/9RNmnvhYOk1zmoRjt4aB_05_e085c4d5067a05130247d18616e93f02_file.pdf
    • https://www.siriusarchitects.com/advert/adobe-photoshop-cs3-keygen-crack-serial-key-full-product-key-download-3264bit/
    • https://www.rcr.ac.uk/system/files/webform/photoshop-2021-version-2241.pdf
    • http://www.7daystobalance.com/advert/photoshop-2021-crack-exe-file-free-3264bit/
    • http://buyzionpark.com/?p=31269
    • https://delcohempco.com/2022/07/04/photoshop-2021-version-22-4-3-keygen-crack-setup-product-
    • http://escortguate.com/adobe-photoshop-2021-version-22-4-3-serial-number-and-product-key-crack-
    • https://www.cameraitacina.com/en/system/files/webform/feedback/photoshop-2021-version-2200_4
    • https://sfinancialsolutions.com/adobe-photoshop-2021-version-22-0-0-with-serial-key-download-mac-
    • https://ex0-sys.app/upload/files/2022/07/bB8ugUjm7XcueX1JYc4n_05_b08a7666351573b9b9c2b279b
    • https://thaiherbbank.com/social/upload/files/2022/07/x8RZIsbIdAWoWXW94fXr_05_b08a7666351573
    • https://volektravel.com/wp-content/uploads/2022/07/Photoshop_CC_2015_Version_16_LifeTime_Activ
    • https://atennis.kz/tour/upload/files/2022/07/SgMfZmlHR6B88GIkgbHE_05_b08a7666351573b9b9c2b2
    • https://talkotive.com/upload/files/2022/07/9RNmnvhYOk1zmoRjt4aB_05_e085c4d5067a05130247d1
    • https://www.siriusarchitects.com/advert/adobe-photoshop-cs3-keygen-crack-serial-key-full-product-
    • http://imtripeb.yolasite.com/resources/Adobe-Photoshop-2021-Version-2200-Crack--Free-2022.pdf
    • https://www.ems.psu.edu/system/files/webform/hardeb938.pdf
    • https://healthpsychology.ucsf.edu/system/files/webform/Photoshop-2020.pdf
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    +1 more URL(s)