Malicious PDF — malware analysis report

Static analysis result for SHA-256 8eb889a4d5344339…

MALICIOUS

PDF

143.4 KB Created: 2022-07-05 18:35:44 +00:00 Authoring application: saedber (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 0ab1a2a76e739e9ddabeb1c8307a4a00 SHA-1: 80b4fa9a460c1ad52566862193bcd3c3263eb1d2 SHA-256: 8eb889a4d5344339d714c67f815e1783700d0ed62c98818571e82af657d0291e
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which appear to be SEO-optimized and lead to potentially malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a high volume of such links, suggesting a coordinated effort to direct users to external sites. The primary IOC is the first external URI found, which likely serves as a gateway to a malicious payload.

Machine Learning

  • Nyx PDF Classifier clean score 0.0103

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://sitesworlds.com/ashkenazic/odsal=RmlmYSAyMgRml=gyzj=marinelli=tendon=ZG93bmxvYWR8ZGY4TkhWNVpIeDhNVFkxTnpBek5qSXlNM3g4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA
    • https://yachay.unat.edu.pe/blog/index.php?entryid=9337
    • https://www.palpodia.com/upload/files/2022/07/hvwTFKu685VULnHp1JbK_05_8e66cbdc1aee5b94e6a5d735c8c14c01_file.pdf
    • https://sugaringspb.ru/fifa-22-patch-full-version-mac-win-2022/
    • https://poetbook.com/upload/files/2022/07/uCfVpnzzarOxHinkqOar_05_26b634adbeff929430904b2123c5681e_file.pdf
    • https://bodhibliss.org/fifa-22-mem-patch-pc-windows/
    • https://natepute.com/advert/fifa-22-download-for-pc-final-2022-2/
    • https://travelfamilynetwork.com/wp-content/uploads/2022/07/Fifa_22_X64_2022.pdf
    • https://www.riseupstar.com/upload/files/2022/07/x1x8yPaEu596zOGAkYp5_05_26b634adbeff929430904b2123c5681e_file.pdf
    • https://www.pickupevent.com/fifa-22-activation-serial-key-2022-new/
    • https://nelsonescobar.site/fifa-22-keygen-generator-free-latest-2022/
    • http://mandarininfo.com/?p=27439
    • https://holytrinitybridgeport.org/advert/fifa-22-free-download-mac-win-updated-2022/
    • http://it-labx.ru/?p=62375
    • http://techque.xyz/?p=11287
    • https://alafdaljo.com/fifa-22-crack-file-only-free-license-key-final-2022/
    • https://ideatranslate.ru/en/system/files/webform/xirevayl151.pdf
    • https://versiis.com/40943/fifa-22-crack-exe-file-updated-2022/
    • https://www.sunsquare.com/system/files/webform/useruploads/fifa-22_79.pdf
    • https://intrendnews.com/fifa-22-key-generator-obtain/
    • https://yachay.unat.edu.pe/blog/index.php?entryid
    • https://www.palpodia.com/upload/files/2022/07/hv
    • https://sugaringspb.ru/fifa-22-patch-full-version-
    • https://poetbook.com/upload/files/2022/07/uCfVpn
    • https://bodhibliss.org/fifa-22-mem-patch-pc-
    • https://natepute.com/advert/fifa-22-download-for-
    • https://travelfamilynetwork.com/wp-
    • https://www.riseupstar.com/upload/files/2022/07/x
    • https://www.pickupevent.com/fifa-22-activation-
    • https://nelsonescobar.site/fifa-22-keygen-
    • https://holytrinitybridgeport.org/advert/fifa-22-free-
    • https://alafdaljo.com/fifa-22-crack-file-only-free-
    • https://ideatranslate.ru/en/system/files/webform/xi
    • https://versiis.com/40943/fifa-22-crack-exe-file-
    • https://www.sunsquare.com/system/files/webform/
    • https://intrendnews.com/fifa-22-key-generator-
    • https://engineering.louisiana.edu/system/files/webform/welinde981.pdf
    • http://www.tcpdf.org
    • https://engineering.louisiana.edu/system/files/web
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/