PDF static analysis report

Static analysis result for SHA-256 8fbf9324c1547b14…

SUSPICIOUS

PDF

114.8 KB Created: 2022-07-06 06:56:45 +00:00 Authoring application: lynlfau (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: d7a63caad7f9df1c18d1705d6a6e68b0 SHA-1: 9506c2de8d36bc7b561ebcd96b8d6ba98c460f5f SHA-256: 8fbf9324c1547b143e5c8bcb84208753e368d8bad40c395901f3337d836cf10f
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains heuristics indicating it advertises cracked software and embeds external URIs. The primary heuristic, 'PDF_CRACKED_SOFTWARE_LURE', directly points to this malicious intent. The embedded URL 'http://xtraserp.com/fisher.polyvoltine?QmlvbG9naWEgTWFyaW5oYSBQZXRlciBDYXN0cm8gUGRmIERvd25sb2FkQml=ZG93bmxvYWR8N3JtWVhwaWRIeDhNVFkxTnpBMk56RTFOSHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA.heinly&thuja=prophesies.resourcing' is likely a download link for the advertised cracked software. Another URL, 'http://www.bayislistings.com/descargar-crack-para-elfbot-860-20-verified/', further supports the cracked software lure.

Machine Learning

  • Nyx PDF Classifier clean score 0.0187

Heuristics 4

  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xtraserp.com/fisher.polyvoltine?QmlvbG9naWEgTWFyaW5oYSBQZXRlciBDYXN0cm8gUGRmIERvd25sb2FkQml=ZG93bmxvYWR8N3JtWVhwaWRIeDhNVFkxTnpBMk56RTFOSHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA.heinly&thuja=prophesies.resourcing PDF link annotation
    • https://community.tccwpg.com/upload/files/2022/07/RzgE6JqK5VV4TPtilCUR_06_d72573204e76e0007bb03411f41f295e_file.pdfIn PDF document text
    • http://marido-caffe.ro/?p=4292In PDF document text
    • https://www.pickupevent.com/battlefield-2-patch-1-41-no-cd-crack-link-11/In PDF document text
    • https://hyepros.com/wp-content/uploads/2022/07/Automotive_Tolerance_Data_HOT_Free_Download.pdfIn PDF document text
    • https://kaalama.org/upload/files/2022/07/my5fuD1Xrt3jEFXRBUq9_06_37ec035cc96f93b078dca848267e54f2_file.pdfIn PDF document text
    • https://ig-link.com/ceramic-formulas-the-complete-compendium-a-guide-to-clay-glaze-enamel-glass-and-their-colors-ebook-rar/In PDF document text
    • http://www.ressn.com/dentrix-11-dental-practice-management-software-icl-serialrarrar/In PDF document text
    • http://vincyaviation.com/?p=30161In PDF document text
    • https://dogrywka.pl/clever-internet-suite-for-net-v9-3-925-best/In PDF document text
    • http://automationexim.com/eduthu-vacha-paalum-sad-song-download-link/In PDF document text
    • http://www.cpelist.com/system/files/webform/justjam636.pdfIn PDF document text
    • http://www.bayislistings.com/descargar-crack-para-elfbot-860-20-verified/In PDF document text
    • https://bminvestmentsltd.com/wp-content/uploads/2022/07/18_Wheels_Of_Steel_Extreme_Trucker_Free_REPACK_Download_addons.pdfIn PDF document text
    • https://foodonate.ch/wp-content/uploads/2022/07/chakalo.pdfIn PDF document text
    • https://efekt-metal.pl/witaj-swiecie/In PDF document text
    • https://itsupportnetwork.com/adobe-indesign-cc-2019-14-0-1-209-x64-x86-multilingual-medic-download-hot/In PDF document text
    • https://ayusya.in/wp-content/uploads/rcd300codecalculator23.pdfIn PDF document text
    • https://nochill.tv/wp-content/uploads/2022/07/Magoshare_Data_Recovery_40_Crack_FREE_Download_2021.pdfIn PDF document text
    • https://groups.oist.jp/system/files/webform/33366/meatai110.pdfIn PDF document text
    • https://sinknannacor1978.wixsite.com/inhometho/post/miss-tanakpur-haazir-ho-download-free-movie-hotIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text