Malicious PDF — malware analysis report

Static analysis result for SHA-256 91fb865c46e99447…

MALICIOUS

PDF

144.0 KB Created: 2022-07-04 05:58:38 +00:00 Authoring application: lautwali (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: de134576985cc54da34d13d351fcf590 SHA-1: 1af90a2698556757a5c7bf85cd2231b681a57b81 SHA-256: 91fb865c46e9944739d9e677d2c263441a6eb29a13723c51d9af655977a5ecb7
64 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious Link

The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. One of these links, http://emailgoal.com/..., is directly embedded in the document's text, suggesting a lure to download potentially malicious content. The presence of numerous links indicates a strategy to distribute malware or engage in SEO spam.

Machine Learning

  • Nyx PDF Classifier clean score 0.0090

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://emailgoal.com/ZG93bmxvYWR8QlQ5T0hSNWNueDhNVFkxTmpnNU1qTTFNbng4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA/batting/imagining.blanketed.QXJ0aXN0aWMgRWZmZWN0cwQXJ?neurontin=.bohm
    • http://outdooryogany.com/wp-content/uploads/2022/07/vybfari.pdf
    • https://www.hypebunch.com/upload/files/2022/07/nlxrZ2Q1VzmoFOTjBt7n_04_bec1bcebec33cfc4e088e4339444b1da_file.pdf
    • https://made4you.london/jaudiotagger-serial-key-free-pc-windows/
    • https://knowconhecimento.com/random-numbers-statistical-analysis-crack-free-registration-code-x64/
    • https://organicway-cityvest.dk/cs3000-control-and-configuration-software-crack-download-april-2022/
    • https://talkotive.com/upload/files/2022/07/7OEe7wJycziWTV5jWh98_04_738d9e1083247adcd102134da4196468_file.pdf
    • http://historyfootsteps.net/core2maxperf-crack-download-for-windows-updated-2022/
    • https://ceza.gov.ph/system/files/webform/resume/deleng409.pdf
    • https://lifedreamsorganizer.com/xbuildstudio-crack-mac-win/
    • https://maisonchaudiere.com/advert/freesshd-crack-with-license-code-free-3264bit-april-2022/
    • https://www.lapelpinscustom.com.au/sites/www.lapelpinscustom.com.au/files/webform/briaeiri535.pdf
    • https://rhemaaccra.org/wp-content/uploads/2022/07/dariobel.pdf
    • https://www.quadernicpg.it/2022/07/04/novtel-vehicle-hire-crack-product-key-full-x64-updated-2022/
    • https://thebakersavenue.com/wp-content/uploads/2022/07/lathro.pdf
    • https://www.mycatchyphrases.com/data-flask-x64-updated-2/
    • http://itkursove.bg/wp-content/uploads/2022/07/Mobile_Buddy_2006__Crack_Free_Download.pdf
    • https://www.hypebunch.com/upload/files/2022/07/nlxrZ2Q1VzmoFOTjBt7n_04_bec1bcebec33cfc4e08
    • https://knowconhecimento.com/random-numbers-statistical-analysis-crack-free-registration-code-
    • https://talkotive.com/upload/files/2022/07/7OEe7wJycziWTV5jWh98_04_738d9e1083247adcd102134
    • https://www.lapelpinscustom.com.au/sites/www.lapelpinscustom.com.au/files/webform/briaeiri535.pd
    • http://vecunu.yolasite.com/resources/Base64-File-Converter-Crack--With-Serial-Key-WinMac-2022.pdf
    • http://snowtibbest.yolasite.com/resources/Symantec-Ramnit-Removal-Tool-Crack--Free-Final-2022.pdf
    • https://groups.oist.jp/system/files/webform/8979/tortim613.pdf
    • http://trusviepres.yolasite.com/resources/Word-List-Duplicate-Remover-Crack--Keygen-For-LifeTime-Free.pdf
    • http://www.tcpdf.org
    • http://snowtibbest.yolasite.com/resources/Symantec-Ramnit-Removal-Tool-Crack--Free-
    • http://trusviepres.yolasite.com/resources/Word-List-Duplicate-Remover-Crack--Keygen-For-LifeTime-
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/