Malicious PDF — malware analysis report

Static analysis result for SHA-256 94ce888cd2de6ee8…

MALICIOUS

PDF

134.7 KB Created: 2022-07-06 08:20:46 +00:00 Authoring application: brewebs (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: f1098c26bc4c7391fe8d32f6c59bdbd0 SHA-1: c1ef887f2f38594022a3fa71a2f6e00999e1c041 SHA-256: 94ce888cd2de6ee8b33dfc7c53abdd2924e202f76d57ea4f7829aa38dbaa6ea2
72 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. One of these links, http://starsearchtool.com/cutlass/..., points to a potential download location. The presence of a "download button" lure further suggests a malicious intent to trick the user into downloading unwanted files.

Machine Learning

  • Nyx PDF Classifier clean score 0.0138

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://starsearchtool.com/cutlass/ZG93bmxvYWR8RHQ1Wkdwek5IeDhNVFkxTnpBMk56RTFOSHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA?goals=pasco&segunda=freeflying&UmVnaXN0cmF0aW9uIE5hbWUgQW5kIFNlcmlhbCBLZXkgRm9yIEdvbGQgTWluZXIgVmVnYXMUmV.peeling=rued
    • https://www.tailormade-logistics.com/sites/default/files/webform/gratal245.pdf
    • http://feelingshy.com/downloadcrackresidentevil4ultimatehd11-best/
    • https://treelovellc.com/wp-content/uploads/2022/07/Game_Men_Of_War_Assault_Squad_V20515_Trainer_Limited_Edition-1.pdf
    • https://media.smaskstjohnpaul2maumere.sch.id/upload/files/2022/07/z46oGP3ahfx8Dgc25Vb5_06_2e85519b845c1ff2763fb231228eec31_file.pdf
    • https://www.2el3byazici.com/road-rash-no-cd-crack-high-quality-download/
    • https://allweboutreach.com/wp-content/uploads/2022/07/weyour.pdf
    • https://chatbook.pk/upload/files/2022/07/W9ywf1lnNxLwlIhPMnwB_06_2bad40f4d05593671900dc95cd0b7bcd_file.pdf
    • https://lapa.lv/the-house-next-door-dvdrip-720p-hd-free-download-movie-work/
    • https://www.interprys.it/wp-content/uploads/2022/07/Fisica_O_Quimica_All_Seasons_English_14.pdf
    • http://berlin-property-partner.com/?p=30561
    • https://shielded-waters-16480.herokuapp.com/Solidworks_electrical_2017_crack.pdf
    • https://roundabout-uk.com/serial-admisco-rar/
    • https://forallequal.com/pltw-digital-electronics-answer-key-all-lessons-zipl-upd/
    • https://www.apokoronews.gr/advert/bluesoleil-7-0-337-0-serial-bsplayer-bells-trans/
    • https://marshryt.by/wp-content/uploads/Embarcadero_RadPHP_XE2_4001547_ISOrar_Crack_Serial_Keygen_Cd_Keyrar_Hit_Fixed.pdf
    • https://acarticles.com/wp-content/uploads/2022/07/Fst_7_Refined_Torrent_Full.pdf
    • https://www.sanjeevsrivastwa.com/cisco-configmaker-v-2-6-full-version-60-portable/
    • https://sc-designgroup.com/wp-content/uploads/2022/07/I_fine_thank_you_love_you_full_Movie_tagalog.pdf
    • https://treelovellc.com/wp-content/uploads/2022/07/Game_Men_Of_War_Assault_Squad_V2051
    • https://media.smaskstjohnpaul2maumere.sch.id/upload/files/2022/07/z46oGP3ahfx8Dgc25Vb5
    • https://chatbook.pk/upload/files/2022/07/W9ywf1lnNxLwlIhPMnwB_06_2bad40f4d0559367190
    • https://www.interprys.it/wp-
    • https://marshryt.by/wp-content/uploads/Embarcadero_RadPHP_XE2_4001547_ISOrar_Crack_Se
    • https://sc-designgroup.com/wp-
    • https://trello.com/c/0Ru2ZZY9/51-coreldraw-x6-portable-11-exclusive
    • https://www.iol.unh.edu/sites/default/files/webform/resumes/ordelli719.pdf
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/