Malicious PDF — malware analysis report

Static analysis result for SHA-256 9575adefa00f774b…

MALICIOUS

PDF

119.7 KB Created: 2022-07-02 16:40:17 +00:00 Authoring application: kalelvi (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: e7b7b3d7d43925f4797cd292e9b8a410 SHA-1: 196adf14ef13004a96f7792d0439875c6b77a7ad SHA-256: 9575adefa00f774bc2033f8150275bda953ef99118b1c62a4ec7d915e70b6e41
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which point to other PDF files, suggesting a link farm designed to improve search engine rankings. One specific URL, http://evacdir.com/helptogo/tomoka.liberian/preemie/TWV0cm8gMjAzMyBDcmFjayBPbmx5IDQwTWV?ZG93bmxvYWR8RVI3TTNBM04zeDhNVFkxTmpjM01UZ3hPSHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA&sera=lotrimin.walford, is directly embedded and likely serves as a lure. The presence of a 'Password-protected archive handoff' heuristic indicates the document may be instructing the user to open a password-protected archive, a common tactic to bypass security filters.

Machine Learning

  • Nyx PDF Classifier clean score 0.0152

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://evacdir.com/helptogo/tomoka.liberian/preemie/TWV0cm8gMjAzMyBDcmFjayBPbmx5IDQwTWV?ZG93bmxvYWR8RVI3TTNBM04zeDhNVFkxTmpjM01UZ3hPSHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA&sera=lotrimin.walford
    • https://www.handmademarket.de/wp-content/uploads/2022/07/deefru.pdf
    • http://armenianbusinessdirectory.ca/wp-content/uploads/2022/07/Soal_Ujian_Wppe_Ebook_Download_LINK.pdf
    • https://libertinosdaalcova.com/fs2004-fsd-pilatus-porter-pc6-v2-all-repaints-included-top/
    • https://rebon.com.co/wp-content/uploads/2022/07/Kasumi_Rebirth_V3_Full_Game_59.pdf
    • https://teenmemorywall.com/epsonl110resetteradjustmentprogramfreedownload-hot/
    • https://community.soulmateng.net/upload/files/2022/07/Wbe4mtEJueczGwGtP8ew_02_de02e49a1c5e9ed8049c8af82d1a0291_file.pdf
    • https://doitory.com/wp-content/uploads/2022/07/Dil_Dosti_Dance_Serial_Episode_Download.pdf
    • https://www.artec3d.com/es/system/files/webform/business_development/angry-birds-rio-key-code-for-pc-free-download.pdf
    • https://www.nooganightlife.com/wp-content/uploads/2022/07/enreloi.pdf
    • https://kingphiliptrailriders.com/advert/mp3-doctor-pro-serial-keygen-12-new/
    • https://likesmeet.com/upload/files/2022/07/RWbd7az8IgxPVTPOcYIr_02_de02e49a1c5e9ed8049c8af82d1a0291_file.pdf
    • http://www.hva-concept.com/chaalis-chauraasi-2-movie-download-in-hindi-720p-download-2021/
    • https://gembeltraveller.com/malwarebytes-anti-malware-premium-4-9-1-1046-21-36-crack-link-serial-key-keygenl/
    • https://www.coursesuggest.com/wp-content/uploads/2022/07/Swiftec_V182.pdf
    • https://lacomfortair.com/captain-america-super-soldier-pc-full-rip-cracked-rar-password-new/
    • https://kramart.com/adobe-illustrator-cs3-crack-only-work/
    • http://www.babel-web.eu/p7/amma-bhagwan-mp3-song-free-download-link/
    • https://cashonhomedelivery.com/mobiles/plex-earth-tools-license-key/
    • https://www.gayleatherbiker.de/upload/files/2022/07/YLFy2LyZofuDnxYgBvsv_02_de02e49a1c5e9ed8049c8af82d1a0291_file.pdf
    • https://mac.com.hk/advert/dias-de-reyes-magos-emilio-pascual-pdf-86/
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/