Malicious PDF — malware analysis report

Static analysis result for SHA-256 a01565c78a37718e…

MALICIOUS

PDF

85.0 KB Created: 2022-06-10 05:15:42 +02:00 Authoring application: stanwan (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 3cb26e5a3a86c1021999d41d6db128a0 SHA-1: 501629dd43c324b007943b0b0806ae322a531e22 SHA-256: a01565c78a37718ee2ffa3bb27722b7a7a4637bbb207ade07cce90a59acbbede
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, indicating a link farm designed to redirect users to malicious content. One critical heuristic identified a PDF link farm with 26 external links, and another noted an embedded URI pointing to 'evacdir.com'. These findings suggest the document's primary purpose is to facilitate the download of further malware or phishing content.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.2513

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://evacdir.com/ZG93bmxvYWR8dEs3Tm1VeVlueDhNVFkxTkRjNE1EZzNPWHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA/reflects.anglia.SXZpZXcgRm9yIFlvdSBWNCBaaXASXZ.black/rally/orthodic/poisons/saveur
    • https://journeytwintotheunknown.com/wp-content/uploads/2022/06/Mixmeister_Pro_6_Free_Download_Crack_PORTABLE.pdf
    • https://karahvi.fi/wp-content/uploads/2022/06/KeiluVisionv817aC51Portablerar_Download.pdf
    • https://writeforus.website/wp-content/uploads/2022/06/tandder.pdf
    • https://flagonsworkshop.net/upload/files/2022/06/QfQEqqP8OyzSILztseL4_10_16a36f66af09522fb2a7d4e75acdefa2_file.pdf
    • https://teaway.pl/wp-content/uploads/2022/06/variwal.pdf
    • https://lavivafashion.ie/wp-content/uploads/2022/06/Restorer_Ultimate_Crack_Keygen_Download_13.pdf
    • https://lfbridge.com/upload/files/2022/06/n4xuaPSuALs4AtjFjdba_10_16a36f66af09522fb2a7d4e75acdefa2_file.pdf
    • https://super-sketchy.com/wp-content/uploads/2022/06/vanjnish.pdf
    • https://www.cbdxpress.de/wp-content/uploads/Download_Zone_Code_Pre_Gfxff_Direct_Downloadrar.pdf
    • https://www.slothtrip.com/wp-content/uploads/2022/06/bensan.pdf
    • http://beliketheheadland.com/wp-content/uploads/2022/06/windows_7_language_changer_download.pdf
    • http://homeprosinsulation.com/wp-content/uploads/2022/06/resenar.pdf
    • http://www.fuertebazar.com/2022/06/10/nissan-data-scan-2-53-keygen-patched/
    • https://nisharma.com/avf-double-shock-controller-driver/
    • https://www.proindustria.net/wp-content/uploads/2022/06/Windows_Loader_Gratuit_01net_LINK.pdf
    • http://twinmyclub.com/wp-content/uploads/2022/06/burrhath.pdf
    • https://eventouritaly.com/wp-content/uploads/2022/06/hisanave.pdf
    • https://winecountryontario.ca/wp-content/uploads/2022/06/odeind.pdf
    • https://yietnam.com/upload/files/2022/06/29xycmMsFonzj7GdtsTJ_10_16a36f66af09522fb2a7d4e75acdefa2_file.pdf
    • https://journeytwintotheunknown.com/wp-
    • https://worknugawisjackkon.wixsite.com/inorsurmu/post/atnsoft-key-manager-1-15-crack-exe
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off000012f1.bin
3bd1b62f1277a9e85094e434d3d29add16fd516257e9610fa8c516ea168cf8d5
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x12F1 126848 bytes