Malicious PDF — malware analysis report

Static analysis result for SHA-256 a507c9e7bd00f619…

MALICIOUS

PDF

97.9 KB Created: 2022-06-10 05:22:20 +02:00 Authoring application: wankae (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 152e7783527a8889968defdbcaf9bec0 SHA-1: 3f09f48da2e06ded1076d2c593b8f2a00367b36f SHA-256: a507c9e7bd00f61940fe1d06fc3684d853d3fd08b3fa8c0bf247e5d532b31cd1
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of external links, identified as a 'PDF SEO link farm'. One of these links, http://evacdir.com/..., is flagged as an external URI. This technique is often used to distribute malware or redirect users to phishing sites. No scripts were extracted, and the document body was heavily truncated, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier clean score 0.0177

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://evacdir.com/ZG93bmxvYWR8N2c0Tm0xaWJIeDhNVFkxTkRjNE1EZzNPWHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA/craniotomy&lane=precooked&iridescence=VGhlIFVsdGltYXRlIFN1cnZleSBCb3QgQUNDRVNTIEtFWQVGh.keratectomy
    • https://bisnisdijogja.com/6666-games-in-1-ultimate-classic-games-collection-retro-legends-verified/
    • https://hanna-kash.ru/?p=8340
    • https://misasgregorianas.com/alwaysup-7-5-0-39-incl-keygen-vokeon-link/
    • https://panda-app.de/upload/files/2022/06/pSig9ApgIHP37soDMWhg_10_a5eb1f01fbe048a14c837deea2c36d49_file.pdf
    • https://drwellness.net/iobit-uninstaller-pro-13-2-5-39-multilingual-crack-top-serial-key-keygen/
    • https://smartbizad.com/advert/lounge-lizard-20-full-package-serial-number/
    • https://www.kmjgroupfitness.com/cummins-calterm-full-keygen-download-mediafire/
    • http://www.antiquavox.it/wp-content/uploads/2022/06/oleambr.pdf
    • https://fryter.com/upload/files/2022/06/WCxwvXNA36yxFz3MLATC_10_8eb1630b7b90efb2848b7b7795842cd8_file.pdf
    • https://hanna-kash.ru/wp-content/uploads/2022/06/novel_fredy_s_yang_berjudul_tante_marissa_annfron.pdf
    • https://www.laundryandcleaningtoday.co.uk/advert/microsoft-office-2007-gratuit-tunisia-sat/
    • https://www.lion.tech/wp-content/uploads/2022/06/westman.pdf
    • https://octopi.nl/wp-content/uploads/2022/06/tekla_structures_multi_user_server_23_20.pdf
    • https://tarpnation.net/gra-strzel-sobie-2-download/
    • https://cecj.be/wp-content/uploads/2022/06/panway.pdf
    • https://foaclothing.com/wp-content/uploads/2022/06/Mortal_Kombat_Komplete_Edition_CrackOnlyFLT_Skidrow_Reloaded_VERIFIED.pdf
    • https://www.palpodia.com/upload/files/2022/06/wffUO9YRZA3Ez8WHJOsn_10_8eb1630b7b90efb2848b7b7795842cd8_file.pdf
    • https://madreandiscovery.org/fauna/checklists/checklist.php?clid=19803
    • https://cdn.lyv.style/wp-content/uploads/2022/06/10052219/Daisys_Destruction.pdf
    • https://foaclothing.com/wp-
    • https://www.palpodia.com/upload/files/2022/06/wffUO9YRZA3Ez8WHJOsn_10_8eb1630b7b90efb2848b7b7795842cd8_file
    • https://biokic4.rc.asu.edu/sandbox/portal/checklists/checklist.php?clid=8871
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off000028af.bin
a217f12862e0ff75203bdd4136ca0d68471050be46bb09aed5306898926ffdd4
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x28AF 120140 bytes