Malicious PDF — malware analysis report

Static analysis result for SHA-256 a58b5a19141f4c1a…

MALICIOUS

PDF

138.4 KB Created: 2022-07-07 22:31:29 +00:00 Authoring application: eleaalta (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 3d21e4a590c45d9e5213ecfca896a9f0 SHA-1: 8c0ba4e648a2c0ad686e9df44d653a477f34c84f SHA-256: a58b5a19141f4c1a919259d4da17ae31013cc9e72026067aa52b6cefc2487fbe
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or phishing attempt. One of the embedded URLs, http://find24hs.com/, appears to be a gateway for further malicious activity. The document body was unreadable, but the presence of numerous links strongly indicates a malicious intent to redirect users to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier clean score 0.0087

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://find24hs.com/?carri=/volatilization/carvers/jason/shipwreck/morven/oviparous/ZG93bmxvYWR8b3o1Tm0xNmRIeDhNVFkxTnpFNE5qazFOWHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA.bGlnYSAxIHJvbWFuaWEgZmlmYSAxMyBkb3dubG9hZCB0b3JlbnQbGl
    • https://financetalk.ltd/audioeasealtiverb7xl726vstaaxx86x642016-portable/
    • https://designfils.eba.gov.tr/blog/index.php?entryid=84521
    • https://questionnaire.ur.ac.rw/sites/default/files/webform/repotingdocs/amiquote-3-12-crack-14.pdf
    • https://playerclub.app/upload/files/2022/07/DqMqtHnrbiKfBy1zDgCG_08_a0e1fe7d089a31dc9ed84c159f2c48bc_file.pdf
    • https://poetbook.com/upload/files/2022/07/mBsw9i16VrIC52yBYPU6_07_7e05b402f9206fc2a6a248b6ede106d2_file.pdf
    • https://www.careion.be/sites/default/files/webform/glegas241.pdf
    • https://www.reperiohumancapital.com/system/files/webform/safran-morpho-mso-1300-e-software-587.pdf
    • http://palladium.bg/wp-content/uploads/2022/07/Adobe_Photoshop_Cs5_Extended_V12_Keygen_FREE_Only_Embrace_Deantjah.pdf
    • https://revitiq.com/wp-content/uploads/2022/07/Rustangelo_PRO_Basic_Torrent_Download_Extra_Quality_Crack_Serial_Key.pdf
    • https://panda-app.de/upload/files/2022/07/175Rbsk2nfBVgQx8luTm_07_a0e1fe7d089a31dc9ed84c159f2c48bc_file.pdf
    • https://forms.miis.edu/system/files/webform/fabrwayn111.pdf
    • https://influencerstech.com/upload/files/2022/07/KDJ6qpA4rIwjADJxO4Vt_07_a0e1fe7d089a31dc9ed84c159f2c48bc_file.pdf
    • https://moodle.ezorock.org/blog/index.php?entryid=8170
    • https://escuelainternacionaldecine.com/blog/index.php?entryid=3554
    • https://wakandaplace.com/wp-content/uploads/2022/07/wylkata.pdf
    • https://www.tailormade-logistics.com/sites/default/files/webform/edwaari813.pdf
    • http://countrylifecountrywife.com/philta-xl-vst-download-crack-extra-quality/
    • https://www.cameraitacina.com/en/system/files/webform/feedback/leiben290.pdf
    • https://playerclub.app/upload/files/2022/07/DqMqtHnrbiKfBy1zDgCG_08_a0e1fe7d089a31dc9ed84c1
    • https://poetbook.com/upload/files/2022/07/mBsw9i16VrIC52yBYPU6_07_7e05b402f9206fc2a6a248b6
    • https://www.reperiohumancapital.com/system/files/webform/safran-morpho-mso-1300-e-
    • http://palladium.bg/wp-content/uploads/2022/07/Adobe_Photoshop_Cs5_Extended_V12_Keygen_FREE
    • https://revitiq.com/wp-content/uploads/2022/07/Rustangelo_PRO_Basic_Torrent_Download_Extra_Qua
    • https://panda-app.de/upload/files/2022/07/175Rbsk2nfBVgQx8luTm_07_a0e1fe7d089a31dc9ed84c15
    • https://influencerstech.com/upload/files/2022/07/KDJ6qpA4rIwjADJxO4Vt_07_a0e1fe7d089a31dc9ed8
    • https://wakelet.com/wake/UCc7x0gvcOc2YpEhEV968
    • https://olegot4zus.wixsite.com/visvadema/post/full-hd-video-songs-1080p-hindi-ishq-junoon-link
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_011_off0001b024.bin
df221e87b81d1531cafdadb6c09a602e9f604d1baf0a17bbd350cbb83baa06f7
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1B024 119072 bytes