Malicious PDF — malware analysis report

Static analysis result for SHA-256 a90141e959c0fd42…

MALICIOUS

PDF

119.8 KB Created: 2022-07-06 06:55:17 +00:00 Authoring application: naomtrev (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: f05ff1b3dea338ec2e322a43966274b0 SHA-1: 7f3466d79180c3f5b279cea369ef6949862877b5 SHA-256: a90141e959c0fd4215c7799c21a1b2667cba4457d517b535d32d5a38b0cd060b
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF document contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic. One of these links, http://bestentrypoint.com/..., points to a URL that appears to be designed for downloading further content. The presence of numerous external links suggests a tactic to distribute malicious payloads or engage in link farming for SEO manipulation.

Machine Learning

  • Nyx PDF Classifier clean score 0.0012

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bestentrypoint.com/ZGFtbXUgdGVsdWd1IG1vdmllIHN1YnRpdGxlcyBkb3dubG9hZAZGF/canons/drescher/ZG93bmxvYWR8OEM4WVhocE5ueDhNVFkxTnpBMk56RTFOSHg4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA&steroids.glamour.hamm
    • https://www.noidabestproperty.com/wp-content/uploads/2022/07/athove.pdf
    • https://orderino.de/wp-content/uploads/2022/07/decamerone_dieci_novelle_raccontate_da_piero_chiara_pdf_11.pdf
    • https://richard-wagner-werkstatt.com/2022/07/06/povestiri-istorice-dumitru-almas-pdf-download-__top__/
    • http://chatroom.thabigscreen.com:82/upload/files/2022/07/8UClfXAQDgKxcn2tH9hN_06_4d31fc61cd9ef56f59fbff24490997c8_file.pdf
    • https://friendship.money/upload/files/2022/07/O9W1DPjj2PwFrkebUCPl_06_07110c0e995479f8520debc8ecf8e0e8_file.pdf
    • https://www.lakemaryfl.com/sites/g/files/vyhlif746/f/uploads/fy22_adopted_budget_ada.pdf
    • https://dawnintheworld.net/fall-of-light-darkest-edition-free-download-crack-with-full-gamel-repack/
    • https://fraenkische-rezepte.com/wp-content/uploads/2022/07/jansbeli.pdf
    • https://ex0-sys.app/upload/files/2022/07/rVj2gM1UZjhvbt7twgwy_06_4d31fc61cd9ef56f59fbff24490997c8_file.pdf
    • https://libres.nomasmentiras.uy/upload/files/2022/07/9ZBlQH9k6iPXrhb4Bpfg_06_4d31fc61cd9ef56f59fbff24490997c8_file.pdf
    • https://alafdaljo.com/mca-cet-books-pdf-free-download-_top_/
    • https://www.iscribble.org/wp-content/uploads/2022/07/Smart_Slider_3_Nulled_Cracking.pdf
    • https://www.painterparts.com/system/files/webform/customer-support/2022/volbird195.pdf
    • https://www.bywegener.dk/wp-content/uploads/2022/07/feltvass.pdf
    • https://www.mypolithink.com/advert/download-sp5-solidworks-2012-crack-new/
    • http://fairdalerealty.com/?p=8760
    • https://tcep.or.th/sites/default/files/webform/amtcep2020/flyielbi842.pdf
    • https://www.tuttoporte.com/sites/default/files/webform/halfere991.pdf
    • http://www.ventadecoches.com/m3-bitlocker-recovery-keygen-idm-link/
    • https://topnotchjobboard.com/system/files/webform/resume/power-fm-top-40-listesi-e.pdf
    • https://orderino.de/wp-
    • https://richard-wagner-werkstatt.com/2022/07/06/povestiri-istorice-dumitru-almas-pdf-
    • http://chatroom.thabigscreen.com:82/upload/files/2022/07/8UClfXAQDgKxcn2tH9hN_06_4d31fc61cd
    • https://friendship.money/upload/files/2022/07/O9W1DPjj2PwFrkebUCPl_06_07110c0e995479f8520de
    • https://ex0-sys.app/upload/files/2022/07/rVj2gM1UZjhvbt7twgwy_06_4d31fc61cd9ef56f59fbff244909
    • https://libres.nomasmentiras.uy/upload/files/2022/07/9ZBlQH9k6iPXrhb4Bpfg_06_4d31fc61cd9ef56f5
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/