Malicious PDF — malware analysis report

Static analysis result for SHA-256 abfa42f5daaed906…

MALICIOUS

PDF

121.6 KB Created: 2022-07-08 05:37:47 +00:00 Authoring application: wavdar (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 35a993633b11c72fb1e8e42305e36120 SHA-1: ff2d33c948c2b7fb64c3ad062f97df5cf18b8319 SHA-256: abfa42f5daaed906a02a40808390009f3d2da928ba11d31aa4e71ededc4d8504
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic. One of the primary external links, http://bestentrypoint.com/chantry/dockable.Y2hlYXQgY2hpcCBwb2tlciB0ZXhhcyBib3lhYSBmYWNlYm9vawY2h.weathervanes/eater/interconference.mbps.ZG93bmxvYWR8TWQzYUdFMWRYeDhNVFkxTnpFNE5qazFOWHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA.paraphrasing, appears to be a malicious lure. The presence of numerous links suggests an attempt to manipulate search engine results or distribute malicious content.

Machine Learning

  • Nyx PDF Classifier clean score 0.0146

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bestentrypoint.com/chantry/dockable.Y2hlYXQgY2hpcCBwb2tlciB0ZXhhcyBib3lhYSBmYWNlYm9vawY2h.weathervanes/eater/interconference.mbps.ZG93bmxvYWR8TWQzYUdFMWRYeDhNVFkxTnpFNE5qazFOWHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA.paraphrasing
    • https://social.urgclub.com/upload/files/2022/07/D97OcXxD5axQfr9ZNhnJ_08_eb0f7bce44f5d6a752d6627a15609858_file.pdf
    • http://modiransanjesh.ir/rio-crtani-film-na-hrvatskom-16-full/
    • https://endleleni.com/wp-content/uploads/2022/07/Kraljevstvo_Hazara_Dejan_Lucic_Pdf_Download.pdf
    • https://teko.my/upload/files/2022/07/t7U1cBklGfm7y7x9Z9dR_08_ceef24a0b2abbfc60f73e2b70098ee00_file.pdf
    • https://propertynet.ng/discografia-roupa-nova-1975-a-2008-38-cds-torrent-exclusive/
    • http://www.lab20.it/2022/07/08/eastward-pc-game-free-download-link/
    • https://www.sitedirectory.biz/tina-v9-3-50-crck-v2-by-pertican-rar-link
    • http://barrillos.org/2022/07/08/windows-server-2012-termsrv-dll-53-new/
    • https://www.northfieldnh.org/sites/g/files/vyhlif6621/f/pages/news_july.pdf
    • https://topnotchjobboard.com/system/files/webform/resume/foldest711.pdf
    • http://pacificaccommodation.com/fairy-tail-season-5-eng-sub-720p-episode-176-226-l-mbert-better/
    • http://www.giffa.ru/uncategorized/adobe-photoshop-cc-2018-25-0-1-29687-patch-utorrent-cracked/
    • http://jeunvie.ir/?p=6951
    • https://www.armerdo.com/wp-content/uploads/2022/07/Adobe_Photoshop_Cs7_Portable_HOT_Free_Download_Full_Versionl.pdf
    • https://adhicitysentulbogor.com/wp-content/uploads/2022/07/farrsak.pdf
    • http://www.hva-concept.com/the-sims-3-kinkyworld/
    • http://djolof-assurance.com/?p=28874
    • https://4g65.com/loiloscope-2-serial-upd-crack-logic-59/
    • https://social.urgclub.com/upload/files/2022/07/D97OcXxD5axQfr9ZNhnJ_08_eb0f7bce44f5d6a752d6
    • https://endleleni.com/wp-
    • https://teko.my/upload/files/2022/07/t7U1cBklGfm7y7x9Z9dR_08_ceef24a0b2abbfc60f73e2b70098e
    • https://www.armerdo.com/wp-
    • http://nobasbe.yolasite.com/resources/Solucionario-De-Estadistica-De-Schaum-Gratis-Free.pdf
    • https://circles.nyc3.digitaloceanspaces.com/upload/files/2022/07/uMPlKHFpGXCgcg8ZEZz6_08_eb0f7bce44f5d6a752d6627a15609858_file.pdf
    • http://www.tcpdf.org
    • https://circles.nyc3.digitaloceanspaces.com/upload/files/2022/07/uMPlKHFpGXCgcg8ZEZz6_08_eb0f7
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/