Malicious PDF — malware analysis report

Static analysis result for SHA-256 b24046cd50bb3b3b…

MALICIOUS

PDF

125.8 KB Created: 2022-07-04 04:32:23 +00:00 Authoring application: wannvyn (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 2fb34b594914691d850e7964e5246400 SHA-1: 7ff9d58582b61100e618212819410b5464aa6176 SHA-256: b24046cd50bb3b3b10f5dc4bd78571d206aa0bf4db42051f5fd09a79e47884cd
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic. One of these links, http://hardlyfind.com/harkened/ZG93bmxvYWR8bnUxTm5KelkzeDhNVFkxTmpnNU1qTTFNbng4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA.druid/enhancedhealing/healthtalk/feduc/TGl2ZSBPcmJpdGFsIFdhbGxwYXBlcnMTGl.fuentes?part, is flagged as a potential entry point to malicious content. The overall structure suggests a link farm or a distribution mechanism for further malicious payloads.

Machine Learning

  • Nyx PDF Classifier clean score 0.0137

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://hardlyfind.com/harkened/ZG93bmxvYWR8bnUxTm5KelkzeDhNVFkxTmpnNU1qTTFNbng4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA.druid/enhancedhealing/healthtalk/feduc/TGl2ZSBPcmJpdGFsIFdhbGxwYXBlcnMTGl.fuentes?part
    • https://ipayif.com/upload/files/2022/07/fy5odBdg2f9MPTfrcide_04_39f3a1a785d6e08f3cf7321e1fe4aab6_file.pdf
    • https://theludwigshafen.com/magic-aac-to-mp3-converter-crack-serial-number-full-torrent-free-x64-2022/
    • https://www.periodicoelapogeo.com.ar/site/advert/spelling-bee-crack-license-key-full-latest/
    • https://www.realvalueproducts.com/sites/realvalueproducts.com/files/webform/raymar291.pdf
    • https://geto.space/upload/files/2022/07/dx6UP9jlidOzmKRkcrfi_04_51886c7f92aaa3d238deb559c3b222f3_file.pdf
    • https://colonialrpc.com/advert/desktop-launcher-and-communicator-crack-torrent/
    • https://dragalacoaching1.com/aumbi-crack-free-download/
    • https://kate-mobilez.ru/ssh-edit-crack-free-mac-win.html
    • https://technospace.co.in/upload/files/2022/07/1SqSowg7b3XXFejp5Z6b_04_aa8a8cd54a3a53a9de49abda95ace668_file.pdf
    • https://axisflare.com/upload/files/2022/07/FQMyjJCX7SFxmzqyzIAe_04_39f3a1a785d6e08f3cf7321e1fe4aab6_file.pdf
    • http://radialamoladora.com/?p=3336
    • http://adomemorial.com/2022/07/04/ivolume-9-5-0-5-crack-activator-free-download-latest-2/
    • https://kalapor.com/ipixsoft-gif-to-swf-converter-crack-license-code-keygen-free-download-latest-2022/
    • http://quitoscana.it/2022/07/04/taksi-2-4-4-crack-for-pc/
    • http://www.trabajosfacilespr.com/advance-elite-adware-removal-tool-crack-with-license-key-pc-windows/
    • https://himoin.com/upload/files/2022/07/EqTSvWHOwuYeUz1vyJmz_04_51886c7f92aaa3d238deb559c3b222f3_file.pdf
    • https://worlegram.com/upload/files/2022/07/Gbw1QgDKp1YxVMhAZo5G_04_39f3a1a785d6e08f3cf7321e1fe4aab6_file.pdf
    • https://khaosod.us/classified/advert/downgramer-license-key-latest/
    • https://soulattorney.com/geeksnerds-xfs-datarecovery-torrent-free-x64/
    • https://ipayif.com/upload/files/2022/07/fy5odBdg2f9MPTfrcide_04_39f3a
    • https://theludwigshafen.com/magic-aac-to-mp3-converter-crack-serial-
    • https://www.periodicoelapogeo.com.ar/site/advert/spelling-bee-crack-
    • https://www.realvalueproducts.com/sites/realvalueproducts.com/files/w
    • https://geto.space/upload/files/2022/07/dx6UP9jlidOzmKRkcrfi_04_5188
    • https://colonialrpc.com/advert/desktop-launcher-and-communicator-
    • https://technospace.co.in/upload/files/2022/07/1SqSowg7b3XXFejp5Z6b
    • https://axisflare.com/upload/files/2022/07/FQMyjJCX7SFxmzqyzIAe_04_3
    • http://adomemorial.com/2022/07/04/ivolume-9-5-0-5-crack-activator-
    • https://kalapor.com/ipixsoft-gif-to-swf-converter-crack-license-code-
    • http://www.trabajosfacilespr.com/advance-elite-adware-removal-tool-
    • https://himoin.com/upload/files/2022/07/EqTSvWHOwuYeUz1vyJmz_04_
    • https://worlegram.com/upload/files/2022/07/Gbw1QgDKp1YxVMhAZo5G
    • https://wakelet.com/wake/feVp3NEFbHDEHuJFMyQQ5
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/