Malicious PDF — malware analysis report

Static analysis result for SHA-256 b2ab6466e67a1ab0…

MALICIOUS

PDF

144.2 KB Created: 2022-07-05 19:04:15 +00:00 Authoring application: janyfall (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 8facb1e70a85c9b8805587d288ec4150 SHA-1: 498deaa2d46666b30fa4c25b4db0330aa1ba6db9 SHA-256: b2ab6466e67a1ab045d55e2222552d4839fe1a44240e196724da3bb59076b888
104 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1566 Phishing

The PDF document contains a large number of external links, many of which appear to be SEO-optimized lures for downloading software or cracks, such as 'Fifa 22'. The heuristic 'SE_BROWSER_INSTALL_LURE' indicates the document explicitly tells the user to install a browser extension or update. This suggests the primary goal is to trick the user into downloading and executing malicious content disguised as legitimate software or updates.

Machine Learning

  • Nyx PDF Classifier clean score 0.0057

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://evacdir.com/fingered/ZG93bmxvYWR8RlE0TlhCNk1ueDhNVFkxTnpBek5qSXlNM3g4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA/revues.mmatchev?RmlmYSAyMgRml.terrasse.oriol
    • https://teenmemorywall.com/fifa-22-serial-number-and-product-key-crack-activation-key-updated-2022/
    • https://www.lacalleloiza.com/wp-content/uploads/2022/07/Fifa_22_With_License_Key__Torrent_Activation_Code_For_Windows.pdf
    • https://anipal.es/wp-content/uploads/2022/07/pasttibe.pdf
    • https://ciagadgets.com/2022/07/05/fifa-22-keygen-free-x64/
    • https://thecryptobee.com/fifa-22-crack-keygen-with-serial-number-keygen-full-version-pc-windows-latest-2022/
    • https://comecongracia.com/uncategorized/fifa-22-march-2022/
    • https://mandarinrecruitment.com/system/files/webform/fifa-22_1126.pdf
    • https://technospace.co.in/upload/files/2022/07/jVGhZxCKRy7Jirf3GjGX_05_3472e1073a84f43714b4f8e47b6dbff6_file.pdf
    • http://feelingshy.com/fifa-22-crack-with-serial-number/
    • http://www.superlisten.dk/wp-content/uploads/2022/07/elbefall.pdf
    • https://medcoi.com/network/upload/files/2022/07/X9S2Il9V6LFQ1oK443IU_05_3472e1073a84f43714b4f8e47b6dbff6_file.pdf
    • https://resistanceschool.info/fifa-22-4/
    • https://myperfecttutors.com/fifa-22-serial-key-free-download-3264bit-2022/
    • https://braingroom.com/blog/index.php?entryid=4735
    • https://feimes.com/fifa-22-key-generator-product-key-full-april-2022/
    • https://oxfordaustraliascholarships.anu.edu.au/system/files/webform/oxford/referee/crojae581.pdf
    • https://yemensouq.com/wp-content/uploads/2022/07/mahlgau.pdf
    • https://ipayif.com/upload/files/2022/07/FP7sxyEUYCXfa9MgLq3x_05_3472e1073a84f43714b4f8e47b6dbff6_file.pdf
    • https://education.azgovernor.gov/system/files/webform/fifa-22_4.pdf
    • https://startclube.net/upload/files/2022/07/y3ReckwzNxWFCXE2a23C_05_3472e1073a84f43714b4f8e47b6dbff6_file.pdf
    • https://teenmemorywall.com/fifa-22-serial-number-and-product-key-crack-activation-key-
    • https://www.lacalleloiza.com/wp-
    • https://thecryptobee.com/fifa-22-crack-keygen-with-serial-number-keygen-full-version-pc-windows-
    • https://technospace.co.in/upload/files/2022/07/jVGhZxCKRy7Jirf3GjGX_05_3472e1073a84f43714b4f8
    • https://medcoi.com/network/upload/files/2022/07/X9S2Il9V6LFQ1oK443IU_05_3472e1073a84f43714b
    • https://ipayif.com/upload/files/2022/07/FP7sxyEUYCXfa9MgLq3x_05_3472e1073a84f43714b4f8e47b6
    • https://startclube.net/upload/files/2022/07/y3ReckwzNxWFCXE2a23C_05_3472e1073a84f43714b4f8e
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/