Malicious PDF — malware analysis report

Static analysis result for SHA-256 b8c525031c9e80b6…

MALICIOUS

PDF

136.1 KB Created: 2022-07-04 04:58:14 +00:00 Authoring application: jeronola (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 810be9cd6aa4133c221fbb91c55e88f0 SHA-1: 744e3cc3769162b928af3fee5cad955e436c2418 SHA-256: b8c525031c9e80b6807262b9a98b735f61c22b7d8cab75e4b1d577f8443302c4
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document exhibits characteristics of a link farm, containing a large number of external URLs. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links, with 'http://seachtop.com/videoselect&algar/bios/?barbarian=ZG93bmxvYWR8NklKTjJZeGNueDhNVFkxTmpnNU1qTTFNbng4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA&UmVnRXggTGl0ZQUmV=janelleelms' being a prominent example. This suggests the PDF's primary purpose is to lure users to potentially malicious websites.

Machine Learning

  • Nyx PDF Classifier clean score 0.0057

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seachtop.com/videoselect&algar/bios/?barbarian=ZG93bmxvYWR8NklKTjJZeGNueDhNVFkxTmpnNU1qTTFNbng4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA&UmVnRXggTGl0ZQUmV=janelleelms
    • http://elstar.ir/2022/07/04/fast-dvd-converter-crack-download-april-2022/
    • https://kcachurch.org/2022/07/04/pdf-split-merge-pages-crack-torrent-activation-code/
    • https://clasificadostampa.com/advert/color-bars-tone-patch-with-serial-key/
    • https://workplace.vidcloud.io/social/upload/files/2022/07/7uOC3bDZ6hBSAHv47SNe_04_9cee6c4ef1e32a4b1a87a6005bfcac93_file.pdf
    • https://geezfamily.com/wp-content/uploads/2022/07/malland.pdf
    • https://studiolegalefiorucci.it/2022/07/04/ez-word-to-pdf-converter-crack-license-keygen/
    • https://ideaboz.com/2022/07/04/mousetrainer-crack-download-mac-win/
    • https://bizzbless.com/wp-content/uploads/2022/07/faraben.pdf
    • http://kampungkbpucangsawit.com/?p=2730
    • https://warm-thicket-37023.herokuapp.com/MB_Free_Calorie_Calculator.pdf
    • https://globe-med.com/wp-content/uploads/2022/07/dawnqui.pdf
    • https://discoverlosgatos.com/filepush-download-2022/
    • https://topcoffeebar.com/wp-content/uploads/2022/07/Graphs_Made_Easy__Crack___With_License_Key_Download_3264bit.pdf
    • https://jasaborsumurjakarta.com/extra-time-calculator-updated-2022
    • https://www.bigdawgusa.com/moorer-port-scanner-crack-with-serial-key/
    • https://www.the-fox.it/2022/07/04/rar-streamer-crack-activation-code-with-keygen-for-pc-april-2022/
    • http://www.vidriositalia.cl/?p=35080
    • https://www.raven-guard.info/jazz-scale-suggester-system-lite-crack-free-license-key-free-3264bit/
    • https://www.apbara.be/index.php/advert/commandeer-1-8-1-crack-license-code-keygen-for-pc-2022/
    • https://workplace.vidcloud.io/social/upload/files/2022/07/7uOC3bDZ6hBSAHv47SNe_04_9cee6c4ef1e32a4b1a87a
    • https://topcoffeebar.com/wp-
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/