Malicious PDF — malware analysis report

Static analysis result for SHA-256 b91b545f80fc3572…

MALICIOUS

PDF

141.5 KB Created: 2022-07-05 18:16:57 +00:00 Authoring application: galjan (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: cb6df07e6bc2641fd2ed0559b58475e0 SHA-1: 22cc9c9f20467c540c2e6dd7b266654456f5453e SHA-256: b91b545f80fc3572a0f9600e76e7403127cb66572ff628f8371090bf6e2f6515
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link T1059.001 PowerShell

The PDF file contains a large number of external links, many of which are SEO-optimized and point to pages offering cracks or serial keys for FIFA 22. One of the primary external URIs, http://bestsmartfind.com/crashes/sherpa?..., appears to be a download URL. This suggests the document is designed to trick users into visiting malicious sites that likely host malware or phishing content.

Machine Learning

  • Nyx PDF Classifier clean score 0.0059

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bestsmartfind.com/crashes/sherpa?ZG93bmxvYWR8enkzTkdGMlpIeDhNVFkxTnpBek5qSXlNM3g4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA=/iggo/RmlmYSAyMgRml/discoloration/kayaked/medicinals/
    • https://academicpipelinedatabase.net/wp-content/uploads/2022/07/nabivan.pdf
    • https://www.eventogo.com/fifa-22-serial-key-license-code-keygen-x64/
    • https://guaraparadise.com/2022/07/05/fifa-22-crack-with-serial-number-license-key-full-latest-2022/
    • https://provibelife.com/wp-content/uploads/2022/07/Fifa_22-1.pdf
    • https://romanibook.com/upload/files/2022/07/gqIwrNB98Xvotg9RBmwp_05_0cd9a459efc6050f7f8d78a42265fd5c_file.pdf
    • http://www.ndvadvisers.com/fifa-22-free-for-pc-latest-2022/
    • http://www.viki-vienna.com/fifa-22-download-for-pc-latest/
    • https://chuchoola.fun/?u=k8pp605
    • https://csermooc78next.blog/wp-content/uploads/2022/07/fifa_22_serial_number__torrent_free_download.pdf
    • http://www.giffa.ru/who/fifa-22-free-download-2022/
    • https://www.campwoodwings.com/sites/default/files/webform/annarya622.pdf
    • https://lfbridge.com/upload/files/2022/07/jWKlCJJnAx5C2boYvfDy_05_8f6408cc3df5eecee7aa9104103d0f18_file.pdf
    • https://mandarinrecruitment.com/system/files/webform/endret861.pdf
    • https://www.avon.k12.ma.us/sites/g/files/vyhlif4136/f/uploads/child_find_2021_1.pdf
    • https://www.cameraitacina.com/en/system/files/webform/feedback/maryam595.pdf
    • https://makanty.net/wp-content/uploads/2022/07/Fifa_22_Mem_Patch__Free_Download_April2022.pdf
    • https://pieseutilajeagricole.com/wp-content/uploads/2022/07/Fifa_22_Mem_Patch___For_PC.pdf
    • https://www.rehobothma.gov/sites/g/files/vyhlif4911/f/uploads/ma_building_code_on_swimming_pools.pdf
    • https://navbizservices.com/wp-content/uploads/2022/07/Fifa_22-9.pdf
    • https://airbrushinformation.net/wp-content/uploads/2022/07/Fifa_22_Incl_Product_Key_Download_3264bit.pdf
    • https://romanibook.com/upload/files/2022/07/gqIwrNB98Xvotg9RBmwp_05_0cd9a459efc6050f7f8d78
    • https://csermooc78next.blog/wp-
    • https://lfbridge.com/upload/files/2022/07/jWKlCJJnAx5C2boYvfDy_05_8f6408cc3df5eecee7aa9104103
    • https://www.rehobothma.gov/sites/g/files/vyhlif4911/f/uploads/ma_building_code_on_swimming_pool
    • https://airbrushinformation.net/wp-
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/